Researchers have warned of enterprise software misconfigurations leading to the leak of sensitive records on urlscan.io.
Urlscan.io is a website scan and analysis engine. The system accepts URL submissions and generates a wealth of data, including domains, IPs, DOM information, and cookies, alongside screenshots.
The developers say the engine’s purpose is to allow “anyone to easily and confidently analyze unknown and potentially malicious websites”. Urlscan.io supports many enterprise customers and open source projects, and an API is provided to integrate these checks into third-party products.
In a blog post published today (November 2), Positive Security said the urlscan API came to its attention due to an email sent by GitHub in February, warning customers that GitHub Pages URLs had been accidentally leaked via a third party during metadata analysis.
“With the type of integration of this API (for example via a security tool that scans every incoming email and performs a urlscan on all links), and the amount of data in the database, there is a wide variety of sensitive data that can be searched for and retrieved by an anonymous user,” the researchers say.
Upon further investigation, Positive Security found that this could include urlscan.io dorks, password reset links, setup pages, Telegram bots, DocuSign signing requests, meeting invitations, package tracking links, and PayPal invoices.
Pingbacks to leaked email addresses appeared to show that misconfigured security tools that submitted links received via email as public scans to urlscan.io were the culprits.
For example, many API integrations utilized generic python-requests/2.X.Y user agents that ignored account visibility settings, thus allowing scans to be wrongfully submitted as public.
Positive Security reached out to numerous leaked email addresses and there was only one response – from an organization that sent an employee a DocuSign link to their work contract and subsequently launched an investigation.
The employer found that a misconfiguration of their Security Orchestration, Automation, and Response (SOAR) playbook, which was integrated with urlscan.io, was at fault.
Positive Security examined historic urlscan.io information and uncovered misconfigured clients that could be abused by scraping the system for email addresses and sending them unique links to see if they would appear on urlscan.
For users of such misconfigured clients, password resets for many web services can be triggered, and the leaked link used to set a new password and take over the accounts.
Speaking to Daily Swig, Fabian Bräunlein, co-founder of Positive Security said that this attack vector could be triggered “for personal services like banking or social media or company services such as for popular SaaS or custom applications.
“For many SaaS providers, access to an email address with a certain domain is already sufficient to gain access to internal company data (e.g. chats or code repositories),” Bräunlein added. “In such a case, an attacker does not even need to take over existing accounts but can just create new accounts at interesting services.”
Once the impact of the issue’s assessment was completed in July, Positive Security reported its findings to urlscan.io. As a result, the cybersecurity firm and urlscan.io developers worked together to address the problems uncovered, leading to the release of a new engine version later in the month.
The improved software includes an enhanced scan visibility interface and team-wide visibility settings.
Urlscan.io subsequently also published Scan Visibility Best Practices, which explain the security benefits and risks posed by three visibility settings users choose between when submitting a URL: ‘Public’, ‘Unlisted’, and ‘Private’.
Urlscan.io has also contacted customers who have submitted vast amounts of public scans and begun reviewing third-party SOAR tool integrations. Finally, the developers have added deletion rules, highlighted visibility settings in the user interface, and implemented a report button to deactivate problematic search results.
“Security teams that run a SOAR platform must make sure that no sensitive data is leaked to the public via integrations of third-party services,” Bräunlein commented.
Urlscan GmbH CEO Johannes Gilger told The Daily Swig: “We welcome the research performed by Positive Security and appreciate their professional conduct while working with us to identify the scope and source of these inadvertent information leaks.
“We have improved the visibility of the relevant settings on our platform, we have educated our users about the issue through a dedicated blog post and we continue to work with third party automation providers to ensure adherence to safe default behaviors.
“A platform like urlscan will always carry the risk of unintended information disclosure due to the nature of its operation, so we take every available measure to minimize the likelihood of these things happening.”
