Production Key and Data Found on Subdomain No Longer Operated by Shopify / Dangling DNS

Disclosed: 2024-05-01 18:17:15 By ryanmoles6 To shopify
None
Vulnerability Details
Hello, Shopify team. I found the subdomain in http://honeybee-honeybee-ingress-data-presto-us-central1-2.shopify-data-presto-global.shopifykloud.com/languages I was allowed to view the source code of the app's configuration (I'm not really sure), he used base64 to encode the source file, I decrypted it through a third party and found a lot of source code, even including, some content that should not be on the internet, for this I recorded a demo video where I will show how I decrypted and retrieved sensitive information within the site I didn't look at all the source code, I found one place where I could prove the harm ''' SCAN {"name":"main/settings.py ███ # SECURITY WARNING: keep the secret key used in production secret! SECRET_KEY = '███' ''' ## Impact Key compromise can cause takeover, or direct operation of the production environment
Actions
View on HackerOne
Report Stats
  • Report ID: 1590115
  • State: Closed
  • Substate: resolved
  • Upvotes: 31
Share this report