Deprecated Hacker101 coursework repository mentions Heroku App that is susceptible to takeover
None
H
HackerOne
Submitted None
Actions:
Reported by
m7mdharoun
Vulnerability Details
Technical details and impact analysis
Hi ,
I'm sure this repo on GitHub `https://github.com/Hacker0x01` belong to `Hackerone,inc`. I've found that your docs on it mention a Heroku app `breaker101.herokuapp.com
` which is no longer work and I could takeover it via HeroKu.
>Suggested Fix :
Remove this app name from your docs or I can remove it from my apps to added it back to your account
#`Poc :`
http://breaker101.herokuapp.com
>Repo https://github.com/Hacker0x01/Hacker101Coursework/blob/master/gae/static/report47.md
{F450943}
## Impact
>New Researchers can be scammed by this app
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$500.00
Submitted
Weakness
Externally Controlled Reference to a Resource in Another Sphere