Bitcoin Forum
May 28, 2024, 11:36:57 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Coinone Critical Vulnerabilities  (Read 142 times)
CBLS (OP)
Newbie
*
Offline Offline

Activity: 9
Merit: 0


View Profile
January 11, 2018, 11:19:32 AM
 #1

Hello friends,

I am an ethical hacker. I found vulnerabilities on Coinone. I sent a report 2 months ago for the first vulnerability.

Response of Coinone (2 month ago);
Thank you for the contact. We have an internal bug bounty program, we’ll review your bug and arrange price. We have a rule for the price depending on the impact. Please send us your report.

Response of Coinone (1 month ago);
We have checking your mail with our own team and security partner.
So we need meeting our council and reward program.


Passed to a month... I wrote it 3 times for remind. Coinone doesn't answer, haven't fixed off vulnerability and they didn't send me a bug bounty.
So, I didn't tell them the second vulnerability(SQLi).

Your memberships aren't safe!
leveler
Member
**
Offline Offline

Activity: 93
Merit: 10


View Profile
January 12, 2018, 02:34:04 AM
 #2

Is this right?
CBLS (OP)
Newbie
*
Offline Offline

Activity: 9
Merit: 0


View Profile
January 12, 2018, 11:27:28 PM
 #3

Absolutely. I have worked with Poloniex before and Mr. Tristan sent 0.5 BTC for bug bounty.
But Coinone didn't fixed vulnerability... Passed to a month. Blackhat can hack many user accounts.
I will share the first vulnerability here within 24 hours. People have to get their own security. This is not a disclosure, it is purely good faith.
CBLS (OP)
Newbie
*
Offline Offline

Activity: 9
Merit: 0


View Profile
January 22, 2018, 10:05:28 PM
 #4

First Vulnerability;
CWE - CWE-601: URL Redirection to Untrusted Site
https://coinone.co.kr/language/?code=en&next=https://attacker.org
POC: https://www.youtube.com/watch?v=N74jnUVUccw

Next video will be for SQLi.(Within 24 hours)
leveler
Member
**
Offline Offline

Activity: 93
Merit: 10


View Profile
January 23, 2018, 04:00:02 AM
 #5

Next video will be for SQLi?

I`m waiting for proof.
CBLS (OP)
Newbie
*
Offline Offline

Activity: 9
Merit: 0


View Profile
January 23, 2018, 10:11:33 AM
 #6

Next video will be for SQLi?

I`m waiting for proof.
Yes. Type of sqli: time-based(stacked queries) + dns exfiltration. Run, Forrest, run!
Please don't send private messages. No sale. I will continue to share from here.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!