My First Grafana Admin Bug Bounty — with Google Dork — $xxx

Proviesec
InfoSec Write-ups
Published in
4 min readJul 20, 2023

--

Today, I will share an Information Disclosure vulnerability that I reported. It involved a Grafana login with default credentials, which I brought to the attention of a security team as part of their bug bounty program at Hackerone. I discovered this Grafana login through a useful Google Dork of mine.

What is Google Dorks?

--

--