Page 1 of 1

Reporting publicly accessible data : IAC ?

Posted: Fri Aug 07, 2020 12:53 pm
by secuwatch
Hello,

I'd like to clarify how to best report security issues where unauthenticated users (simple visitors) can access files and data at a specific URL, withtout any other action than clicking on a link. My recent reports were rejected as "Cannot reproduce"' whereas a click on the provided link shows the issue, typically a database dump or an index listing with public documents in it. However several of my reports were rejected without enough details to understand what I may do incorrectly. For example see submission 1202323.

I seem to understand, and many of my previous reports were classified as such without being rejected, that they fall under the category "Improper Access Control", or Improper Privilege Management which is not offered here ?

I also cannot seem to find again the submission details once it is in "Rejected" status ? Annoying to have to recreate it all over again.

Thank you for that site and your replies..

Re: Reporting publicly accessible data : IAC ?

Posted: Mon Aug 10, 2020 7:37 am
by x1admin
Directory listings is not iac

Re: Reporting publicly accessible data : IAC ?

Posted: Sat Aug 15, 2020 3:19 pm
by secuwatch
Hello,

So how would you qualify for example a list of confidential resumes from applicants that can be found and read by anobody,
or a database dump with all confidential site and credentials in it ? How should a researcher report those ?
Thanks.

Re: Reporting publicly accessible data : IAC ?

Posted: Mon Aug 17, 2020 7:41 am
by x1admin
list of resumes - gdpr
database dump - iac