HomeSecurityNordVPN: Presented a bug that exposes sensitive customer data!

NordVPN: Bug exposed sensitive customer data!

NordVPN has revealed a bug in its payment platform that could allow sensitive and confidential customer data to be leaked. The bug could be exploited by someone with just one request. As reported by “The Register,” the vulnerability was disclosed in February on HackerOne, a bug bounty platform where researchers can reveal private security issues to vendors in exchange for financial rewards. The vulnerability, which was discovered by a researcher using the username “dakitu,” has a severity rating of 7-8.9, which means it is rated “critical.” The Insecure Direct Object Reference (IDOR) could be triggered by simply sending an HTTP POST request to the northvpn.com domain.

Without any form of authentication , a request sent to the site 's API would reveal a range of user information and data. A test account was used to pingback information, including email addresses , merchant payment records, URLs , products purchased, and amounts paid. By changing the user ID, the bug could potentially be used to view other profile information and datasets.NordVPN: Bug exposed sensitive customer data!

A NordVPN spokesperson told ZDNet that the company has confirmed with its technology team that the vulnerability was only disclosed to H1 after ensuring that no data had been compromised. The vulnerability was isolated to three small payment providers and was only exploitable for a limited time. Third-party requests for automated ID generation have always been limited. During the period the vulnerability was raised, the company's detection system did not show any suspicious activity. The company also says it is pleased with the bug bounty program, as it allows it to fix any vulnerabilities before they can be exploited for malicious activity.

The vulnerability was patched in December, and dakitu was awarded a $1,000 bug bounty. A bug bounty was also posted on NordVPN’s platform at the same time. Researcher th3pr0xyb0y uncovered an issue that limited the price of NordVPN’s forgotten password , as there was no limit on password requests. The second security issue was awarded a $500 cash reward.

Last year, the VPN service revealed a data breach at one of its data centers, caused by a remote management system owned by a third-party data center provider. NordVPN wasn’t aware of it until a hacker gained access, but given the seriousness of the issue — as VPN services rely on user trust and data protection to be successful — the company moved its business elsewhere.

 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS