UNPKG

hackerone-report-formatter

Version:

Formats HackerOne report into more readable form

832 lines 107 kB
{ "id": 745324, "url": "https://hackerone.com/reports/745324", "title": "Account takeover via leaked session cookie", "state": "Closed", "substate": "resolved", "severity_rating": "high", "readable_substate": "Resolved", "created_at": "2019-11-24T13:08:59.542Z", "is_member_of_team?": null, "reporter": { "disabled": false, "username": "haxta4ok00", "url": "/haxta4ok00", "profile_picture_urls": { "small": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/3afcb5c896247e7ee8ada31b1c1eb8657e22241f911093acfe4ec7e97a3a959a" }, "is_me?": false, "cleared": false, "hackerone_triager": false, "hacker_mediation": false }, "team": { "id": 13, "url": "https://hackerone.com/security", "handle": "security", "profile_picture_urls": { "small": "https://profile-photos.hackerone-user-content.com/variants/000/000/013/fa942b9b1cbf4faf37482bf68458e1195aab9c02_original.png/3afcb5c896247e7ee8ada31b1c1eb8657e22241f911093acfe4ec7e97a3a959a", "medium": "https://profile-photos.hackerone-user-content.com/variants/000/000/013/fa942b9b1cbf4faf37482bf68458e1195aab9c02_original.png/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "permissions": [], "submission_state": "open", "default_currency": "usd", "awards_miles": false, "offers_bounties": true, "state": "public_mode", "only_cleared_hackers": false, "profile": { "name": "HackerOne", "twitter_handle": "Hacker0x01", "website": "https://hackerone.com", "about": "Vulnerability disclosure should be safe, transparent, and rewarding." } }, "has_bounty?": true, "in_validation?": false, "rejected_anc_report_that_can_be_sent_back_to_anc_triagers?": false, "can_view_team": true, "is_external_bug": false, "is_published": false, "is_participant": false, "stage": 4, "public": true, "visibility": "full", "cve_ids": [], "singular_disclosure_disabled": false, "disclosed_at": "2019-12-03T17:00:22.005Z", "bug_reporter_agreed_on_going_public_at": null, "team_member_agreed_on_going_public_at": "2019-12-03T17:00:12.269Z", "comments_closed?": false, "facebook_team?": false, "team_private?": false, "vulnerability_information": "**Summary:**\nYou are disclose for me you session\n**Description:**\nyou are gevi me your session on last report\nI am can use your session(sorry)\n███\n████████\n█████████\n\n## Impact\n\nHackerOneStaff Access, i can read all reports @security and more program", "vulnerability_information_html": "<p><strong>Summary:</strong><br>\nYou are disclose for me you session<br>\n<strong>Description:</strong><br>\nyou are gevi me your session on last report<br>\nI am can use your session(sorry)<br>\n███<br>\n████████<br>\n█████████</p>\n\n<h2 id=\"impact\">Impact</h2>\n\n<p>HackerOneStaff Access, i can read all reports <a href=\"/security\">@security</a> and more program</p>\n", "bounty_amount": "20000.0", "formatted_bounty": "$20,000", "weakness": { "id": 27, "name": "Improper Authentication - Generic" }, "original_report_id": null, "original_report_url": null, "attachments": [], "allow_singular_disclosure_at": "2020-01-02T17:00:12.378Z", "allow_singular_disclosure_after": -14325911.759449996, "singular_disclosure_allowed": true, "vote_count": 1362, "voters": [ "iv1", "physuru", "ri0-", "0xt4144t", "arif_y", "k0z3r0", "a_null", "jukra", "mvalle", "rupeshdubey", "and 1352 more..." ], "severity": { "rating": "high", "score": 8.3, "author_type": "Team", "metrics": { "attack_vector": "network", "attack_complexity": "high", "privileges_required": "none", "user_interaction": "required", "scope": "changed", "confidentiality": "high", "integrity": "high", "availability": "high" } }, "structured_scope": { "databaseId": 3, "asset_type": "URL", "asset_identifier": "https://hackerone.com", "max_severity": "critical" }, "abilities": { "assignable_team_members": [], "assignable_team_member_groups": [] }, "pentest_id": null, "can_edit_custom_fields_attributes": false, "activities": [ { "id": 6390330, "is_internal": false, "editable": false, "type": "Activities::ReportTitleUpdated", "message": "", "markdown_message": "", "automated_response": false, "created_at": "2019-11-24T13:11:26.479Z", "updated_at": "2019-11-26T23:03:52.146Z", "additional_data": { "old_title": "██████████", "new_title": "█████████" }, "actor": { "username": "haxta4ok00", "cleared": false, "url": "/haxta4ok00", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": false, "hackerone_employee": false }, "genius_execution_id": null, "team_handle": "security" }, { "id": 6390338, "is_internal": false, "editable": false, "type": "Activities::Comment", "message": "████████\n█████", "markdown_message": "<p>████████<br>\n█████</p>\n", "automated_response": false, "created_at": "2019-11-24T13:13:46.613Z", "updated_at": "2019-11-26T21:38:00.674Z", "actor": { "username": "haxta4ok00", "cleared": false, "url": "/haxta4ok00", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": false, "hackerone_employee": false }, "genius_execution_id": null, "team_handle": "security" }, { "id": 6390601, "is_internal": false, "editable": false, "type": "Activities::Comment", "message": "i