All Time Argentina’s Top Goal Scorer At The FIFA World Cup
Will There Be Wednesday (Tv Series) Season 2, Release Date, Cast, Latest News
Portugal Coach Fire-back at Ronaldo For Sub Reaction
[STORY] TIMISIRE THE GOLDEN GIRL (Episode 22)
[STORY] BEHIND THE FINE FACE (Episode 08)
Actress, Keke Palmer announces pregnancy during ‘Saturday Night Live’
2023: Time to liberate yourself, vote out APC – Atiku to Lagosians
2023: INEC to meet NCC, telcos, on Tuesday
FIFA World Cup 2022: Croatia beat Japan on penalties to reach World Cup quarter-finals
GraphQL password hash leak problem fixed in Ibexa DXP
Gunmen kidnap Benue Commissioner for Housing
Adeleke threatens to penalize MDAs, starts payment of salaries
FG slams Atiku, ‘You live in Dubai’, you don’t really know Nigeria
Tinubu criticizes Arise TV, claiming they wish to profit from him
Tinubu Speaks about the debate surrounding his birth certificate and birth date
Singer AV drops highly anticipated debut EP, ‘Thug Love’
I’m disappointed – Blaqbonez reacts to Wizkid’s comments
South Africa parliament to vote on Ramaphosa’s impeachment Tuesday
OAU to graduate 5,852 students, 130 bag first class
Oseni: “If I Am To Start With Him, Reno Will Not Exist” – Reno Shares New Audio
Atiku has no moral basis to criticise Buhari — Lai Mohammed
Elon Musk says risk of him being assassinated is ‘quite significant’
Variation in the Types of Cryptocurrencies
Factors To Consider Before Choosing Bitcoin Exchange
Things You Should Know About Bitcoin Statistics: Future Trends
Bitcoin For Beginners: An Informative Report On The Digital Currency
Oil can’t feed Nigeria anymore – Obasanjo
Sesame Street Icon, Bob McGrath Dies At 90
Sigourney Weaver channelled her own teenage self into role 14-year-old Na’vi Kiri in Avatar: The Way of Water
Kate Winslet was ‘traumatised’ by Titanic – James Cameron
Jude Bellingham defends Liverpool star after England win
Gilberto Silva promises to speak to Edu about signing England star
Harry Kane praises team’s mentality after beating Senegal
Raheem Sterling to leave England’s World Cup camp after armed robbery
Your daily horoscope for Monday, December 5, 2022
NNPC not sincere about oil theft, exaggerating figures – Navy
FIFA World Cup 2022: Giroud and Mbappe break records as France reach World Cup quarter-finals
“I Owe No One Apology For Commending Buhari”: Wike To PDP Members
NCC Reveals List Of Unapproved Phones In Nigerian Markets To Be Avoided
Greetings flow in as Buhari and Aisha celebrate 33 years of marriage
DOWNLOAD Complete Wednesday (TV series) (2022 film) Season 1 Subtitles File [English SRT] 2022
DOWNLOAD Complete Troll (2022 film) Subtitles File [English SRT] 2022
DOWNLOAD Complete My Name Is Vendetta (2022 film) Subtitles File [English SRT] 2022
[STORY] THE VIRGIN WIFE (Complete Episodes)
[STORY] BEHIND THE FINE FACE (Complete Episodes)
[Music] Timaya – Sweet Us (As e Dey Sweet Us e Dey Pain Dem)
Top 10 Celebrities With Brazilian Butt Lift Surgery (BBL) [PHOTOS]
[STORY] THE VIRGIN WIFE (Episode 06)
[STORY] THE VIRGIN WIFE (Episode 07)
[STORY] THE VIRGIN WIFE (Episode 01)
[STORY] THE VIRGIN WIFE (Episode 02)
[STORY] THE VIRGIN WIFE (Episode 12)
[STORY] THE VIRGIN WIFE (Episode 05)
[STORY] THE VIRGIN WIFE (Final Episode 13)
[STORY] THE VIRGIN WIFE (Episode 04)
[STORY] THE VIRGIN WIFE (Episode 10)
[STORY] THE VIRGIN WIFE (Episode 08)
[STORY] DIARY OF A PASTOR’S SON (Complete Episodes)
[STORY] THE VIRGIN WIFE (Episode 03)
Your daily horoscope for Thursday, December 1, 2022
[STORY] BEHIND THE FINE FACE (Episode 01)
[STORY] BEHIND THE FINE FACE (Episode 04)
Top 5 Richest Kid Nigerian Skit Makers And How Their Networth
Who Manchester United should sign instead of Cody Gakpo – Sven-Goran Eriksson
Kehlani Goes Viral After Flirting With Underage Girl At Concert
[STORY] BEHIND THE FINE FACE (Episode 02)
DOWNLOAD Complete Blood & Water (TV series) (2022 film) Season 3 Subtitles File [English SRT] 2022
[STORY] THE VIRGIN WIFE (Episode 11)
[STORY] BEHIND THE FINE FACE (Episode 03)
Antony blames Qatar’s air conditioning for World Cup illness
[STORY] THE VIRGIN WIFE (Episode 09)
Timaya – Sweet Us [Lyrics]
[STORY] BEHIND THE FINE FACE (Episode 05)
[STORY] TIMISIRE THE GOLDEN GIRL (Episode 20)
Chelsea set to sign Andrey Santos in January
Victoria Chintex assassinated in Kaduna State
[STORY] DIARY OF A PASTOR’S SON (Episode 01)
Buhari Appoints Hairdresser As Boss Of Financial Institution – Lawyers Demand Sack
[STORY] DIARY OF A PASTOR’S SON (Episode 02)
Cardi B Threatens To Murder Comedian Nicole Arbour’s Mother
ANE Billboard Hots
Technology5 months ago
VoIP Number: Everything You Need To Know
Movie Subtitle2 weeks ago
DOWNLOAD Complete Black Adam (2022 film) Subtitles File [English SRT] 2022
Music3 years ago
[Music] Gnash Ft Olivia O’Brien – I Hate you, I Love you
Music5 months ago
[Music] Akon – Sorry Blame It On Me
Music5 months ago
Alan Walker – Faded [INSTRUMENTAL]
Music5 months ago
[Instrumental] Wiz Khalifa – See You Again ft. Charlie Puth
Music5 months ago
[INSTRUMENTAL] John Legend – All Of Me
Music5 months ago
[Video] 21 Savage ft. Offset & Metro Boomin – Rap Saved Me