Possible LDAP username and password disclosed on Github
Medium
A
Acronis
Submitted None
Actions:
Reported by
vovohelo
Vulnerability Details
Technical details and impact analysis
## Summary
The file hosted at https://github.com/mlanin/go/blob/3dbd856c3f542c54e512a295ac498c79cd952ed6/.env.testing contains the following information:
**LDAP_DOMAIN=███
LDAP_BASE_DN=███
LDAP_ADMIN_USER=███████
LDAP_ADMIN_PASSWORD=██████**
## Recommendations
Verify if credentials are still in use if so remove the file from GitHub and reset passwords.
## NOTE
Please let me self-close this report if the credentials do not belong to Acronis or are not active. I took a better safe than sorry approach.
## Impact
Although I was not able to find any port open on the ███████ server, if the credentials are valid they can be used by insider threats for lateral movement and privilege escalation.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Information Disclosure