found what is you can edit private program ( for test ) I have not changed anything and not used , all for the sake of hacking", "markdown_message": "<p>i found what is you can edit private program ( for test ) I have not changed anything and not used , all for the sake of hacking</p>\n", "automated_response": false, "created_at": "2019-11-24T14:30:35.449Z", "updated_at": "2019-11-24T14:30:35.449Z", "actor": { "username": "haxta4ok00", "cleared": false, "url": "/haxta4ok00", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": false, "hackerone_employee": false }, "genius_execution_id": null, "team_handle": "security" }, { "id": 6390724, "is_internal": false, "editable": false, "type": "Activities::BugNeedsMoreInfo", "message": "In what report was the token disclosed?\n", "markdown_message": "<p>In what report was the token disclosed?</p>\n", "automated_response": false, "created_at": "2019-11-24T15:08:42.776Z", "updated_at": "2019-11-24T15:08:42.776Z", "actor": { "username": "ktistai", "cleared": false, "url": "/ktistai", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/000/322/520/01cd21dce301646646276fd9125cffd448fbffd6_original.png/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": true, "hackerone_employee": null }, "genius_execution_id": null, "team_handle": "security" }, { "id": 6390739, "is_internal": false, "editable": false, "type": "Activities::BugNew", "message": " █████ here, ██████████", "markdown_message": "<p>█████ here, ██████████</p>\n", "automated_response": false, "created_at": "2019-11-24T15:12:33.419Z", "updated_at": "2019-11-26T23:06:23.131Z", "actor": { "username": "haxta4ok00", "cleared": false, "url": "/haxta4ok00", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": false, "hackerone_employee": false }, "genius_execution_id": null, "team_handle": "security" }, { "id": 6390741, "is_internal": false, "editable": false, "type": "Activities::Comment", "message": "If you need Proof, I can write a message ███.", "markdown_message": "<p>If you need Proof, I can write a message ███.</p>\n", "automated_response": false, "created_at": "2019-11-24T15:13:14.215Z", "updated_at": "2019-11-26T23:06:50.985Z", "actor": { "username": "haxta4ok00", "cleared": false, "url": "/haxta4ok00", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": false, "hackerone_employee": false }, "genius_execution_id": null, "team_handle": "security" }, { "id": 6390742, "is_internal": false, "editable": false, "type": "Activities::BugNeedsMoreInfo", "message": "Can you check if it's still working? ", "markdown_message": "<p>Can you check if it&#39;s still working? </p>\n", "automated_response": false, "created_at": "2019-11-24T15:14:06.181Z", "updated_at": "2019-11-24T15:14:06.181Z", "actor": { "username": "ktistai", "cleared": false, "url": "/ktistai", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/000/322/520/01cd21dce301646646276fd9125cffd448fbffd6_original.png/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": true, "hackerone_employee": null }, "genius_execution_id": null, "team_handle": "security" }, { "id": 6390744, "is_internal": false, "editable": false, "type": "Activities::BugNew", "message": "Fixed, not working", "markdown_message": "<p>Fixed, not working</p>\n", "automated_response": false, "created_at": "2019-11-24T15:15:07.686Z", "updated_at": "2019-11-24T15:15:07.686Z", "actor": { "username": "haxta4ok00", "cleared": false, "url": "/haxta4ok00", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": false, "hackerone_employee": false }, "genius_execution_id": null, "team_handle": "security" }, { "id": 6390753, "is_internal": false, "editable": false, "type": "Activities::Comment", "message": "██████", "markdown_message": "<p>██████</p>\n", "automated_response": false, "created_at": "2019-11-24T15:20:39.111Z", "updated_at": "2019-11-26T23:05:52.866Z", "actor": { "username": "haxta4ok00", "cleared": false, "url": "/haxta4ok00", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": false, "hackerone_employee": false }, "genius_execution_id": null, "team_handle": "security" }, { "id": 6390756, "is_internal": false, "editable": false, "type": "Activities::Comment", "message": "@haxta4ok00 \n\nI asked the appropriate people on how we deal with such reports and as soon as there will be more information, we will let you know. \n\nThanks, \n@ktistai", "markdown_message": "<p><a href=\"/haxta4ok00\">@haxta4ok00</a> </p>\n\n<p>I asked the appropriate people on how we deal with such reports and as soon as there will be more information, we will let you know. </p>\n\n<p>Thanks, <br>\n<a href=\"/ktistai\">@ktistai</a></p>\n", "automated_response": false, "created_at": "2019-11-24T15:21:39.849Z", "updated_at": "2019-11-24T15:21:39.849Z", "actor": { "username": "ktistai", "cleared": false, "url": "/ktistai", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/000/322/520/01cd21dce301646646276fd9125cffd448fbffd6_original.png/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": true, "hackerone_employee": null }, "genius_execution_id": null, "team_handle": "security" }, { "id": 