Brad Dandler
kiwifarms.net
- Joined
- Jan 29, 2021
What do you mean by "all their metrics?" Could you link the pages you're referring to? If you're talking about these pages:Basically all of their metrics. The panel had an option to create an account to access it open.
https://api.cozy.tv/public/zpc?fn=getHomepage
https://api.cozy.tv/public/zpc?fn=getChannelInfo&channel=nick
they are not are at all indicative of poor/insecure design. The Cozy website is a single-page application, it uses the information returned by those API pages to fill in the content on the site. The API pages being public is not a mistake or a design flaw, it is literally how this type of website works. Additionally, the information that is returned on those pages could just be gathered by scraping the site; it is not sensitive in any way. I mean for fuck's sake, the URLs literally have "public" in them.
As for the backend panel, if you're referring to https://rocket.cozy.tv, this is a third-party piece of analytics software. (see: https://plausible.io) It seems like they are hosting it themselves using the community edition. Creating an account lets you track analytics on a site that you own, but doesn't give you access to Cozy's analytics. In order to gain access to them, you would have to find and exploit a vulnerability in Plausible.
This all feels like deja vu.