proxy port 7000 and shell port 514 not filtered

Disclosed: 2016-02-20 12:12:01 By bulla To gratipay
None
Vulnerability Details
port 7000 on assets.gratipay.com was found to be open to the public. The port seems to be working on a proxy module of nginx and i was able to connect to ot by configuring my browser to use it as a proxy. also port 514 is also found to be open and connection to it via rlogin succeeds although no substantial data is revealed. These ports may reveal internal architecture of application and can be use to communicate to internal d=network of the server, hence should be filtered from direct interation
Actions
View on HackerOne
Report Stats
  • Report ID: 116618
  • State: Closed
  • Substate: informative
Share this report