Amazon Bucket Accessible (http://inpref.s3.amazonaws.com/)
Unknown
Vulnerability Details
Searching through the source code of your homepage shows a few http://inpref.s3.amazonaws.com/ URLS.
I assume that you own this s3 Amazon bucket.
The problem here is, visiting that amazon bucket on a browser will shows the files on the bucket, whilst a secure bucket would bring up an access denied page. I have attached Screenshots showing Hackerone's bucket compared to your bucket to show you what a secure bucket looks like and where the bucket is being used in your source code.
Actions
View on HackerOneReport Stats
- Report ID: 137487
- State: Closed
- Substate: resolved
- Upvotes: 3