Security Affairs
Pegasus Used Against MEP Investigating Pegasus, Citizen Lab Finds|JADEPUFFER: First End-to-End AI-Driven Ransomware Operation|The Anatomy of a Shadow AI Supply-Chain Breach: Lessons from the 2026 Vercel Incident|Law enforcememt operation disrupted Malicious Residential Proxy Networks NetNut|Government and Healthcare Are the Weakest Links in Global Email Security|Europe Confirms Record €4.1B Penalty Against Google for Android Practices|U.S. CISA adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog|430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link|Adobe fixed multiple maximum-severity flaws in ColdFusion and Campaign Classic|Alleged Scattered Spider Hacker Extradited to U.S. to Face Cybercrime Charges|Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed|Azure CLI Targeted in LSHIY Password Spray Campaign Across 64 Orgs|Pegasus Used Against MEP Investigating Pegasus, Citizen Lab Finds|JADEPUFFER: First End-to-End AI-Driven Ransomware Operation|The Anatomy of a Shadow AI Supply-Chain Breach: Lessons from the 2026 Vercel Incident|Law enforcememt operation disrupted Malicious Residential Proxy Networks NetNut|Government and Healthcare Are the Weakest Links in Global Email Security|Europe Confirms Record €4.1B Penalty Against Google for Android Practices|U.S. CISA adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog|430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link|Adobe fixed multiple maximum-severity flaws in ColdFusion and Campaign Classic|Alleged Scattered Spider Hacker Extradited to U.S. to Face Cybercrime Charges|Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed|Azure CLI Targeted in LSHIY Password Spray Campaign Across 64 Orgs|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

Bug hunter downloaded the entire Vine source code

The Indian security expert and bug hunter Avinash has accessed and downloaded the entire Vine source code and it was really easy. A hacker has accessed and downloaded the source code of the Twitter’s Vine application. Vine is a short-form video sharing service, acquired by Twitter in 2012, that allows users to share small videos of 6 seconds […]

Bug hunter downloaded the entire Vine source code

The Indian security expert and bug hunter Avinash has accessed and downloaded the entire Vine source code and it was really easy.

A hacker has accessed and downloaded the source code of the Twitter’s Vine application. Vine is a short-form video sharing service, acquired by Twitter in 2012, that allows users to share small videos of 6 seconds looping them.

The security expert and bug hunter Avinash has discovered a flaw in Vine that allowed him to download a Docker image containing the source code of the application.

Docker is a widely used open platform for developers and sysadmins to build, ship, and run distributed applications, it allows administrators to run more apps on the same old servers.

While running a penetration test, Avinash  surprisingly discovered that Vine was using Docker images publicly available online.

Avinash used the Censys.io search engine to find dockers images online, and he found more that 80 images.

Censys.io gave me an interesting URL https://docker.vineapp.com in its result.” Avinash wrote in a blog post. “If it is supposed to be private, then why is it publicly accessible? There has to be some thing else to going on here. On googling /* private docker registry */ I get to know that the docker provides a functionality which allows a developer to host and share images through the web.”

censys Vine source code docker

One of the images named ‘vinewww‘ was related to the Vine application, he downloaded it and examined it with a docker image viewer.

Vine Source Code Docker

He could not believe what I had found! The complete source code of the Vine platform was on the screen. The code includes API keys as well as third-party keys.

“I was able to see the entire source code of vine, its API keys and third party keys and secrets. Even running the image without any parameter, was letting me host a replica of VINE locally.” added the expert.

Vine Source Code Docker 4

The hacker reported the issue to Vine that rewarded him with $10,080 Bounty award. Of course, the problem was fixed in a few minutes.

Below the complete timeline of the event that allowed the hacker to download the entire Vine Source Code.

  • March 21,2016 – Bug Reported through Hackerone
  • March 22,2016 – Need more info
  • March 31,2016 – Full exploitation shown
  • March 31,2016 – Bug fixed (within 5 min)
  • April 2,2016 – $10080 Bounty awarded

[adrotate banner=”9″]

Pierluigi Paganini

(Security Affairs – Vine Source Code, hacking)