6391025, "is_internal": false, "editable": false, "type": "Activities::Comment", "message": "Hi @haxta4ok00 thanks for reporting this so quickly, we really appreciate it! We're currently looking into the report and appropriate mitigations. If we have any more questions for you we'll reach out to you here. ", "markdown_message": "<p>Hi <a href=\"/haxta4ok00\">@haxta4ok00</a> thanks for reporting this so quickly, we really appreciate it! We&#39;re currently looking into the report and appropriate mitigations. If we have any more questions for you we&#39;ll reach out to you here. </p>\n", "automated_response": false, "created_at": "2019-11-24T17:04:47.056Z", "updated_at": "2019-11-24T17:04:47.056Z", "actor": { "username": "zander", "cleared": false, "url": "/zander", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/Uo6n4mYPr4yDiaaavu7F8GVK/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": false, "hackerone_employee": true }, "genius_execution_id": null, "team_handle": "security" }, { "id": 6391569, "is_internal": false, "editable": false, "type": "Activities::Comment", "message": "Hi @haxta4ok00,\n\nThank you for confirming you no longer have unauthorized access. As part of our investigation, we also want to make sure we have all the relevant information from you to ensure we’re capturing everything, even as we review our own logs / audit records. As such, we would appreciate your answers to a few questions to assist us.\n\n* Are there things outside of the screenshots you provided that you looked at? Specifically, did you review any specific programs, reports, etc.?\n * If so, could you list these programs?\n\n* Did you provide any of this information to other people outside of your report submission?\n\n* Have you made mention of this issue to any other people at all?\n\n* Can you confirm if you took any actions at all outside of viewing data? As in, did you perform any actions (pay bounties, modify program details, add users, etc.)?\n\n* Can you please delete all screenshots, exports, etc. that you may have captured as part of your report submission and send us a confirmation in this report once complete?\n\n* Can you confirm that you have no other copies of vulnerability data that was stored on your computer, such as proxy logs, browser history, and any other screenshots or data exports?\n\n* Lastly, do you have any other questions we can answer for you or important information to share with us related to this report?\n\nAgain, thank you so much for responsibly reporting this issue to us. We really do appreciate it, and we thank you for your assistance with our investigation.", "markdown_message": "<p>Hi <a href=\"/haxta4ok00\">@haxta4ok00</a>,</p>\n\n<p>Thank you for confirming you no longer have unauthorized access. As part of our investigation, we also want to make sure we have all the relevant information from you to ensure we’re capturing everything, even as we review our own logs / audit records. As such, we would appreciate your answers to a few questions to assist us.</p>\n\n<ul>\n<li>\n<p>Are there things outside of the screenshots you provided that you looked at? Specifically, did you review any specific programs, reports, etc.?</p>\n\n<ul>\n<li>If so, could you list these programs?</li>\n</ul>\n</li>\n<li><p>Did you provide any of this information to other people outside of your report submission?</p></li>\n<li><p>Have you made mention of this issue to any other people at all?</p></li>\n<li><p>Can you confirm if you took any actions at all outside of viewing data? As in, did you perform any actions (pay bounties, modify program details, add users, etc.)?</p></li>\n<li><p>Can you please delete all screenshots, exports, etc. that you may have captured as part of your report submission and send us a confirmation in this report once complete?</p></li>\n<li><p>Can you confirm that you have no other copies of vulnerability data that was stored on your computer, such as proxy logs, browser history, and any other screenshots or data exports?</p></li>\n<li><p>Lastly, do you have any other questions we can answer for you or important information to share with us related to this report?</p></li>\n</ul>\n\n<p>Again, thank you so much for responsibly reporting this issue to us. We really do appreciate it, and we thank you for your assistance with our investigation.</p>\n", "automated_response": false, "created_at": "2019-11-24T21:22:33.820Z", "updated_at": "2019-11-24T21:22:33.820Z", "actor": { "username": "reed", "cleared": false, "url": "/reed", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/000/003/132/66d7eadcea16b878bb67bfd697b9542250a801a7_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": false, "hackerone_employee": true }, "genius_execution_id": null, "team_handle": "security" }, { "id": 6391605, "is_internal": false, "editable": false, "type": "Activities::Comment", "message": " Hi @reed \n\n* Are there things outside of the screenshots you provided that you looked at? Specifically, did you review any specific programs, reports, etc.? If so, could you list these programs?