Ebuddy Web Messenger Disclosure / CSRF Vulnerabilities

Juan Carlos Garcia
Security Risk Low
web applications
Date add
Ebuddy Web Messenger Index of Disclosure / htaccess file readable / HTML Form without CSRF Protection / User Credential sent in clear text

#Title: Ebuddy  htaccess file readable / HTML Form without CSRF Protection / User Credential sent in clear text


#Author:Juan Carlos García (@secnight)

#Follow me 


Index of / Disclosure


htaccess file readable

Vulnerability description

This directory contains an .htaccess file that is readable. This may indicate a server misconfiguration. htaccess files 
are designed to be parsed by web server and should not be directly accessible. These files could contain sensitive information 
that could help an attacker to conduct further attacks. It's recommended to restrict access to this file.

Affected items


The impact of this vulnerability

Sensitive information disclosure.


HTML form without CSRF protection

Cross-site request forgery, also known as a one-click attack or session riding and abbreviated as 
CSRF or XSRF, is a type of malicious exploit of a website whereby unauthorized commands are transmitted
from a user that the website trusts.

Affected items


The impact of this vulnerability
An attacker may force the users of a web application to execute actions of the attacker's choosing.
A successful CSRF exploit can compromise end user data and operation in case of normal user. If the targeted end 
user is the administrator account, this can compromise the entire web application.


User credentials are sent in clear text

Vulnerability description
User credentials are transmitted over an unencrypted channel. 
This information should always be transferred via an encrypted channel (HTTPS) 
to avoid being intercepted by malicious users.

Affected items


The impact of this vulnerability

A third party may be able to read the user credentials by intercepting an unencrypted HTTP connection


This type of failure Messengers line they have so many customers are extremely dangerous because they 
can be a serious impact on customers and users

Write Secure Code


This vulnerability has been discovered
by Juan Carlos García(@secnight)

Special Thnaks:Perseo


The Author accepts no responsibility for any damage
caused by the use or misuse of this information.

