logoalt Hacker News

janoelzelast Tuesday at 10:02 PM1 replyview on HN

really bad stuff in the results. very easy to find API tokens, penetration test reports, confidental PDFs, internal APIs. Fiverr needs to immediately block all static asset access until this is resolved. business continuity should not be a concern here.


Replies

mpeglast Tuesday at 10:04 PM

lots of admin credentials too, which have probably never been changed

show 1 reply