# Reconocimiento - Refaccionarias del Valle (Heroku) **Objetivo:** https://refaccionariasdelvalle.herokuapp.com **Fecha:** 2026-03-25 ## Infraestructura - **Hosting:** Heroku (Salesforce) - **Servidor:** Heroku Router - **Tecnología:** Ruby on Rails (cookie `_refaccionariasdelvalle_session`, X-Runtime header) - **Frontend:** jQuery - **SSL:** Amazon (wildcard *.herokuapp.com) — válido hasta 2027-01-29 - **CORS:** Access-Control-Allow-Origin apunta a `d134yvfg5nzhu8.cloudfront.net` ## Headers de Seguridad | Header | Estado | |--------|--------| | HSTS | OK (max-age=63072000; includeSubDomains) | | Content-Security-Policy | FALTA | | X-Frame-Options | ALLOWALL (inseguro) | | X-Content-Type-Options | FALTA | | X-XSS-Protection | FALTA | | Referrer-Policy | FALTA | | Permissions-Policy | FALTA | ## Hallazgos | # | Hallazgo | Severidad | |---|----------|-----------| | 1 | **X-Frame-Options: ALLOWALL** — vulnerable a clickjacking | ALTA | | 2 | **Endpoint `/users/sign_in` retorna 500** — error interno, posible Devise mal configurado, info disclosure en errores | ALTA | | 3 | **CORS abierto** — `Access-Control-Allow-Origin: https://d134yvfg5nzhu8.cloudfront.net/` con `Allow-Credentials: true` y todos los métodos (POST, PUT, DELETE, GET, OPTIONS) | ALTA | | 4 | **Link a cPanel webmail expuesto** — `chi-pnode6.websitehostserver.net:2096` visible en footer del login | MEDIA | | 5 | **Link a sistema externo** — `b2b-pos.com/login` enlazado desde la página de login (sistema B2B/POS) | MEDIA | | 6 | 5 de 7 headers de seguridad ausentes | MEDIA | | 7 | Cookie de sesión Rails con HttpOnly + Secure (bien configurada) | OK | | 8 | HSTS habilitado con max-age alto (bien) | OK | | 9 | CSRF token de Rails expuesto en meta tags (normal para Rails) | INFO | | 10 | robots.txt apunta a sitemap del dominio principal | INFO | ## Página de Login - **URL:** `/cuentas/ingresar` - **Framework:** Rails con Devise (formulario `new_user`) - **Campos:** `user[email]`, `user[password]`, `user[remember_me]` - **Sin CAPTCHA ni rate limiting visible** - **Footer expone:** enlace a correo corporativo (cPanel webmail) y enlace a b2b-pos.com ## Endpoints Descubiertos | Ruta | Respuesta | Nota | |------|-----------|------| | `/` | Redirect → login | App requiere autenticación | | `/cuentas/ingresar` | 200 | Login de Devise | | `/admin` | 302 → `/cuentas/ingresar` | Admin protegido | | `/users/sign_in` | 500 | **Error interno** — posible ruta Devise rota | | `/api` | 302 → `/` | API requiere auth | | `/robots.txt` | 200 | Sitemap del dominio principal | ## CORS Detalle ``` Access-Control-Allow-Credentials: true Access-Control-Allow-Headers: Origin, X-Requested-With, Content-Type, Accept, Authorization Access-Control-Allow-Methods: POST, PUT, DELETE, GET, OPTIONS Access-Control-Allow-Origin: https://d134yvfg5nzhu8.cloudfront.net/ ``` Si el origin se refleja dinámicamente, podría permitir CSRF cross-origin. ## Siguiente Paso - Verificar si CORS refleja el Origin del request (probar con Origin header custom) - Probar brute force en login (sin rate limiting) - Investigar el error 500 en `/users/sign_in` - Verificar si b2b-pos.com está relacionado - Crear PoC de clickjacking