3.1 KiB
3.1 KiB
Reconocimiento - Refaccionarias del Valle (Heroku)
Objetivo: https://refaccionariasdelvalle.herokuapp.com Fecha: 2026-03-25
Infraestructura
- Hosting: Heroku (Salesforce)
- Servidor: Heroku Router
- Tecnología: Ruby on Rails (cookie
_refaccionariasdelvalle_session, X-Runtime header) - Frontend: jQuery
- SSL: Amazon (wildcard *.herokuapp.com) — válido hasta 2027-01-29
- CORS: Access-Control-Allow-Origin apunta a
d134yvfg5nzhu8.cloudfront.net
Headers de Seguridad
| Header | Estado |
|---|---|
| HSTS | OK (max-age=63072000; includeSubDomains) |
| Content-Security-Policy | FALTA |
| X-Frame-Options | ALLOWALL (inseguro) |
| X-Content-Type-Options | FALTA |
| X-XSS-Protection | FALTA |
| Referrer-Policy | FALTA |
| Permissions-Policy | FALTA |
Hallazgos
| # | Hallazgo | Severidad |
|---|---|---|
| 1 | X-Frame-Options: ALLOWALL — vulnerable a clickjacking | ALTA |
| 2 | Endpoint /users/sign_in retorna 500 — error interno, posible Devise mal configurado, info disclosure en errores |
ALTA |
| 3 | CORS abierto — Access-Control-Allow-Origin: https://d134yvfg5nzhu8.cloudfront.net/ con Allow-Credentials: true y todos los métodos (POST, PUT, DELETE, GET, OPTIONS) |
ALTA |
| 4 | Link a cPanel webmail expuesto — chi-pnode6.websitehostserver.net:2096 visible en footer del login |
MEDIA |
| 5 | Link a sistema externo — b2b-pos.com/login enlazado desde la página de login (sistema B2B/POS) |
MEDIA |
| 6 | 5 de 7 headers de seguridad ausentes | MEDIA |
| 7 | Cookie de sesión Rails con HttpOnly + Secure (bien configurada) | OK |
| 8 | HSTS habilitado con max-age alto (bien) | OK |
| 9 | CSRF token de Rails expuesto en meta tags (normal para Rails) | INFO |
| 10 | robots.txt apunta a sitemap del dominio principal | INFO |
Página de Login
- URL:
/cuentas/ingresar - Framework: Rails con Devise (formulario
new_user) - Campos:
user[email],user[password],user[remember_me] - Sin CAPTCHA ni rate limiting visible
- Footer expone: enlace a correo corporativo (cPanel webmail) y enlace a b2b-pos.com
Endpoints Descubiertos
| Ruta | Respuesta | Nota |
|---|---|---|
/ |
Redirect → login | App requiere autenticación |
/cuentas/ingresar |
200 | Login de Devise |
/admin |
302 → /cuentas/ingresar |
Admin protegido |
/users/sign_in |
500 | Error interno — posible ruta Devise rota |
/api |
302 → / |
API requiere auth |
/robots.txt |
200 | Sitemap del dominio principal |
CORS Detalle
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Origin, X-Requested-With, Content-Type, Accept, Authorization
Access-Control-Allow-Methods: POST, PUT, DELETE, GET, OPTIONS
Access-Control-Allow-Origin: https://d134yvfg5nzhu8.cloudfront.net/
Si el origin se refleja dinámicamente, podría permitir CSRF cross-origin.
Siguiente Paso
- Verificar si CORS refleja el Origin del request (probar con Origin header custom)
- Probar brute force en login (sin rate limiting)
- Investigar el error 500 en
/users/sign_in - Verificar si b2b-pos.com está relacionado
- Crear PoC de clickjacking