Disclosure of ip addresses in local network of uber

Disclosed: 2016-06-13 22:22:56 By laps-forever To uber
Unknown
Vulnerability Details
Hi, i have found several DNS records at Google DNS server 8.8.8.8 pointing to Uber local servers: ``` ▶ nslookup logs.uber.com Server: 8.8.8.8 Address: 8.8.8.8#53 Non-authoritative answer: Name: logs.uber.com Address: 10.6.0.1 ``` ``` ▶ nslookup kerberos.uber.com Server: 8.8.8.8 Address: 8.8.8.8#53 Non-authoritative answer: Name: kerberos.uber.com Address: 10.6.0.74 ``` ``` ▶ nslookup ldap.uber.com Server: 8.8.8.8 Address: 8.8.8.8#53 Non-authoritative answer: Name: ldap.uber.com Address: 10.30.14.3 ``` This information could be used, if attacker gets SSRF,XXE,LFI etc in order to address local network of Uber.
Actions
View on HackerOne
Report Stats
  • Report ID: 126569
  • State: Closed
  • Substate: informative
  • Upvotes: 2
Share this report