Live data from Hacker News

Tell HN: Fiverr left customer files public and searchable

news.ycombinator.com

11–20 of 252 posts

Re: Tell HN: Fiverr left customer files public and searchable

#11

This is crazy! So many tax and other financial forms out in the open. But the most interesting file I’ve seen so far seems to be a book draft titled “HOOD NIGGA AFFIRMATIONS: A Collection of Affirming Anecdotes for Hood Niggas Everywhere”. I made it to page 27 out of 63.

I've read worse. Better than Dan Brown!

Re: Tell HN: Fiverr left customer files public and searchable

#13

Probably not in scope but maybe https://bugcrowd.com/engagements/cloudinary will care? This is bad.

They probably wouldn't act immediately as there's no way for them to enable signing without breaking their client's site. The only cleanup you could do without that would be having google pull that subdomain I guess?

(Fiverr itself uses Bugcrowd but is private, having to first email their SOC as I did.)

Re: Tell HN: Fiverr left customer files public and searchable

#15

really bad stuff in the results. very easy to find API tokens, penetration test reports, confidental PDFs, internal APIs. Fiverr needs to immediately block all static asset access until this is resolved. business continuity should not be a concern here.

lots of admin credentials too, which have probably never been changed

Re: Tell HN: Fiverr left customer files public and searchable

#19
post #15

really bad stuff in the results. very easy to find API tokens, penetration test reports, confidental PDFs, internal APIs. Fiverr needs to immediately block all static asset access until this is resolved. business continuity should not be a concern here.

lots of admin credentials too, which have probably never been changed

admin passwords to dating sites, that's the stuff people get blackmailed with
Post reply on HN