\n\n>No, only screenshots , Yes ███ and some programs to see the access rights of this account(I do not remember the name, sorry) (Exclusively for white hacks)\n\n* Did you provide any of this information to other people outside of your report submission?\n\n>No\n\n* Have you made mention of this issue to any other people at all?\n\n>No \n\n* Can you confirm if you took any actions at all outside of viewing data? As in, did you perform any actions (pay bounties, modify program details, add users, etc.)?\n\n>No , Did not do any actions, did not add participants and did not pay remuneration. Only read-only .\n\n* Can you please delete all screenshots, exports, etc. that you may have captured as part of your report submission and send us a confirmation in this report once complete?\n\n>Only was screenshots, I didn't export the reports. I don't quite understand how I can prove to you that I deleted all the screenshots ? I will of course remove them as you ask\n\n* Can you confirm that you have no other copies of vulnerability data that was stored on your computer, such as proxy logs, browser history, and any other screenshots or data exports?\n\n>Again. I do not know how to prove it to you, but they are not present, I did not make copies and export reports\n\n* Lastly, do you have any other questions we can answer for you or important information to share with us related to this report?\n\n>On this moment until nope. But I wonder, ██████████?\n\nThanks for the answer and this report only white hacks \nSorry i bad speak english\nI hope you understand me\nThank you,haxta4ok00", "markdown_message": "<p>Hi <a href=\"/reed\">@reed</a> </p>\n\n<ul>\n<li>Are there things outside of the screenshots you provided that you looked at? Specifically, did you review any specific programs, reports, etc.? If so, could you list these programs?</li>\n</ul>\n\n<blockquote>\n<p>No, only screenshots , Yes ███ and some programs to see the access rights of this account(I do not remember the name, sorry) (Exclusively for white hacks)</p>\n</blockquote>\n\n<ul>\n<li>Did you provide any of this information to other people outside of your report submission?</li>\n</ul>\n\n<blockquote>\n<p>No</p>\n</blockquote>\n\n<ul>\n<li>Have you made mention of this issue to any other people at all?</li>\n</ul>\n\n<blockquote>\n<p>No </p>\n</blockquote>\n\n<ul>\n<li>Can you confirm if you took any actions at all outside of viewing data? As in, did you perform any actions (pay bounties, modify program details, add users, etc.)?</li>\n</ul>\n\n<blockquote>\n<p>No , Did not do any actions, did not add participants and did not pay remuneration. Only read-only .</p>\n</blockquote>\n\n<ul>\n<li>Can you please delete all screenshots, exports, etc. that you may have captured as part of your report submission and send us a confirmation in this report once complete?</li>\n</ul>\n\n<blockquote>\n<p>Only was screenshots, I didn&#39;t export the reports. I don&#39;t quite understand how I can prove to you that I deleted all the screenshots ? I will of course remove them as you ask</p>\n</blockquote>\n\n<ul>\n<li>Can you confirm that you have no other copies of vulnerability data that was stored on your computer, such as proxy logs, browser history, and any other screenshots or data exports?</li>\n</ul>\n\n<blockquote>\n<p>Again. I do not know how to prove it to you, but they are not present, I did not make copies and export reports</p>\n</blockquote>\n\n<ul>\n<li>Lastly, do you have any other questions we can answer for you or important information to share with us related to this report?</li>\n</ul>\n\n<blockquote>\n<p>On this moment until nope. But I wonder, ██████████?</p>\n</blockquote>\n\n<p>Thanks for the answer and this report only white hacks <br>\nSorry i bad speak english<br>\nI hope you understand me<br>\nThank you,haxta4ok00</p>\n", "automated_response": false, "created_at": "2019-11-24T21:53:21.608Z", "updated_at": "2019-11-26T23:08:18.238Z", "actor": { "username": "haxta4ok00", "cleared": false, "url": "/haxta4ok00", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": false, "hackerone_employee": false }, "genius_execution_id": null, "team_handle": "security" }, { "id": 6391652, "is_internal": false, "editable": false, "type": "Activities::Comment", "message": "Hi @haxta4ok00,\n\nMuch appreciated for the responses. Especially thank you for confirming your removal of all screenshots and other data you may have downloaded as part of your report submission.\n\nWe can confirm that ██████ uses 2FA via SAML. That is, the built-in HackerOne 2FA functionality is not used, as our identity provider handles 2FA itself. Authentication to the HackerOne Platform is federated from our identity provider to HackerOne via SAML.\n\nAgain, thanks for reporting this to us. We'll be in touch soon on next steps.", "markdown_message": "<p>Hi <a href=\"/haxta4ok00\">@haxta4ok00</a>,</p>\n\n<p>Much appreciated for the responses. Especially thank you for confirming your removal of all screenshots and other data you may have downloaded as part of your report submission.