6 ms·
Sega Europe left AWS S3 creds laying around in a server image on downloads.sega.com. I was able to use them to enumerate a bunch of storage, dig out more keys,
by aaronwp 5y ago
Sega Europe left AWS S3 creds laying around in a server image on downloads.sega.com. I was able to use them to enumerate a bunch of storage, dig out more keys, and mock up a spear phishing attack against the Football Manager forums.
All the keys and services are secure and the breach is closed.
- robtaylor 5y agoAssertive: Show me something else.
- aaronwp 5y agostay tuned
- duxup 5y ago> dig out more keys I guess that if they leave them lying around that it is likely there are more.
- imwillofficial 5y agoThis would be awesome as a blog post if you ever want to go into detail on how you executed each step.
- deleted 5y ago[deleted]
- phnofive 5y agoIs it common, now or historically, to follow up a notification of compromise with self-directed PoC and privilege escalation exercises on the resources of a company with which you're not under contract? My naïve take is that this was a series of well-intentioned but possibly criminal actions used to illustrate a lesson we could all be reminded of from time to time. Also, the HackerOne page doesn't appear to be claimed by SEGA Sammy, so notices might dead-end there as well.
- aaronwp 5y agoYes, if PII is involved it's common to run an audit like this. In addition to the access keys on the server image, Sega also accidentally published a database export containing PII. In order to write a comprehensive disclosure I have to investigate thoroughly. And yeah, there's no branding or information on HackerOne. Even if this had been in scope, I would have thought twice about submitting anything. Our publishing standards match HackerOne ethical disclosure standards.
- tentacleuno 5y ago> Even if this had been in scope, I would have thought twice about submitting anything. Sorry, I don't understand. Why would you be hesitant to responsibly disclose it to HackerOne?
- phnofive 5y agoThey didn't know about it beforehand, but even if you visit the page, it says that SEGA Sammy hasn't claimed it, so it appears unofficial.
- phnofive 5y agoDid Sega agree to this public disclosure? Referring to the HackerOne standards, it appears your team violated a couple: > Respect privacy. Make a good faith effort not to access or destroy another user's data. > Do no harm. Act for the common good through the prompt reporting of all found vulnerabilities. Never willfully exploit others without their permission.
- wwtrv 5y agoPublic disclosing it seems to clearly fall under the ‘ Act for the common good through the prompt’ since SEGA’s user are the real victims in this situation and have the right to known that SEGA us incapable of keeping their data safe.
- 5y ago
- vmception 5y agoShould have just left it at that and collected the bug bounty, defacing for a proof of concept and telling everyone pretty much makes you ineligible in any white hat program. Can I get dibs on your flat while you're in the... camp?
- jsploit 5y ago> I was able to use them to enumerate a bunch of storage, dig out more keys That's unethical and likely criminal without explicit testing authorization (which it appears you didn't have). I wonder if there are any examples of "researchers" being sued/prosecuted for stunts like this.