Production Key and Data Found on Subdomain No Longer Operated by Shopify / Dangling DNS
None
Vulnerability Details
Hello, Shopify team.
I found the subdomain in
http://honeybee-honeybee-ingress-data-presto-us-central1-2.shopify-data-presto-global.shopifykloud.com/languages
I was allowed to view the source code of the app's configuration (I'm not really sure), he used base64 to encode the source file, I decrypted it through a third party and found a lot of source code, even including, some content that should not be on the internet, for this I recorded a demo video where I will show how I decrypted and retrieved sensitive information within the site
I didn't look at all the source code, I found one place where I could prove the harm
'''
SCAN
{"name":"main/settings.py
███
# SECURITY WARNING: keep the secret key used in production secret!
SECRET_KEY = '███'
'''
## Impact
Key compromise can cause takeover, or direct operation of the production environment
Actions
View on HackerOneReport Stats
- Report ID: 1590115
- State: Closed
- Substate: resolved
- Upvotes: 31