Sensitive Data Exposure on renowned Airline Company

I hope you got some information from my previous writing on Account Takeover Vulnerability. Today, I am going to discuss about a vulnearblity that I found on one of the most reputed airline company. At the end of the write up I have provided a video link that will help you to find sensitive data on the domain.

Now lets jump to the issue.

The power of bash scripting allowed to explore the target and look for different functionality while my recon stuff is done automatically by my bash script.I tried many different vulnerabilities there, ranging from Account Takeover to IDOR. After I was done with first cut hunting, I switched to my VPS to look out what other things my script bought for me.

To my surprise, my fuzzing tool bought me plethora of results. Some of them were of RTFS kind. (UKWIM, Read The Fucking Screen :-p ). But one thing caught my eye and that was SQL Log file.

This file was sensitive because it contained data like credentials, operations, File group, File type , File name and much more juicy things.

This was not it. When I saw the file structure of SQL and how the other files were stored, I was able to traverse from one directory to other as well. Although some directory where not found but still traversing through the directories helped me collect some more data.

Now I would like you to try the recursion while using any fuzzing tool.You can find best 5 usage of FFUF that will help you to find Sensitive data here.

