Amazon Bucket Accessible (http://inpref.s3.amazonaws.com/)

Disclosed: 2016-05-12 21:43:22 By xmly To localtapiola
Unknown
Vulnerability Details
Searching through the source code of your homepage shows a few http://inpref.s3.amazonaws.com/ URLS. I assume that you own this s3 Amazon bucket. The problem here is, visiting that amazon bucket on a browser will shows the files on the bucket, whilst a secure bucket would bring up an access denied page. I have attached Screenshots showing Hackerone's bucket compared to your bucket to show you what a secure bucket looks like and where the bucket is being used in your source code.
Actions
View on HackerOne
Report Stats
  • Report ID: 137487
  • State: Closed
  • Substate: resolved
  • Upvotes: 3
Share this report