{"id":53579,"date":"2019-12-05T00:00:00","date_gmt":"2019-12-04T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/ataka-na-hackerone-pozvolivshaya-poluchit-dostup-k-zakrytym-otchyotam-ob-uyazvimostyah"},"modified":"2021-01-02T13:04:14","modified_gmt":"2021-01-02T11:04:14","slug":"ataka-na-hackerone-pozvolivshaya-poluchit-dostup-k-zakrytym-otchyotam-ob-uyazvimostyah","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/ataka-na-hackerone-pozvolivshaya-poluchit-dostup-k-zakrytym-otchyotam-ob-uyazvimostyah","title":{"rendered":"Ataque en HackerOne que permiti\u00f3 acceder a informes cerrados sobre vulnerabilidades","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>La plataforma HackerOne, que permite a los investigadores de seguridad informar a los desarrolladores sobre la detecci\u00f3n de vulnerabilidades y recibir recompensas por ello, ha sufrido <noindex><a rel=\"nofollow\" href=\"https:\/\/hackerone.com\/reports\/745324\">un informe<\/a><\/noindex> una violaci\u00f3n de su propia seguridad. Uno de los investigadores logr\u00f3 acceder a la cuenta de un analista de seguridad de HackerOne, que ten\u00eda la capacidad de ver materiales confidenciales, incluyendo informaci\u00f3n sobre vulnerabilidades que a\u00fan no se hab\u00edan corregido. Desde el inicio de la plataforma, se han pagado a los investigadores un total de 23 millones de d\u00f3lares por la detecci\u00f3n de vulnerabilidades en productos de m\u00e1s de 100 clientes, entre los que se encuentran Twitter, Facebook, Google, Apple, Microsoft, Slack, el Pent\u00e1gono y la Marina de los EE. UU.<\/p>\n<p>Es notable que la captura de la cuenta fue posible debido al factor humano. Uno de los investigadores envi\u00f3 una solicitud sobre una posible vulnerabilidad en HackerOne. Un analista de HackerOne, al revisar la solicitud, intent\u00f3 reproducir el m\u00e9todo de ataque propuesto, pero no pudo replicar el problema, y se envi\u00f3 una respuesta al autor de la solicitud pidiendo detalles adicionales. Sin embargo, el analista no se dio cuenta de que, junto con los resultados de la revisi\u00f3n fallida, envi\u00f3 inadvertidamente el contenido de su Cookie de sesi\u00f3n. En particular, durante el di\u00e1logo, el analista present\u00f3 un ejemplo de una solicitud HTTP ejecutada mediante la utilidad curl, incluyendo encabezados HTTP de los que se olvid\u00f3 limpiar el contenido de la Cookie de sesi\u00f3n.<\/p>\n<p>El investigador not\u00f3 este descuido y pudo acceder a la cuenta privilegiada en el sitio hackerone.com, simplemente sustituyendo el valor de la Cookie que hab\u00eda notado, sin necesidad de pasar por el sistema de autenticaci\u00f3n multifactor que se aplica en el servicio. El ataque fue posible porque en hackerone.com no se aplicaba el v\u00ednculo de la sesi\u00f3n a la IP o al navegador del usuario. El identificador de sesi\u00f3n problem\u00e1tico fue eliminado dos horas despu\u00e9s de la publicaci\u00f3n del informe sobre la filtraci\u00f3n. Se decidi\u00f3 pagar al investigador 20,000 d\u00f3lares por informar sobre el problema.<\/p>\n<p>HackerOne inici\u00f3 una auditor\u00eda para analizar la posible ocurrencia de filtraciones similares de cookies en el pasado y para evaluar las posibles filtraciones de informaci\u00f3n confidencial sobre los problemas de los clientes del servicio. La auditor\u00eda no detect\u00f3 hechos de filtraciones en el pasado y determin\u00f3 que el investigador que demostr\u00f3 el problema pudo haber obtenido informaci\u00f3n sobre aproximadamente el 5% de todos los programas presentados en el servicio, a los que se le hab\u00eda otorgado acceso al analista, cuyo clave de sesi\u00f3n fue utilizada.<\/p>\n<p>Para protegerse contra ataques similares en el futuro, se ha implementado la vinculaci\u00f3n de la clave de sesi\u00f3n a <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/es\/lir\/ipv4\/\"   title=\"IP\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"594\">IP<\/a> y la filtraci\u00f3n de claves de sesi\u00f3n y tokens de autenticaci\u00f3n en los comentarios. En el futuro, se planea reemplazar la vinculaci\u00f3n a IP por la vinculaci\u00f3n a los dispositivos del usuario, ya que la vinculaci\u00f3n a IP es inc\u00f3moda para los usuarios con direcciones din\u00e1micamente asignadas. Tambi\u00e9n se ha decidido ampliar el sistema de registros con informaci\u00f3n sobre el acceso de los usuarios a los datos y llevar a cabo un modelo de acceso granular de los analistas a los datos de los clientes.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fuente: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51977\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u0430 HackerOne, \u0434\u0430\u044e\u0449\u0430\u044f \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044f\u043c \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u043d\u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u043e\u0432 \u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0438 \u043f\u043e\u043b\u0443\u0447\u0430\u0442\u044c \u0437\u0430 \u044d\u0442\u043e \u0432\u043e\u0437\u043d\u0430\u0433\u0440\u0430\u0436\u0434\u0435\u043d\u0438\u044f, \u043f\u043e\u043b\u0443\u0447\u0438\u043b\u0430 \u043e\u0442\u0447\u0451\u0442 \u043e \u0441\u043e\u0431\u0441\u0442\u0432\u0435\u043d\u043d\u043e\u043c \u0432\u0437\u043b\u043e\u043c\u0435. \u041e\u0434\u043d\u043e\u043c\u0443 \u0438\u0437 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0443\u0434\u0430\u043b\u043e\u0441\u044c \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0443\u0447\u0451\u0442\u043e\u0439 \u0437\u0430\u043f\u0438\u0441\u0438 \u0430\u043d\u0430\u043b\u0438\u0442\u0438\u043a\u0430 \u043f\u043e \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 HackerOne, \u0438\u043c\u0435\u044e\u0449\u0435\u0433\u043e \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u043f\u0440\u043e\u0441\u043c\u043e\u0442\u0440\u0430 \u0437\u0430\u043a\u0440\u044b\u0442\u044b\u0445 \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u043e\u0432, \u0432 \u0442\u043e\u043c \u0447\u0438\u0441\u043b\u0435 \u0441\u043e \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f\u043c\u0438 \u043e\u0431 \u0435\u0449\u0451 \u043d\u0435 \u0443\u0441\u0442\u0440\u0430\u043d\u0451\u043d\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445. \u0417\u0430 \u0432\u0440\u0435\u043c\u044f \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u043e\u0432\u0430\u043d\u0438\u044f \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b \u0447\u0435\u0440\u0435\u0437 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-53579","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u0430 HackerOne, \u0434\u0430\u044e\u0449\u0430\u044f \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044f\u043c \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u043d\u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u043e\u0432 \u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0438 \u043f\u043e\u043b\u0443\u0447\u0430\u0442\u044c \u0437\u0430 \u044d\u0442\u043e \u0432\u043e\u0437\u043d\u0430\u0433\u0440\u0430\u0436\u0434\u0435\u043d\u0438\u044f, \u043f\u043e\u043b\u0443\u0447\u0438\u043b\u0430\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/ataka-na-hackerone-pozvolivshaya-poluchit-dostup-k-zakrytym-otchyotam-ob-uyazvimostyah\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0410\u0442\u0430\u043a\u0430 \u043d\u0430 HackerOne, \u043f\u043e\u0437\u0432\u043e\u043b\u0438\u0432\u0448\u0430\u044f \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0437\u0430\u043a\u0440\u044b\u0442\u044b\u043c \u043e\u0442\u0447\u0451\u0442\u0430\u043c \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u0430 HackerOne, \u0434\u0430\u044e\u0449\u0430\u044f \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044f\u043c \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u043d\u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u043e\u0432 \u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0438 \u043f\u043e\u043b\u0443\u0447\u0430\u0442\u044c \u0437\u0430 \u044d\u0442\u043e \u0432\u043e\u0437\u043d\u0430\u0433\u0440\u0430\u0436\u0434\u0435\u043d\u0438\u044f, \u043f\u043e\u043b\u0443\u0447\u0438\u043b\u0430\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/ataka-na-hackerone-pozvolivshaya-poluchit-dostup-k-zakrytym-otchyotam-ob-uyazvimostyah\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-12-04T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-01-02T11:04:14+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Ataque a HackerOne que permiti\u00f3 acceder a informes confidenciales sobre vulnerabilidades | ProHoster","description":"La plataforma HackerOne, que permite a los investigadores de seguridad informar a los desarrolladores sobre la detecci\u00f3n de vulnerabilidades y recibir recompensas por ello, ha sufrido","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/ataka-na-hackerone-pozvolivshaya-poluchit-dostup-k-zakrytym-otchyotam-ob-uyazvimostyah","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0410\u0442\u0430\u043a\u0430 \u043d\u0430 HackerOne, \u043f\u043e\u0437\u0432\u043e\u043b\u0438\u0432\u0448\u0430\u044f \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0437\u0430\u043a\u0440\u044b\u0442\u044b\u043c \u043e\u0442\u0447\u0451\u0442\u0430\u043c \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 | ProHoster","og:description":"\u041f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u0430 HackerOne, \u0434\u0430\u044e\u0449\u0430\u044f \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044f\u043c \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u043d\u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u043e\u0432 \u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0438 \u043f\u043e\u043b\u0443\u0447\u0430\u0442\u044c \u0437\u0430 \u044d\u0442\u043e \u0432\u043e\u0437\u043d\u0430\u0433\u0440\u0430\u0436\u0434\u0435\u043d\u0438\u044f, \u043f\u043e\u043b\u0443\u0447\u0438\u043b\u0430","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/ataka-na-hackerone-pozvolivshaya-poluchit-dostup-k-zakrytym-otchyotam-ob-uyazvimostyah","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-12-04T21:00:00+00:00","article:modified_time":"2021-01-02T11:04:14+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"53579","title":null,"description":"","keywords":"","keyphrases":null,"primary_term":null,"canonical_url":"","og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-02-08 20:46:20","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 20:22:50","updated":"2026-02-08 20:46:20","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/53579","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=53579"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/53579\/revisions"}],"predecessor-version":[{"id":157785,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/53579\/revisions\/157785"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=53579"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=53579"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=53579"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}