diff --git a/EXIF_Geo_Data_Not_Stripped/exif_geo.md b/EXIF_Geo_Data_Not_Stripped/exif_geo.md index 55795cd5..9d130383 100644 --- a/EXIF_Geo_Data_Not_Stripped/exif_geo.md +++ b/EXIF_Geo_Data_Not_Stripped/exif_geo.md @@ -7,9 +7,9 @@ When a user uploads an image in example.com, the uploaded image’s EXIF Geoloca 2. There are lot of images having resolutions (i.e 1280 * 720 ) , and also whith different MB’s .
3. Go to Upload option on the website
4. Upload the image
-5. see the path of uploaded image ( Either by right click on image then copy image address OR right click, inspect the image, the URL will come in the inspect , edit it as html )
-6. open it (http://exif.regex.info/exif.cgi)
-7. See wheather is that still showing exif data , if it is then Report it. +5. Capture the URL of the image served by the application, then download that processed copy.
+6. Open the downloaded copy in [Metadata Viewer](https://metadataremover.ai/metadata-viewer) to inspect its EXIF, GPS, IPTC, and XMP fields.
+7. Check whether sensitive metadata remains. Preserve the original sample and confirm important values with a second parser such as [ExifTool](https://exiftool.org/) before reporting. # Reports (Hackerone)