Deprecated Hacker101 coursework repository mentions Heroku App that is susceptible to takeover

Disclosed: 2019-04-04 19:41:54 By m7mdharoun To security
None
Vulnerability Details
Hi , I'm sure this repo on GitHub `https://github.com/Hacker0x01` belong to `Hackerone,inc`. I've found that your docs on it mention a Heroku app `breaker101.herokuapp.com ` which is no longer work and I could takeover it via HeroKu. >Suggested Fix : Remove this app name from your docs or I can remove it from my apps to added it back to your account #`Poc :` http://breaker101.herokuapp.com >Repo https://github.com/Hacker0x01/Hacker101Coursework/blob/master/gae/static/report47.md {F450943} ## Impact >New Researchers can be scammed by this app
Actions
View on HackerOne
Report Stats
  • Report ID: 514451
  • State: Closed
  • Substate: resolved
  • Upvotes: 68
Share this report