</p>\n\n<p>We can confirm that ██████ uses 2FA via SAML. That is, the built-in HackerOne 2FA functionality is not used, as our identity provider handles 2FA itself. Authentication to the HackerOne Platform is federated from our identity provider to HackerOne via SAML.</p>\n\n<p>Again, thanks for reporting this to us. We&#39;ll be in touch soon on next steps.</p>\n", "automated_response": false, "created_at": "2019-11-24T22:33:44.797Z", "updated_at": "2019-11-26T23:09:01.122Z", "actor": { "username": "reed", "cleared": false, "url": "/reed", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/000/003/132/66d7eadcea16b878bb67bfd697b9542250a801a7_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": false, "hackerone_employee": true }, "genius_execution_id": null, "team_handle": "security" }, { "id": 6391654, "is_internal": false, "editable": false, "type": "Activities::Comment", "message": "Hi @reed -- Thanks for answer", "markdown_message": "<p>Hi <a href=\"/reed\">@reed</a> -- Thanks for answer</p>\n", "automated_response": false, "created_at": "2019-11-24T22:35:06.445Z", "updated_at": "2019-11-24T22:35:06.445Z", "actor": { "username": "haxta4ok00", "cleared": false, "url": "/haxta4ok00", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": false, "hackerone_employee": false }, "genius_execution_id": null, "team_handle": "security" }, { "id": 6391736, "is_internal": false, "editable": false, "type": "Activities::ChangedScope", "message": "", "markdown_message": "", "automated_response": false, "created_at": "2019-11-24T23:59:19.098Z", "updated_at": "2019-11-24T23:59:19.098Z", "actor": { "username": "jobert", "cleared": true, "url": "/jobert", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/ht4b9SmcYNqmpbyCFXd7cxHB/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": false, "hackerone_employee": true }, "old_scope": "None", "new_scope": "https://hackerone.com", "genius_execution_id": null, "team_handle": "security" }, { "id": 6391766, "is_internal": false, "editable": false, "type": "Activities::ReportSeverityUpdated", "message": "", "markdown_message": "", "automated_response": false, "created_at": "2019-11-25T00:22:42.098Z", "updated_at": "2019-11-25T00:22:42.098Z", "additional_data": { "old_severity": "Critical", "new_severity": "High (8.3)" }, "actor": { "username": "jobert", "cleared": true, "url": "/jobert", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/ht4b9SmcYNqmpbyCFXd7cxHB/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": false, "hackerone_employee": true }, "genius_execution_id": null, "team_handle": "security" }, { "id": 6391767, "is_internal": false, "editable": false, "type": "Activities::Comment", "message": "Hi @haxta4ok00 - thanks again for bringing this to our attention. We’re still actively working on this, primarily preparing communications to affected customers and a root cause analysis. As part of that, we’re updating the severity according to the impact of the vulnerability. At this point, we have not made a decision on the bounty amount, and it may be different from what our bounty table indicates. See below for our reasoning behind the corrected severity, which with the environmental score of the affected asset, brings the CVSS to 8.3 (High).\n\n**Attack Vector: Network** - The vulnerability was exploitable from anywhere in case the attacker had a copy of an active session cookie.\n\n**Attack Complexity: High** - The semi-feasible attack scenario is for a HackerOne employee to share an active session cookie. Carrying this out is beyond an attacker’s control, which is why the Attack Complexity to High.\n\n**Privileges Required: None** - The attacker does not need to be authenticated to exploit the vulnerability.\n\n**User Interaction: Required** - The victim needs to share the session cookie, making User Interaction Required for the vulnerability to be exploited.\n\n**Scope: Changed** - Due to the nature of the data that could’ve been accessed, systems other than hackerone.com may be accessible. Scope includes any customer assets because of the vulnerability information that could have been accessed.\n\n**Confidentiality: High** - Vulnerability information could be accessed when the attacker has an active session cookie of the HackerOne employee. Any security vulnerability that affects vulnerability information automatically bumps Confidentiality to High.\n\n**Integrity: High** - The HackerOne employee had sufficient privileges to make updates to programs they were managing, causing Impact to being set to High.\n\n**Availability: High** - Due to the HackerOne employee’s permissions, they could suspend submissions for a number of HackerOne customers. Although this technically doesn’t affect the availability of the platform, the team ended up going with a High impact because submissions are a business critical process on the platform.", "markdown_message": "<p>Hi <a href=\"/haxta4ok00\">@haxta4ok00</a> - thanks again for bringing this to our attention. We’re still actively working on this, primarily preparing communications to affected customers and a root cause analysis. As part of that, we’re updating the severity according to the impact of the vulnerability. At this point, we have not made a decision on the bounty amount, and it may be different from what our bounty table indicates. See below for our reasoning behind the corrected severity, which with the environmental score of the affected asset, brings the CVSS to 8.3 (High).