Information Disclosure through .DS_Store in ██████████
X
X (Formerly Twitter)
Submitted None
Actions:
Reported by
lewerkun
Vulnerability Details
Technical details and impact analysis
Hello!
Description:
The website located at █████████ suffers from an information disclosure through ".DS_Store" file, accessible to unauthorised external users.
In the Apple OS X operating system, .DS_Store is a file that stores custom attributes of its containing folder.
Reproduction Steps:
Guide for installing DS_Store parser - https://digi.ninja/projects/fdb.php
First link: (See pic 0 and 1)
███████.DS_Store
Second link: (See pic 2 and 3)
████Packages/.DS_Store
This directory contain tons of packages for MacOS
Including licence keys (See pic 4 and 5)
██████████Packages/█████████
██████████Packages/████
and etc
Certificate for WIFI (See pic 6)
█████████Packages/█████
Twitter Root certificate (See pic 8)
█████████Packages/███████
And other juicy stuff which is intended only for Twitter employees
Third link (See pic 7)
██████████Scripts/.DS_Store
This directory contain tons of scripts for installation and configuring corporate computers.
In one case the attacker can just use Twitter licenses and etc (for obvious reasons, I didn't check whether this licences is still active ), in other this information can be useful for future attacks.
Please let me know if you need some extra information.
Thanks in advance!
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$560.00
Submitted
Weakness
Information Disclosure