Possible LDAP username and password disclosed on Github
Medium
Vulnerability Details
## Summary
The file hosted at https://github.com/mlanin/go/blob/3dbd856c3f542c54e512a295ac498c79cd952ed6/.env.testing contains the following information:
**LDAP_DOMAIN=███
LDAP_BASE_DN=███
LDAP_ADMIN_USER=███████
LDAP_ADMIN_PASSWORD=██████**
## Recommendations
Verify if credentials are still in use if so remove the file from GitHub and reset passwords.
## NOTE
Please let me self-close this report if the credentials do not belong to Acronis or are not active. I took a better safe than sorry approach.
## Impact
Although I was not able to find any port open on the ███████ server, if the credentials are valid they can be used by insider threats for lateral movement and privilege escalation.
Actions
View on HackerOneReport Stats
- Report ID: 1004412
- State: Closed
- Substate: resolved
- Upvotes: 35