Reporting publicly accessible data : IAC ?

Questions or suggestions about the platform
Post Reply
secuwatch
Posts:9
Joined:Thu Dec 12, 2019 9:13 am
Reporting publicly accessible data : IAC ?

Post by secuwatch » Fri Aug 07, 2020 12:53 pm

Hello,

I'd like to clarify how to best report security issues where unauthenticated users (simple visitors) can access files and data at a specific URL, withtout any other action than clicking on a link. My recent reports were rejected as "Cannot reproduce"' whereas a click on the provided link shows the issue, typically a database dump or an index listing with public documents in it. However several of my reports were rejected without enough details to understand what I may do incorrectly. For example see submission 1202323.

I seem to understand, and many of my previous reports were classified as such without being rejected, that they fall under the category "Improper Access Control", or Improper Privilege Management which is not offered here ?

I also cannot seem to find again the submission details once it is in "Rejected" status ? Annoying to have to recreate it all over again.

Thank you for that site and your replies..

User avatar
x1admin
Site Admin
Posts:3102
Joined:Sun Nov 15, 2015 7:04 pm

Re: Reporting publicly accessible data : IAC ?

Post by x1admin » Mon Aug 10, 2020 7:37 am

Directory listings is not iac

secuwatch
Posts:9
Joined:Thu Dec 12, 2019 9:13 am

Re: Reporting publicly accessible data : IAC ?

Post by secuwatch » Sat Aug 15, 2020 3:19 pm

Hello,

So how would you qualify for example a list of confidential resumes from applicants that can be found and read by anobody,
or a database dump with all confidential site and credentials in it ? How should a researcher report those ?
Thanks.

User avatar
x1admin
Site Admin
Posts:3102
Joined:Sun Nov 15, 2015 7:04 pm

Re: Reporting publicly accessible data : IAC ?

Post by x1admin » Mon Aug 17, 2020 7:41 am

list of resumes - gdpr
database dump - iac

Post Reply

Who is online

Users browsing this forum: No registered users and 2 guests