Delivered-To: info@designerliving.com
Received: by 2002:a05:6214:588a:b0:572:8365:f630 with SMTP id md10csp3156684qvb;
        Tue, 28 Feb 2023 09:57:19 -0800 (PST)
X-Received: by 2002:a05:6808:309a:b0:378:91e4:56f9 with SMTP id bl26-20020a056808309a00b0037891e456f9mr2184685oib.0.1677607039532;
        Tue, 28 Feb 2023 09:57:19 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; t=1677607039; cv=none;
        d=google.com; s=arc-20160816;
        b=iamKrvq3waHPFa2CSfWZaqspiXIr5DYNC8tyMukdPTfRXXkwb/WQN3HOckc3hzsilr
         evmU41aGBB97C6q+MSKvIlADUENxmFwYCil77NQbqHV0XDFfv6mqEbLrgymZerx4PpUD
         s6dvYaIhHI1TOlvPDLHrLhvNf9cDmesfyQtB1JTkT85SEp+Kiw8g069M+AUb2qmc01gP
         UUdXaa9sNzz/G5Y6emgs9ICFbMgHSRJ62BRVZIbmymZCFCm5VdXowIA6T9slMa0aZ/K3
         d1xFPzkjRAMzV7c3DCdZljg49lMGqFUnOJrUh/QL6KChP7LTwBZakaD/kALeS0ddarSw
         ns8Q==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816;
        h=to:subject:message-id:date:from:in-reply-to:references:mime-version
         :dkim-signature;
        bh=pZId0sGQRXN+4d5tKxQ3ZHTkZie93NUEqnrbYyHUTQg=;
        b=QykBHd2T9D3iaPAHHLVvNDt/bSceWMNXXirPvbatOfpOswq3n03CxR3WoqQomfRYXV
         3sxEYUenRfFreHyirQi/YtxlnzgOvtgYtJ5Zi5CIAsy5TWpGsKOixvsxQsNxKdk6dDLI
         IR/aJY98BGy5MkGGfesk8k5eohG22D/6STt4jFOMpZ3GDTHuAl6Yl4/WR+aEGNbhrsHc
         1DZJivkqPJ49y7P2VevS0tOEeg+v+wkTcS+EB8JxTL1ZMnsX3Dxrnireb4espnlrOfMQ
         RiN+Qe7AOBHHJP0O+xieVldJ8fEFX7id2JS7qPRpn7ODRzJt8uNFQymC8v7a2xpM9vae
         Khdw==
ARC-Authentication-Results: i=1; mx.google.com;
       dkim=pass header.i=@gmail.com header.s=20210112 header.b=kkg8URi3;
       spf=pass (google.com: domain of danieljoseph11556@gmail.com designates 209.85.220.41 as permitted sender) smtp.mailfrom=danieljoseph11556@gmail.com;
       dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com
Return-Path: <danieljoseph11556@gmail.com>
Received: from mail-sor-f41.google.com (mail-sor-f41.google.com. [209.85.220.41])
        by mx.google.com with SMTPS id s11-20020a0568080b0b00b0037b6e150207sor2617934oij.77.2023.02.28.09.57.19
        for <info@designerliving.com>
        (Google Transport Security);
        Tue, 28 Feb 2023 09:57:19 -0800 (PST)
Received-SPF: pass (google.com: domain of danieljoseph11556@gmail.com designates 209.85.220.41 as permitted sender) client-ip=209.85.220.41;
Authentication-Results: mx.google.com;
       dkim=pass header.i=@gmail.com header.s=20210112 header.b=kkg8URi3;
       spf=pass (google.com: domain of danieljoseph11556@gmail.com designates 209.85.220.41 as permitted sender) smtp.mailfrom=danieljoseph11556@gmail.com;
       dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=gmail.com; s=20210112; t=1677607039;
        h=to:subject:message-id:date:from:in-reply-to:references:mime-version
         :from:to:cc:subject:date:message-id:reply-to;
        bh=pZId0sGQRXN+4d5tKxQ3ZHTkZie93NUEqnrbYyHUTQg=;
        b=kkg8URi3Do9HGIHW7r+uKevWvwIcDME7DeRpSIf4U6Y5f4NZsCv1uxaeM+vHU5/OyC
         KRLq7Gsm8Ye8qTxnyt3+JbNjhAWwCiBDvEejOyFafAB22HP6Rxje2QE4tBWJSFWr5Ent
         o+SpnZzhNiSpIitkf2Qn+s6T/8MHxoSJuOW4sy3N+SXnoLHrJZ9G96f64WqoVCvPzSCv
         pPJbhBOctrQ9pbyIQesaUZb3hCS22n1ACR7lzib7Sv/OKTB8CkYg5W91aOd7eVBAlBjL
         CKkKteAro091tCX/HytDZa0N16cgyC4GjWqUkJdrflFcBTbJ3vvwlXwnZJ44kObyiLpC
         rRrg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=1e100.net; s=20210112; t=1677607039;
        h=to:subject:message-id:date:from:in-reply-to:references:mime-version
         :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to;
        bh=pZId0sGQRXN+4d5tKxQ3ZHTkZie93NUEqnrbYyHUTQg=;
        b=HubWugZLpYsFhMDEtjMptV4GBjKaXsZVuIFsUuQ6+6I73ZI+C5Wn8wES09VcUtS+ri
         /A5bBk3kLzSYouCSzBYB6vGZNKxgiGh0XFIg0ET4g7vQRZOMxP+GnHJZpCVF6FtF50sa
         mkDGy3LKXwk1voC6Vove2qDiu9pKaZtdM5ZAIimrt08RpUg0lWORQhj8hh0q4HbZYmXT
         nEtTrOcZxn3iYRWV7J29cNZEG55vn1fLZcSC+2sLI39aZqu6mowluBVgOq7dzcKA1vCo
         u2ktFvwzo/sDUyaWqprVeRtiEZVc6Ngy3yPp5AXk2Fwjx4Jz1xLDYtAtRF7gkL47ZtAn
         e8Jg==
X-Gm-Message-State: AO0yUKXtsW3d0Ql6OGEZn2s70/T79YbYelZbNsGZwR+VBN8/P2FZbdyr
	MBi4v7PUUbQGh3aVzZdMXVi4zZGFDZeoO2t1GZT8Mn2HRwcVBPenrxM=
X-Google-Smtp-Source: AK7set+dEnqxwx31Sc9xPKPHSS2IHLJRVnabhCqTCsijtEiusMzHz2uQRgnvAEeKIPPR9FGqvMyXcxXw7Gp45Jl/z/s=
X-Received: by 2002:a05:6808:c9:b0:384:323b:4cab with SMTP id
 t9-20020a05680800c900b00384323b4cabmr1127960oic.0.1677607039038; Tue, 28 Feb
 2023 09:57:19 -0800 (PST)
MIME-Version: 1.0
References: <CAC3NA0AcqtgL67wYWhyx_hwyzn2qPtJbu2WRf9EdFma3BbQ0bQ@mail.gmail.com>
 <CAC3NA0DE+iq9ngpaG1sKQtFC0DOU14eYoPjAvhnAAg3zNdP8Ww@mail.gmail.com>
In-Reply-To: <CAC3NA0DE+iq9ngpaG1sKQtFC0DOU14eYoPjAvhnAAg3zNdP8Ww@mail.gmail.com>
From: Daniel joseph <danieljoseph11556@gmail.com>
Date: Tue, 28 Feb 2023 22:57:12 +0500
Message-ID: <CAC3NA0D-BVrO9FpPbB+Lu4n7JW7XWz_Y23B-_o4DxsdeBgwv9w@mail.gmail.com>
Subject: Re: Vulnerability Report-Broken Authentication
To: info@designerliving.com
Content-Type: multipart/alternative; boundary="000000000000a279b205f5c653d2"

--000000000000a279b205f5c653d2
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hi Team,

I believe that you have had an opportunity to read our previous email
regarding the vulnerability report. As it's been long already and your team
hasn't responded to the vulnerability report submitted by me, I was
expecting $500 for responsible disclosure of vulnerability.

Furthermore I would like to publicly disclose vulnerability reports on our
blogs for research and educational purposes. If you have any concerns do
let me know.

Regards,
Daniel


On Thu, Dec 8, 2022 at 12:49=E2=80=AFPM Daniel joseph <danieljoseph11556@gm=
ail.com>
wrote:

> Hi Team,
>
> Any update regarding the report and bounty?
>
> On Fri, Oct 21, 2022 at 11:28 PM Daniel joseph <
> danieljoseph11556@gmail.com> wrote:
>
>> Hey Team,
>>
>> I'm a penetration tester and bug bounty hunter. I have found a potential
>> vulnerability in the site. Please review the report below.
>>
>> Vulnerability: Broken Authentication & Session Management
>> We have observed that when we change "password" from one browser in plac=
e
>> of session expiration from another browser it just updates the password
>> from another browser and the old session gets updated without being logg=
ed
>> out. The flows goes like this:
>> Broken Authentication and Session Management > Failure to Invalidate
>> Session > On Password Change
>> Steps:
>> 1- Login from two browsers at a time [From Chrome browser and from
>> Mozilla Firefox].
>> 2- Change password in settings from chrome browser.
>> 3- Now Check Mozilla Firefox.
>> 4- Your Session got "updated" in place of expiration.
>>
>> Same goes with when using two different computer systems.
>> 1- Login from two computers at a time
>> 2- Change password in settings from computer A.
>> 3- Now Check computer B.
>> 4- Your Session got "updated" in place of expiration.
>>
>> Recommendations: If Session is Updating from one Browser/Computer so
>> other should expire first to renew session after login.
>>
>> If you require any additional information, please let me know. I'll be
>> waiting to hear from your side regarding the report and bounty.
>>
>> --
>> Regards,
>> Daniel
>>
>
>
> --
> Regards,
> Daniel
>

--000000000000a279b205f5c653d2
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Hi Team,<br><br>I believe that you have had an opportunity=
 to read our previous email regarding the vulnerability report. As it&#39;s=
 been long already and your team hasn&#39;t responded to the vulnerability =
report submitted by me, I was expecting $500 for responsible disclosure of =
vulnerability.<br><br>Furthermore I would like to publicly disclose vulnera=
bility reports on our blogs for research and educational purposes. If you h=
ave any concerns do let me know.<div><div dir=3D"ltr" class=3D"gmail_signat=
ure" data-smartmail=3D"gmail_signature"><div dir=3D"ltr"><div><br></div>Reg=
ards,<div><span style=3D"font-family:&quot;Google Sans&quot;,Roboto,RobotoD=
raft,Helvetica,Arial,sans-serif;font-size:16px;letter-spacing:0.1px;text-al=
ign:center;white-space:nowrap">Daniel</span><br></div></div></div></div><br=
></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr"=
>On Thu, Dec 8, 2022 at 12:49=E2=80=AFPM Daniel joseph &lt;<a href=3D"mailt=
o:danieljoseph11556@gmail.com">danieljoseph11556@gmail.com</a>&gt; wrote:<b=
r></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex=
;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir=3D"ltr">=
<div dir=3D"ltr"><div>Hi Team,</div><div><br></div><div>Any update regardin=
g the report and bounty?</div></div></div><br><div class=3D"gmail_quote"><d=
iv dir=3D"ltr" class=3D"gmail_attr">On Fri, Oct 21, 2022 at 11:28 PM Daniel=
 joseph &lt;<a href=3D"mailto:danieljoseph11556@gmail.com" target=3D"_blank=
">danieljoseph11556@gmail.com</a>&gt; wrote:<br></div><blockquote class=3D"=
gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(20=
4,204,204);padding-left:1ex"><div dir=3D"ltr"><div dir=3D"ltr">Hey Team,<br=
><br>I&#39;m a penetration tester and bug bounty hunter. I have found a pot=
ential vulnerability in the site. Please review the report below.<br><br>Vu=
lnerability: Broken Authentication &amp; Session Management<br>We have obse=
rved that when we change &quot;password&quot; from one browser in place of =
session expiration from another browser it just updates the password from a=
nother browser and the old session gets updated without being logged out. T=
he flows goes like this:<br>Broken Authentication and Session Management &g=
t; Failure to Invalidate Session &gt; On Password Change<br>Steps:<br>1- Lo=
gin from two browsers at a time [From Chrome browser and from Mozilla Firef=
ox].<br>2- Change password in settings from chrome browser.<br>3- Now Check=
 Mozilla Firefox.<br>4- Your Session got &quot;updated&quot; in place of ex=
piration.<br><br>Same goes with when using two different computer systems.<=
br>1- Login from two computers at a time<br>2- Change password in settings =
from computer A.<br>3- Now Check computer B.<br>4- Your Session got &quot;u=
pdated&quot; in place of expiration.<br><br>Recommendations: If Session is =
Updating from one Browser/Computer so other should expire first to renew se=
ssion after login.<br><br>If you require any additional information, please=
 let me know. I&#39;ll be waiting to hear from your side regarding the repo=
rt and bounty.<br><div><br></div>--<br><div dir=3D"ltr"><div dir=3D"ltr">Re=
gards,<div>Daniel</div></div></div></div></div>
</blockquote></div><br clear=3D"all"><div><br></div>-- <br><div dir=3D"ltr"=
><div dir=3D"ltr">Regards,<div><span style=3D"font-family:&quot;Google Sans=
&quot;,Roboto,RobotoDraft,Helvetica,Arial,sans-serif;font-size:16px;letter-=
spacing:0.1px;text-align:center;white-space:nowrap">Daniel</span><br></div>=
</div></div>
</blockquote></div>

--000000000000a279b205f5c653d2--
