Loading HuntDB...

Deprecated Hacker101 coursework repository mentions Heroku App that is susceptible to takeover

None
H
HackerOne
Submitted None
Reported by m7mdharoun

Vulnerability Details

Technical details and impact analysis

Externally Controlled Reference to a Resource in Another Sphere
Hi , I'm sure this repo on GitHub `https://github.com/Hacker0x01` belong to `Hackerone,inc`. I've found that your docs on it mention a Heroku app `breaker101.herokuapp.com ` which is no longer work and I could takeover it via HeroKu. >Suggested Fix : Remove this app name from your docs or I can remove it from my apps to added it back to your account #`Poc :` http://breaker101.herokuapp.com >Repo https://github.com/Hacker0x01/Hacker101Coursework/blob/master/gae/static/report47.md {F450943} ## Impact >New Researchers can be scammed by this app

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$500.00

Submitted

Weakness

Externally Controlled Reference to a Resource in Another Sphere