Loading HuntDB...

Slack token leaking in stackoverflow and devtimes

Medium
S
Shipt
Submitted None

Team Summary

Official summary from Shipt

A Shipt employee inadvertently posted a Slack Webhook URI including the authentication token on two public tech forums: Stackoverflow.com and devtimes.com. While this incoming webhook's configuration was restricted to posting in a single channel (created for testing this application) and only 2 Shipt users were in this channel, this allowed the researcher to enumerate those 2 users and post unauthorized messages as the bot associated with the Webhook. Upon receiving the report, Shipt 's security team immediately invalidated the Webhook.

Reported by streaak

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$300.00

Submitted

Weakness

Cleartext Storage of Sensitive Information