An attack on HackerOne that allowed access to confidential vulnerability reports

The HackerOne platform, which enables security researchers to inform developers about discovered vulnerabilities and receive rewards for it, has been report hacked. One of the researchers managed to gain access to the account of a HackerOne security analyst who had the ability to view restricted materials, including information about unresolved vulnerabilities. Since the platform's inception, HackerOne has paid researchers a total of $23 million for discovering vulnerabilities in the products of more than 100 clients, including Twitter, Facebook, Google, Apple, Microsoft, Slack, the Pentagon, and the US Navy.

Notably, the account takeover was possible due to human error. One of the researchers submitted a request regarding a potential vulnerability on HackerOne. The HackerOne analyst, while reviewing the submission, attempted to reproduce the proposed hacking method but was unable to replicate the problem, and the submitter received a response asking for additional details. Meanwhile, the analyst overlooked the fact that along with the results of the unsuccessful check, he mistakenly sent the content of his session cookie. Specifically, during the dialogue, the analyst provided an example of an HTTP request executed using the curl utility, including HTTP headers, from which he forgot to remove the session cookie content.

The researcher noticed this mistake and was able to access the privileged account on hackerone.com simply by substituting the observed cookie value without needing to undergo the two-factor authentication implemented by the service. The attack was possible because session binding to the user's IP or browser was not enforced on hackerone.com. The problematic session identifier was removed two hours after the leak report was published. The researcher was awarded $20,000 for reporting the issue.

HackerOne initiated an audit to analyze the potential occurrences of similar Cookie leaks in the past and to assess potential leaks of sensitive information about customer issues with the service. The audit found no evidence of leaks in the past and determined that the researcher who demonstrated the issue could have accessed information from approximately 5% of all programs available in the service, to which an analytics session key had been used.

To protect against similar attacks in the future, session key binding to IP address and filtering of session keys and authentication tokens in comments have been implemented. In the future, the binding to IP addresses is planned to be replaced with binding to user devices, as IP binding is inconvenient for users with dynamically assigned addresses. It was also decided to expand the logging system with information about user access to data and to implement a model of granular access for analysts to customer data.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster