Leaked Valid Credentials on NASA Subdomain

Disclosed by
MiguelSantareno's avatar
MiguelSantareno
Summary by MiguelSantareno

On this report, I was able to get a username and password using Google Dorks.
That credential was exposed on a webpage, and it was from the developer.
I was able to log in to a specific application, and after digging a little into the application, I was able to access and download a collection called "Mars 2020 Genetic Inventory".

Activity
  1. Martin’s avatar
    Martin Customer published the disclosure report

    ()

  2. MiguelSantareno’s avatar
    MiguelSantareno updated the disclosure summary

    ()

  3. MiguelSantareno’s avatar
    MiguelSantareno requested disclosure

    ()

  4. Medx’s avatar
    Medx Customer changed the state to Resolved

    ()

  5. Medx’s avatar
    Medx Customer sent a message

    ()

  6. Medx’s avatar
    Medx Customer sent a message

    ()

  7. Cesar_Sanchez’s avatar
    Cesar_Sanchez Customer changed the state to Unresolved

    ()

  8. Tal_Bugcrowd’s avatarbugcrowd logo
    Tal_Bugcrowd sent a message

    ()

  9. Tal_Bugcrowd’s avatarbugcrowd logo
    Tal_Bugcrowd changed the state to Triaged

    ()

  10. MiguelSantareno’s avatar
    MiguelSantareno sent a message

    ()

  11. MiguelSantareno’s avatar
    MiguelSantareno resolved a blocker for Bugcrowd Operations by providing information on reproduction

    ()

  12. MiguelSantareno’s avatar
    MiguelSantareno sent a message

    ()

  13. Raven_Bugcrowd’s avatarbugcrowd logo
    Raven_Bugcrowd created a blocker on the researcher to provide information on reproduction

    ()

  14. Raven_Bugcrowd’s avatarbugcrowd logo
    Raven_Bugcrowd sent a message

    ()

  15. MiguelSantareno’s avatar
    MiguelSantareno created the submission

    ()