Loading HuntDB...

Multiple Information Disclosure with Go PPROF on api-ne.mackeeper.com

Low
C
Clario
Submitted None

Team Summary

Official summary from Clario

## Summary Multiple Information Disclosure with Go PPROF on `api-ne.mackeeper.com`. ## Steps To Reproduce Go to: `https://api-ne.mackeeper.com/debug/pprof/` You will see these links: - allocs: A sampling of all past memory allocations - block: Stack traces that led to blocking on synchronization primitives - cmdline: The command line invocation of the current program - goroutine: Stack traces of all current goroutines - heap: A sampling of memory allocations of live objects. You can specify the gc GET parameter to run GC before taking the heap sample. - mutex: Stack traces of holders of contended mutexes - profile: CPU profile. You can specify the duration in the seconds GET parameter. After you get the profile file, use the go tool pprof command to investigate the profile. - threadcreate: Stack traces that led to the creation of new OS threads - trace: A trace of execution of the current program. You can specify the duration in the seconds GET parameter. After you get the trace file, use the go tool trace command to investigate the trace.

Reported by m4ll0k

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Information Disclosure