sensitive data exposure

Disclosed: 2022-11-10 14:41:12 By saibalaji143_ To reddit
High
Vulnerability Details
## Summary: [A Password hash entry was found in /etc/passwd. This is a major vulnerability since /etc/passwd is a world-readable file by default. Once the password hash is found, an attacker may extract the password using a program like crack.] ## Impact: it is high impact vulnerability .once hacker found password hash it may be leads to develop a program like crack ## Steps To Reproduce: [https://www.reddit.com/etc%2fpasswd] 1. [add step] 1. [add step] 1. [add step] ## Supporting Material/References: [list any additional material (e.g. screenshots, logs, etc.)] * [attachment / reference] ## Impact A Password hash entry was found in /etc/passwd. This is a major vulnerability since /etc/passwd is a world-readable file by default. Once the password hash is found, an attacker may extract the password using a program like crack.
Actions
View on HackerOne
Report Stats
  • Report ID: 1716249
  • State: Closed
  • Substate: not-applicable
  • Upvotes: 3
Share this report