Need to see if your shared folder is taking up space on your dropbox 👨‍💻? Find out how to check here.

Forum Discussion

GalacticOcean's avatar
GalacticOcean
New member | Level 2
2 years ago
Solved

Security Concern Want To Talk In Private.

Hello , My name is Mujtaba and i am a researcher in bugcrowd as galacticocean . i want to talk in private about a critical vulnerability that i have found in dropbox . you can give me an email address or make this post private if this is an option .

  • Nancy's avatar
    Nancy
    2 years ago

    Hey GalacticOcean, sorry for jumping in. 

     

    To report a bug/potential vulnerability to the relevant department directly, I’d suggest doing so via Bugcrown, as mentioned here.

     

    Thanks!

4 Replies

Replies have been turned off for this discussion
  • Megan's avatar
    Megan
    Icon for Dropbox Community Moderator rankDropbox Community Moderator
    2 years ago

    Hey there, GalacticOcean, I hope you're doing well!

     

    As a starting point you can have a look at this article. 

     

    Now as for your request, would you be able to share some generic info here with us, in order to understand better what it is that you're looking for? 

     

    Let me know more, and we'll take it from there! 

  • GalacticOcean's avatar
    GalacticOcean
    New member | Level 2
    2 years ago
    Can you provide me email address so we can talk this in private without publicly disclosing .
  • GalacticOcean's avatar
    GalacticOcean
    New member | Level 2
    2 years ago

    I have found files in a dropbox subdomain website . which can contain sensitive info like email address , password of accounts and etc which are acquired by dropbox from the customers. These files are blank because some these files are written in server side language and some are configured in a way that a user can not see it . There is no barrier between  the files and the user . user can access these files anytime without login . if you want to know the files name . ask me . 

  • Nancy's avatar
    Nancy
    Icon for Dropbox Community Moderator rankDropbox Community Moderator
    2 years ago

    Hey GalacticOcean, sorry for jumping in. 

     

    To report a bug/potential vulnerability to the relevant department directly, I’d suggest doing so via Bugcrown, as mentioned here.

     

    Thanks!

About Security and Permissions

Start a discussion in the Dropbox Community forum to get help with your account security and permissions. Find support from Community members.

The Dropbox Community team is active from Monday to Friday. We try to respond to you as soon as we can, usually within 2 hours.

If you need more help you can view your support options (expected response time for an email or ticket is 24 hours), or contact us on X, Facebook or Instagram.

For more info on available support options for your Dropbox plan, see this article.

If you found the answer to your question in this Community thread, please 'like' the post to say thanks and to let us know it was useful!