</p>\n\n<p><strong>Attack Vector: Network</strong> - The vulnerability was exploitable from anywhere in case the attacker had a copy of an active session cookie.</p>\n\n<p><strong>Attack Complexity: High</strong> - The semi-feasible attack scenario is for a HackerOne employee to share an active session cookie. Carrying this out is beyond an attacker’s control, which is why the Attack Complexity to High.</p>\n\n<p><strong>Privileges Required: None</strong> - The attacker does not need to be authenticated to exploit the vulnerability.</p>\n\n<p><strong>User Interaction: Required</strong> - The victim needs to share the session cookie, making User Interaction Required for the vulnerability to be exploited.</p>\n\n<p><strong>Scope: Changed</strong> - Due to the nature of the data that could’ve been accessed, systems other than hackerone.com may be accessible. Scope includes any customer assets because of the vulnerability information that could have been accessed.</p>\n\n<p><strong>Confidentiality: High</strong> - Vulnerability information could be accessed when the attacker has an active session cookie of the HackerOne employee. Any security vulnerability that affects vulnerability information automatically bumps Confidentiality to High.</p>\n\n<p><strong>Integrity: High</strong> - The HackerOne employee had sufficient privileges to make updates to programs they were managing, causing Impact to being set to High.</p>\n\n<p><strong>Availability: High</strong> - Due to the HackerOne employee’s permissions, they could suspend submissions for a number of HackerOne customers. Although this technically doesn’t affect the availability of the platform, the team ended up going with a High impact because submissions are a business critical process on the platform.</p>\n", "automated_response": false, "created_at": "2019-11-25T00:22:55.702Z", "updated_at": "2019-11-25T00:22:55.702Z", "actor": { "username": "jobert", "cleared": true, "url": "/jobert", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/ht4b9SmcYNqmpbyCFXd7cxHB/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": false, "hackerone_employee": true }, "genius_execution_id": null, "team_handle": "security" }, { "id": 6391773, "is_internal": false, "editable": false, "type": "Activities::Comment", "message": "Hi @jobert -- You may be right about CVSS, but aren't actions on behalf of H1Staff critical. For example, read reports, add members to private programs, send bounties, etc.?", "markdown_message": "<p>Hi <a href=\"/jobert\">@jobert</a> -- You may be right about CVSS, but aren&#39;t actions on behalf of H1Staff critical. For example, read reports, add members to private programs, send bounties, etc.?</p>\n", "automated_response": false, "created_at": "2019-11-25T00:30:31.231Z", "updated_at": "2019-11-25T00:30:31.231Z", "actor": { "username": "haxta4ok00", "cleared": false, "url": "/haxta4ok00", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": false, "hackerone_employee": false }, "genius_execution_id": null, "team_handle": "security" }, { "id": 6391778, "is_internal": false, "editable": false, "type": "Activities::Comment", "message": "Hi @haxta4ok00 - yup, but that's subjective. We've updated CVSS to capture the objective measurement of impact of the vulnerability. The business impact, which is subjective to some extend, will be discussed when we decide on a bounty amount. Thanks for your understanding and patience!", "markdown_message": "<p>Hi <a href=\"/haxta4ok00\">@haxta4ok00</a> - yup, but that&#39;s subjective. We&#39;ve updated CVSS to capture the objective measurement of impact of the vulnerability. The business impact, which is subjective to some extend, will be discussed when we decide on a bounty amount. Thanks for your understanding and patience!</p>\n", "automated_response": false, "created_at": "2019-11-25T00:37:03.130Z", "updated_at": "2019-11-25T00:37:03.130Z", "actor": { "username": "jobert", "cleared": true, "url": "/jobert", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/ht4b9SmcYNqmpbyCFXd7cxHB/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": false, "hackerone_employee": true }, "genius_execution_id": null, "team_handle": "security" }, { "id": 6391782, "is_internal": false, "editable": false, "type": "Activities::Comment", "message": "@jobert Thanks for the answer", "markdown_message": "<p><a href=\"/jobert\">@jobert</a> Thanks for the answer</p>\n", "automated_response": false, "created_at": "2019-11-25T00:38:13.689Z", "updated_at": "2019-11-25T00:38:13.689Z", "actor": { "username": "haxta4ok00", "cleared": false, "url": "/haxta4ok00", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": false, "hackerone_employee": false }, "genius_execution_id": null, "team_handle": "security" }, { "id": 6391827, "is_internal": false, "editable": false, "type": "Activities::ReportTitleUpdated", "message": "", "markdown_message": "", "automated_response": false, "created_at": "2019-11-25T01:00:19.901Z", "updated_at": "2019-11-26T23:03:31.310Z", "additional_data": { "old_title": "█████████", "new_title": "Account takeover via leaked session token" }, "actor": { "username": "bencode", "cleared": false, "url": "/bencode", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/000/013/117/ddaa1da4e004e1234c6857c42f9bfa8df85b5ccf_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": false, "hackerone_employee": true }, "genius_execution_id": null, "team_handle": "security" }, { "id": 6401007, "is_internal": false, "editable": false, "type": "Activities::BugTriaged", "message": "Hi @haxta4ok00 - we're moving this to triaged so it's easier for us to track. Last night, we've sent customer notifications about the data that was accessed by you. We'll keep you posted throughout the process. Thanks for being so responsive throughout the process so far, it's much appreciated.", "markdown_message": "<p>Hi <a href=\"/haxta4ok00\">@haxta4ok00</a> - we&#39;re moving this to triaged so it&#39;s easier for us to track. Last night, we&#39;ve sent customer notifications about the data that was accessed by you. We&#39;ll keep you posted throughout the process. Thanks for being so responsive throughout the process so far, it&#39;s much appreciated.</p>\n", "automated_response": false, "created_at": "2019-11-25T17:25:07.923Z", "updated_at": "2019-11-25T17:25:07.923Z", "actor": { "username": "jobert", "cleared": true, "url": "/jobert", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/ht4b9SmcYNqmpbyCFXd7cxHB/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": false, "hackerone_employee": true }, "genius_execution_id": null, "team_handle": "security" }, { "id": 6401164, "is_internal": false, "editable": false, "type": "Activities::Comment", "message": "Hi @jobert-- thanks for the answer", "markdown_message": "<p>Hi <a href=\"/jobert--\">@jobert--</a> thanks for the answer</p>\n", "automated_response": false, "created_at": "2019-11-25T17:52:59.114Z", "updated_at": "2019-11-25T17:52:59.114Z", "actor": { "username": "haxta4ok00", "cleared": false, "url": "/haxta4ok00", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": false, "hackerone_employee": false }, "genius_execution_id": null, "team_handle": "security" }, { "id": 6402403, "is_internal": false, "editable": false, "type": "Activities::Comment", "message": "Hi @haxta4ok00 - something came up that we hadn't asked you yet. We didn't find it necessary for you to have opened all the reports and pages in order to validate you had access to the account. Would you mind explaining why you did so to us? Thanks!", "markdown_message": "<p>Hi <a href=\"/haxta4ok00\">@haxta4ok00</a> - something came up that we hadn&#39;t asked you yet. We didn&#39;t find it necessary for you to have opened all the reports and pages in order to validate you had access to the account. Would you mind explaining why you did so to us? Thanks!</p>\n", "automated_response": false, "created_at": "2019-11-25T18:57:35.495Z", "updated_at": "2019-11-25T18:57:35.495Z", "actor": { "username": "jobert", "cleared": true, "url": "/jobert", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/ht4b9SmcYNqmpbyCFXd7cxHB/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": false, "hackerone_employee": true }, "genius_execution_id": null, "team_handle": "security" }, { "id": 6402721, "is_internal": false, "editable": false, "type": "Activities::Comment", "message": "Hi @jobert -- I did it to show the impact. I didn't mean any harm by it.I reported it to you at once. I was not sure that after the token substitution I would own all the rights.\n\nI apologize if I did anything wrong. But it was just a white hack", "markdown_message": "<p>Hi <a href=\"/jobert\">@jobert</a> -- I did it to show the impact. I didn&#39;t mean any harm by it.I reported it to you at once. I was not sure that after the token substitution I would own all the rights.</p>\n\n<p>I apologize if I did anything wrong. But it was just a white hack</p>\n", "automated_response": false, "created_at": "2019-11-25T19:21:04.094Z", "updated_at": "2019-11-25T19:21:04.094Z", "actor": { "username": "haxta4ok00", "cleared": false, "url": "/haxta4ok00", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": false, "hackerone_employee": false }, "genius_execution_id": null, "team_handle": "security" }, { "id": 6405556, "is_internal": false, "editable": false, "type": "Activities::ReportTitleUpdated", "message": "", "markdown_message": "", "automated_response": false, "created_at": "2019-11-25T23:51:15.792Z", "updated_at": "2019-11-25T23:51:15.792Z", "additional_data": { "old_title": "Account takeover via leaked session token", "new_title": "Account takeover via leaked session cookie" }, "actor": { "username": "reed", "cleared": false, "url": "/reed", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/000/003/132/66d7eadcea16b878bb67bfd697b9542250a801a7_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": false, "hackerone_employee": true }, "genius_execution_id": null, "team_handle": "security" }, { "id": 6411489, "is_internal": false, "editable": false, "type": "Activities::Comment", "message": "Hi @jober , @reed , @bencode , @zander -- May I add one remark for you?", "markdown_message": "<p>Hi <a href=\"/jober\">@jober</a> , <a href=\"/reed\">@reed</a> , <a href=\"/bencode\">@bencode</a> , <a href=\"/zander\">@zander</a> -- May I add one remark for you?