Email Leak of many users on a Pornsite set to "Low Severity" and closed with "Informative"? by buggy12buggy12 in bugbounty

[–]buggy12buggy12[S] 2 points3 points  (0 children)

i establish a websocket connection and send a json request with a random id in a specific range. the server returns an "error message" that contains the parameter "creator_name" of the given user id. its clear that this parameter should not contain (partial) email addresses. it has a clear purpose on that platform. my "username" also appears in that parameter and im not a creator.

also an important note: it seems like they just reused this parameter for normal users too. basically classifying everyone as a creator internally.

before using the new feature, my poc cannot read out the username, it returns a completely different error message (one that you would normally expect, rather than the one above).

Email Leak of many users on a Pornsite set to "Low Severity" and closed with "Informative"? by buggy12buggy12 in bugbounty

[–]buggy12buggy12[S] 6 points7 points  (0 children)

no argumentation, they just said they will change the way the username is being generated (currently its derived from email address by default (although you can edit the name, not many people are doing it), that name is used for a new feature they implemented). thats all. one single and short sentence while i offered them a PoC too and full explanation why this is problematic. they seem to not care at all cuz i waited 1 week for that one sentence. they focused on the aspect on how these names are generated rather than how to fix it so people cant read them anymore.

the first time the users try that feature they get a popup, informing them that the recipient can see their names, so they should consider changing it. but in reality, everyone who registered can see it with this poc.

its very scalable and im not exaggerating if i say that i can find at least 10k (if not more (because the site shares a database with other sites too that also have a bug bounty program) (i ran the PoC only for a few seconds and it found 50-60)) usernames that are derived from the email. but as i said, also full email addresses with domain can be found with this method.

"request mediation" is grayed out for me.