Exposed proxy allows to access internal reddit domains

Disclosed: 2025-02-24 15:03:45 By la_revoltage To reddit
High
Vulnerability Details
## Summary: Proxy at https://52.90.28.77:30920 allows to access internal domains ## Steps To Reproduce: To reproduce, simply use this curl command ``` curl --insecure https://52.90.28.77:30920/reddit --header "Host: █████████" ``` ## Supporting Material snoo.dev is obviously an internal domains used by employees: https://search.censys.io/search?resource=certificates&q=snoo.dev It is also references in the GitHub a few times: https://github.com/search?q=org%3Areddit%20snoo.dev&type=code ## Impact Attacker can access internal domains
Actions
View on HackerOne
Report Stats
  • Report ID: 2967634
  • State: Closed
  • Substate: resolved
  • Upvotes: 5
Share this report