</p>\n", "automated_response": false, "created_at": "2019-11-26T13:32:57.293Z", "updated_at": "2019-11-26T13:32:57.293Z", "actor": { "username": "haxta4ok00", "cleared": false, "url": "/haxta4ok00", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": false, "hackerone_employee": false }, "genius_execution_id": null, "team_handle": "security" }, { "id": 6414341, "is_internal": false, "editable": false, "type": "Activities::Comment", "message": "Hi @haxta4ok00 - of course, go for it! No need to ask.", "markdown_message": "<p>Hi <a href=\"/haxta4ok00\">@haxta4ok00</a> - of course, go for it! No need to ask.</p>\n", "automated_response": false, "created_at": "2019-11-26T17:55:22.496Z", "updated_at": "2019-11-26T17:55:22.496Z", "actor": { "username": "jobert", "cleared": true, "url": "/jobert", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/ht4b9SmcYNqmpbyCFXd7cxHB/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": false, "hackerone_employee": true }, "genius_execution_id": null, "team_handle": "security" }, { "id": 6414443, "is_internal": false, "editable": false, "type": "Activities::Comment", "message": "Hi @jobert -- thanks for the answer!\n\n* Three years ago I mentioned such an attack, but it was theoretical and I was not listened to( here #163381 I wrote `in theory find this in the future`). If this will help the I am systemic moderator on one of forums on security. And we protected ourselves from such attacks by binding the session to the IP address at the entrance. We also made basic authorization for access to private sections. Perhaps this will help you.\n\n* I understand, that saw data which should not was see, but this was only hack interest in white purposes, I wanted to watch and show you to prejudice consequence of this can lead ( I've always been taught to write the full impact that can be) . It was a happy white hacking for me.\n\n* Please do not scold █████ he's one of the best staff that help to hackerone\n\nAnd sorry if I that the poorly translated, hope you me will understand. Thanks @jobert again.", "markdown_message": "<p>Hi <a href=\"/jobert\">@jobert</a> -- thanks for the answer!</p>\n\n<ul>\n<li><p>Three years ago I mentioned such an attack, but it was theoretical and I was not listened to( here <a href=\"/reports/163381\">#163381</a> I wrote <code>in theory find this in the future</code>). If this will help the I am systemic moderator on one of forums on security. And we protected ourselves from such attacks by binding the session to the IP address at the entrance. We also made basic authorization for access to private sections. Perhaps this will help you.</p></li>\n<li><p>I understand, that saw data which should not was see, but this was only hack interest in white purposes, I wanted to watch and show you to prejudice consequence of this can lead ( I&#39;ve always been taught to write the full impact that can be) . It was a happy white hacking for me.</p></li>\n<li><p>Please do not scold █████ he&#39;s one of the best staff that help to hackerone</p></li>\n</ul>\n\n<p>And sorry if I that the poorly translated, hope you me will understand. Thanks <a href=\"/jobert\">@jobert</a> again.</p>\n", "automated_response": false, "created_at": "2019-11-26T18:12:12.946Z", "updated_at": "2019-11-26T23:12:12.074Z", "actor": { "username": "haxta4ok00", "cleared": false, "url": "/haxta4ok00", "profile_picture_urls": { "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5" }, "hackerone_triager": false, "hackerone_employee": false }, "genius_execution_id": null, "team_handle": "security" }, { "id": 6414854, "is_internal": false, "editable": false, "type": "Activities::Comment", "message": "Hi @haxta4ok00 - thanks for that, it's much appreciated. No need to worry about ██████████ this was a human error that could've happened to anyone. There won't be any consequences for them. This became a bigger incident due to the amount of data that you accessed, not because it happened in the first place.\n\nAs for your first remark: yesterday we've released an update that limits HackerOne employees and HackerOne Security Analyst sessions to the IP address that they've started the session with. This would've prevented the incident. We're postponing the rollout to all users due to people having legitimate use cases for using multiple IP addresses (e.g. ISPs with DHCP). We're also planning to roll out a number of smaller changes, such as warning the user when a comment seems to contain sensitive information and clarification in