wwivbbs / wwiv

WWIV BBS Software v5
http://www.wwivbbs.org
Other
185 stars 71 forks source link

Found CRITICAL Vulnerability on your website #1462

Closed imchiragprajapati closed 3 years ago

imchiragprajapati commented 3 years ago

Hello I am Chirag Prajapati a Certified Penetration Tester and Ethical Hacker my License no is: 10188-161-078-1726.

I found a CRITICAL Vulnerability on your website: wwivbbs.org For more information I request you to kindly revert me back so that I can share with you the report !

Email: imchiragprajapat@gmail.com

Looking forward to hearing from you !

wwiv commented 3 years ago

Thank you for the report!

The page mentioned has now been secured and the others addressed from software updates.

imchiragprajapati commented 3 years ago

Respected Team, Thank you for the great Response I really appreciate it 🙏 I request you to please reward me 100$ Sir, the reason I am finding the Vulnerabilities on your website because by reporting it to you I can feed my Family from that rewards which you are giving Sir nothing much more than to support my Family 🙏

Paypal Link: paypal.me/Chirag8969 http://paypal.me/Chirag8969

Looking forward hearing from you

On Thu, 20 May 2021 at 08:32, Rushfan @.***> wrote:

Thank you for the report!

The page mentioned has now been secured.

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHub https://github.com/wwivbbs/wwiv/issues/1462#issuecomment-844647592, or unsubscribe https://github.com/notifications/unsubscribe-auth/AON7CVLHG4EIG4QXXRGZZV3TOR3VRANCNFSM45D6YNXA .

wwiv commented 3 years ago

Hi,

As a small, volunteer run open source project while not able to send a monetary award, happy to send a thanks email or add a note of thanks from our twitter handle. Let me know.

Closing this issue as the credentials readonly page is secured (although it doesn't seem the credentials could have been downloaded from there, just their existence was known, and it doesn't need to be visible to un-logged in people)

imchiragprajapati commented 3 years ago

Respected Team, No problem Sir I can understand.

Please tag my Twitter handles: ImCHIRAG99

Looking Forward hearing from you !

On Fri, 21 May 2021 at 08:34, Rushfan @.***> wrote:

Hi,

As a small, volunteer run open source project while not able to send a monetary award, happy to send a thanks email or add a note of thanks from our twitter handle. Let me know.

Closing this issue as the credentials readonly page is secured (although it doesn't seem the credentials could have been downloaded from there, just their existence was known, and it doesn't need to be visible to un-logged in people)

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHub https://github.com/wwivbbs/wwiv/issues/1462#issuecomment-845617978, or unsubscribe https://github.com/notifications/unsubscribe-auth/AON7CVJGPSX3IOHOT4NMZGDTOXEU3ANCNFSM45D6YNXA .

wwiv commented 3 years ago

https://twitter.com/wwivbbs/status/1395766420806377475