<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: View Source code with browser on organisation user or administrator page. in Cloud Networking Platform</title>
    <link>https://community.cisco.com/t5/cloud-networking-platform/view-source-code-with-browser-on-organisation-user-or/m-p/5439514#M10027</link>
    <description>&lt;P&gt;If you think you have found actual security issues you should report them via the Bug Bounty program.  You can earn cash this way.&lt;/P&gt;&lt;P&gt;&lt;A href="https://bugcrowd.com/ciscomeraki" target="_self" rel="nofollow noopener noreferrer"&gt;https://bugcrowd.com/ciscomeraki&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You can also email the Cisco PSIRT team.&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:psirt@cisco.com" target="_blank" rel="nofollow noopener noreferrer"&gt;psirt@cisco.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I've had a quick look at the pages.  For the admin users, are you referring to the "secret" field?  I don't know the format of this field.  I'm going to guess it is a salted hash of some kind.&lt;/P&gt;&lt;P&gt;I can see the &lt;SPAN&gt;psk_passphrase field you refer to.  It seems a funny place to have it on this page.  Note you can retrieve this anyway from the Wireless/SSIDs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I can't see any reason why it should be on this page - so you should report it to the Bug Bount program.  I'm not sure you'll get a reward for this, since it is retrievable anyway, and I think it will get classified as minor.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 02 Apr 2019 22:20:59 GMT</pubDate>
    <dc:creator>Philip D'Ath</dc:creator>
    <dc:date>2019-04-02T22:20:59Z</dc:date>
    <item>
      <title>View Source code with browser on organisation user or administrator page.</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/view-source-code-with-browser-on-organisation-user-or/m-p/5439513#M10026</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;When you browse to network-wide Administrator or User and you click the right mouse button and select view source.&lt;/P&gt;&lt;P&gt;You will see the password encrypted of the admin users. On the User page you also can find the PSA of the Wifi(plaintext).&lt;/P&gt;&lt;P&gt;I understand that they are encrypted but there is always some who can uncrypt the passwords.&lt;/P&gt;&lt;P&gt;Does anybody know why meraki show this information in the source code?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2019 22:05:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/view-source-code-with-browser-on-organisation-user-or/m-p/5439513#M10026</guid>
      <dc:creator>StefanStout</dc:creator>
      <dc:date>2019-04-02T22:05:14Z</dc:date>
    </item>
    <item>
      <title>Re: View Source code with browser on organisation user or administrator page.</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/view-source-code-with-browser-on-organisation-user-or/m-p/5439514#M10027</link>
      <description>&lt;P&gt;If you think you have found actual security issues you should report them via the Bug Bounty program.  You can earn cash this way.&lt;/P&gt;&lt;P&gt;&lt;A href="https://bugcrowd.com/ciscomeraki" target="_self" rel="nofollow noopener noreferrer"&gt;https://bugcrowd.com/ciscomeraki&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You can also email the Cisco PSIRT team.&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:psirt@cisco.com" target="_blank" rel="nofollow noopener noreferrer"&gt;psirt@cisco.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I've had a quick look at the pages.  For the admin users, are you referring to the "secret" field?  I don't know the format of this field.  I'm going to guess it is a salted hash of some kind.&lt;/P&gt;&lt;P&gt;I can see the &lt;SPAN&gt;psk_passphrase field you refer to.  It seems a funny place to have it on this page.  Note you can retrieve this anyway from the Wireless/SSIDs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I can't see any reason why it should be on this page - so you should report it to the Bug Bount program.  I'm not sure you'll get a reward for this, since it is retrievable anyway, and I think it will get classified as minor.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2019 22:20:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/view-source-code-with-browser-on-organisation-user-or/m-p/5439514#M10027</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2019-04-02T22:20:59Z</dc:date>
    </item>
  </channel>
</rss>

