This is crazy! So many tax and other financial forms out in the open. But the most interesting file I’ve seen so far seems to be a book draft titled “HOOD NIGGA AFFIRMATIONS: A Collection of Affirming Anecdotes for Hood Niggas Everywhere”. I made it to page 27 out of 63.
Tell HN: Fiverr left customer files public and searchable
11–20 of 252 posts
Re: Tell HN: Fiverr left customer files public and searchable
#12This is bad.
Re: Tell HN: Fiverr left customer files public and searchable
#13Probably not in scope but maybe https://bugcrowd.com/engagements/cloudinary will care? This is bad.
(Fiverr itself uses Bugcrowd but is private, having to first email their SOC as I did.)
Re: Tell HN: Fiverr left customer files public and searchable
#14Re: Tell HN: Fiverr left customer files public and searchable
#15really bad stuff in the results. very easy to find API tokens, penetration test reports, confidental PDFs, internal APIs. Fiverr needs to immediately block all static asset access until this is resolved. business continuity should not be a concern here.
Re: Tell HN: Fiverr left customer files public and searchable
#16Re: Tell HN: Fiverr left customer files public and searchable
#17Re: Tell HN: Fiverr left customer files public and searchable
#18Re: Tell HN: Fiverr left customer files public and searchable
#19really bad stuff in the results. very easy to find API tokens, penetration test reports, confidental PDFs, internal APIs. Fiverr needs to immediately block all static asset access until this is resolved. business continuity should not be a concern here.
lots of admin credentials too, which have probably never been changed