Request to route quran.com/sunnah.com security vulnerability reports

Category: Questions & membership Priority: P2 Severity: n/a Area: security Reports: 1 Status: Open

Summary

A user first wrote in to report an Android UI transparency bug in the Qaf app, then — having heard Abdellatif previously worked at quran.com — pivoted to say he had found several security vulnerabilities across the quran.com / sunnah.com properties and could not get a response from that team, and asked Abdellatif to share a contact there. The reported issues are concrete and serious (publicly exposed phpinfo() leaking internal IP and stack, an exposed phpMyAdmin behind only Basic Auth, an unauthenticated Jenkins GitHub webhook, an exposed Docker Registry, and an OTP endpoint with no rate limiting). This is not a Qaf product defect, but it is a genuine security disclosure that deserves routing to the right people. Abdellatif suggested opening a GitHub issue and joining their Discord; the reporter said he later reached a team member (possibly "Osama Sayed") but was unsure all issues were fixed.

What users say

scnz scnz141@gmail.com

Says he found security vulnerabilities on quran.com/sunnah.com properties, tried to contact that team without a response, and — knowing Abdellatif worked at quran.com — asks him to share a contact. He lists several specific findings.

Brother sorry to say this but i heard you worked at quran.com and i found some security vulnerabilities on their site and i tried to contact them but didn't get any respond if you have any contact with them please share

On follow-up about whether the issues were resolved:

I contacted one of their team member i think his name is osama sayed But i am not sure they have fixed all the issues

Few days before i was able to run scripts that generated request volume equal to roughly 30% of the sites total traffic without being throttled or blocked using just my phone

Abdellatif's reply:

Oh, these are pretty important. Have you tried creating an issue on their github? Would also recommend that you join their discord and find the admins

Details / repro

Reported vulnerabilities (verbatim from the reporter), for the quran.com / sunnah.com properties — NOT Qaf:

Threads