Twitter Broken Link in https://gener8ads.com (Hackerone Profile)
Low
G
Gener8
Submitted None
Actions:
Reported by
0ctopu3
Vulnerability Details
Technical details and impact analysis
## Summary:
Gener8 has an unclaimed broken Twitter link on their Hackerone Profile which can be claimed by any malicious user. And then later the malicious user can exploit this issue to deceive new researchers to submit their legitimate findings to the wrong hands.
## Steps To Reproduce:
[add details for how we can reproduce the issue]
1.Visit Gener8 Profile On Hackerone.
2.There you see that Gener8 has website and Twitter account are mentioned.
3.Click on the Twitter account, you will redirected to twitter account which i have been hijacked
4.Anyone could claim this username and broken link could be hijacked
5.So, I've impersonated your identity by forming a fake account named on that link. Here just for the PoC purpose, I've taken over that broken link by making an account with that username and added some context to show what impact can be made. Also, I'll surely release that username after your response.
## Supporting Material/References:
[list any additional material (e.g. screenshots, logs, etc.)]
* [attachment / reference]
## Impact
New researchers can be further deceived if they clicked on that hijacked link.
For Example a specific case might be: A malicious user can create a fake account on that broken redirection link and can deceive researchers arriving on that link. For example, the attacker can ask the researcher to submit his report to him first and if he approves, then only he can submit it to your official page. In this way, it can cause huge damage to your company if a report is critical in any case.
Here I've shown a sample impact by adding some info in that impersonated account.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved