Skip to content

Instantly share code, notes, and snippets.

@j3rrykh4n
Created June 28, 2020 10:34
Show Gist options
  • Save j3rrykh4n/e1e6c3ff6565802add480d7f02c5d366 to your computer and use it in GitHub Desktop.
Save j3rrykh4n/e1e6c3ff6565802add480d7f02c5d366 to your computer and use it in GitHub Desktop.

Full scope access on NASA with HTML

Bug report for ..........

Steps To Reproduce

  • Install this by this command apt install example

  • Configure this with this env EXAMPLE=POC

  • Run this for exploit

Output Of My Demonstration

$ hack google.com

HACKING GOOGLE....
80% COMPLETE....
HACKED...
FOUND: THIS, THIS AND THIS

Impact

Critital

  • Anybody can read the data.
  • Anybody can modify the cached data.
  • Anybody can write.
  • Anybody can monitor your system

Fix

Just block any external ip.

Conclusion

I've done everything ethically, I didn't do any harm or I didn't tell any invidual person or company about the leakage. For any other questions about my activities on this finding, [email protected]

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment