CODEX Disclosed Report

Bug bounty report CODEX Exchange

denial-of-service attack

Company
Created date
Jun 10 2019

Target

codex.one

Vulnerability Details

Vulnerability Name :

                denial-of-service attack (DoS attack)

Description :

In computing, a denial-of-service attack (DoS attack) is a cyber-attack in which the perpetrator seeks to make a machine or network

resource unavailable to its intended users by temporarily or indefinitely disrupting services of a host connected to the Internet.

URL : https://codex.one/login

Validation steps

steps to reproduce :

  1. Go to https://codex.one/

  2. click on signup.

  3. enter the normal information to check the functionality signup is working or not.

  4. now again come to signup and put the much big formatesite like i put

www.bing.com

  1. The signup functionality gives the internal error .

  2. these is the enough information to state that the https://codex.one/login is vulnerable for DOS attacker.

Note: The main thing is what i noticed that when i attack on other website it gives error for just 10-15 minute but when

i am trying these attack the site signup functionality dose not work after more than 15 minute i refreshed.

impacts:

for impacts in brief please visit : https://www.globalsign.com/en/blog/denial-of-service-in-the-iot/

CommentsReport History
Details
Statedisclosed
Severity
Low
Bounty$0
Visibilityvisible
VulnerabilityDoS against a specific user
Participants (2)
company admin
author