4 ms·
There was a case where we were able to gain access to Jira instance belonging to a bug bounty target (not even a Red Team engagement), and the Confluence wiki h
by hackerpain 6y ago
There was a case where we were able to gain access to Jira instance belonging to a bug bounty target (not even a Red Team engagement), and the Confluence wiki had every credential the company ever used. They used it as a secure credential storage. Majority of their internal panels didn't have a 2FA and we found internal VPN server credentials too (which didn't have source ip restrictions), so we could freely access tons of data. The bounty we got was around $1000 if I could remember, I think this would motivate a lot of hackers to not go the responsible disclosure way, as the incentives are ridiculously low.
But I could access literally everything related to that organization and their clients from that single Github leak (of Jira creds).
- lock-free 6y agoKind of an example of a "bigger fuck up" I was alluding to