Espamex: explotación completa - 16 hallazgos (4 críticos, 5 altos, 4 medios)
This commit is contained in:
69
refaccionariasdelvalle-heroku/recon.md
Normal file
69
refaccionariasdelvalle-heroku/recon.md
Normal file
@@ -0,0 +1,69 @@
|
||||
# Reconocimiento - Refaccionarias del Valle (Heroku)
|
||||
**Objetivo:** https://refaccionariasdelvalle.herokuapp.com
|
||||
**Fecha:** 2026-03-25
|
||||
|
||||
## Infraestructura
|
||||
- **Hosting:** Heroku (Salesforce)
|
||||
- **Servidor:** Heroku Router
|
||||
- **Tecnología:** Ruby on Rails (cookie `_refaccionariasdelvalle_session`, X-Runtime header)
|
||||
- **Frontend:** jQuery
|
||||
- **SSL:** Amazon (wildcard *.herokuapp.com) — válido hasta 2027-01-29
|
||||
- **CORS:** Access-Control-Allow-Origin apunta a `d134yvfg5nzhu8.cloudfront.net`
|
||||
|
||||
## Headers de Seguridad
|
||||
| Header | Estado |
|
||||
|--------|--------|
|
||||
| HSTS | OK (max-age=63072000; includeSubDomains) |
|
||||
| Content-Security-Policy | FALTA |
|
||||
| X-Frame-Options | ALLOWALL (inseguro) |
|
||||
| X-Content-Type-Options | FALTA |
|
||||
| X-XSS-Protection | FALTA |
|
||||
| Referrer-Policy | FALTA |
|
||||
| Permissions-Policy | FALTA |
|
||||
|
||||
## Hallazgos
|
||||
| # | Hallazgo | Severidad |
|
||||
|---|----------|-----------|
|
||||
| 1 | **X-Frame-Options: ALLOWALL** — vulnerable a clickjacking | ALTA |
|
||||
| 2 | **Endpoint `/users/sign_in` retorna 500** — error interno, posible Devise mal configurado, info disclosure en errores | ALTA |
|
||||
| 3 | **CORS abierto** — `Access-Control-Allow-Origin: https://d134yvfg5nzhu8.cloudfront.net/` con `Allow-Credentials: true` y todos los métodos (POST, PUT, DELETE, GET, OPTIONS) | ALTA |
|
||||
| 4 | **Link a cPanel webmail expuesto** — `chi-pnode6.websitehostserver.net:2096` visible en footer del login | MEDIA |
|
||||
| 5 | **Link a sistema externo** — `b2b-pos.com/login` enlazado desde la página de login (sistema B2B/POS) | MEDIA |
|
||||
| 6 | 5 de 7 headers de seguridad ausentes | MEDIA |
|
||||
| 7 | Cookie de sesión Rails con HttpOnly + Secure (bien configurada) | OK |
|
||||
| 8 | HSTS habilitado con max-age alto (bien) | OK |
|
||||
| 9 | CSRF token de Rails expuesto en meta tags (normal para Rails) | INFO |
|
||||
| 10 | robots.txt apunta a sitemap del dominio principal | INFO |
|
||||
|
||||
## Página de Login
|
||||
- **URL:** `/cuentas/ingresar`
|
||||
- **Framework:** Rails con Devise (formulario `new_user`)
|
||||
- **Campos:** `user[email]`, `user[password]`, `user[remember_me]`
|
||||
- **Sin CAPTCHA ni rate limiting visible**
|
||||
- **Footer expone:** enlace a correo corporativo (cPanel webmail) y enlace a b2b-pos.com
|
||||
|
||||
## Endpoints Descubiertos
|
||||
| Ruta | Respuesta | Nota |
|
||||
|------|-----------|------|
|
||||
| `/` | Redirect → login | App requiere autenticación |
|
||||
| `/cuentas/ingresar` | 200 | Login de Devise |
|
||||
| `/admin` | 302 → `/cuentas/ingresar` | Admin protegido |
|
||||
| `/users/sign_in` | 500 | **Error interno** — posible ruta Devise rota |
|
||||
| `/api` | 302 → `/` | API requiere auth |
|
||||
| `/robots.txt` | 200 | Sitemap del dominio principal |
|
||||
|
||||
## CORS Detalle
|
||||
```
|
||||
Access-Control-Allow-Credentials: true
|
||||
Access-Control-Allow-Headers: Origin, X-Requested-With, Content-Type, Accept, Authorization
|
||||
Access-Control-Allow-Methods: POST, PUT, DELETE, GET, OPTIONS
|
||||
Access-Control-Allow-Origin: https://d134yvfg5nzhu8.cloudfront.net/
|
||||
```
|
||||
Si el origin se refleja dinámicamente, podría permitir CSRF cross-origin.
|
||||
|
||||
## Siguiente Paso
|
||||
- Verificar si CORS refleja el Origin del request (probar con Origin header custom)
|
||||
- Probar brute force en login (sin rate limiting)
|
||||
- Investigar el error 500 en `/users/sign_in`
|
||||
- Verificar si b2b-pos.com está relacionado
|
||||
- Crear PoC de clickjacking
|
||||
Reference in New Issue
Block a user