HackenProof Disclosed Report

Bug bounty report HackenProof

Impersonation via Broken Link Hijacking

Created date
May 20 2023

Target

Main website

Vulnerability Details

I got a bug called impersonation via broken link hijacking at official twitter account of HackenProof.

Validation steps

  1. Go to the official HackenProof Website or Any Email sent from HackenProof
  2. From the bottom of the page, click on the official Twitter Icon
  3. Now click on the attached Telegram account
  4. I have already hijacked the account

Impact:

The users who will want customer support through Telegram, will lose their accounts by sharing secrets with the attackers. Attackers can target the victims and tell them to get support through Telegram. As Attackers already hijacked the account, they may lead a lot of attacks against them.

Reference:

Link --> Broken Link Hijacking on Twitter link --> Severity: Medium --> $250 Bounty

Attachments

poc.mp4
CommentsReport History
Comments on this report are hidden
Details
Statedisclosed
Severity
Medium
Bounty$10
Visibilitypartially
VulnerabilityResource Injection
Participants (3)
company admin
company admin