How I got into Nokia HOF in 5 Mins

https://www.nokia.com/notices/responsible-disclosure/

In this write-up, I will share my journey of how I got into the Nokia Hall of Fame through GitHub dorkings. I hope that my experience will inspire others to pursue their passion for security research and report vulnerabilities responsibly.

Abstract

What is GitHub Dorking?

GitHub Dorking is a technique that involves using advanced search operators in GitHub to find sensitive information or vulnerabilities in public repositories.

Methodology

First of all, I don’t use any Automated Tools in this type of recon “Github Recon”
That’s why you can find a lot of treasures that some people just left it behind depending only on Automated Tools.

Ok, Let’s Pull the Stuff…

website.tld github

Actually, it’s frustrating to check all of these code snippets one by one...
One thing you can do is to check the most popular dorks that find treasures through these snippets.

This list helped me get some cool dorks: https://github.com/techgaun/github-dorks/blob/master/github-dorks.txt

After spending some minutes, fortunately, I found this file holding the Database username and password Publicly!

Reporting

I wrote a report to their Responsible Disclosure E-Mail and After 3 Hrs they Just Replied with this

Don’t hesitate to reach out: https://twitter.com/sl4x0

--

--

CS Student | Security Researcher | Author of: CVE-2022-4093 and CVE-2022-4409

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store
Abdelrhman Allam (sl4x0)

CS Student | Security Researcher | Author of: CVE-2022-4093 and CVE-2022-4409