Skip to content

Security1 publisher3 min readPublished

Gyazo's breach exposed the 32-character image IDs that were the only protection on older captures

Helpfeel says an attacker took about 490 million Gyazo image metadata records, including the IDs that build every capture link, and the company has disabled viewing of some images and asked every user to change their password.

The Watch · Security desk

Illustration accompanying Gyazo's breach exposed the 32-character image IDs that were the only protection on older captures

What happened

  • Helpfeel says the attacker exploited a vulnerability in Gyazo's image upload server, ran arbitrary commands on its systems and reached the Gyazo database; it has not said what kind of flaw it was.
  • About 23.62 million user records were exposed, including email addresses and password hashes, according to the Kyoto company's notice published Wednesday.
  • About 490 million image metadata records were also exposed, mostly for images registered in January 2019 or earlier, including the IDs that make up Gyazo image links.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure A default Gyazo capture is protected by nothing but its link, so whoever holds the metadata set can pull images uploaded years ago by accounts that have not logged in since.
  • constraint The one action Helpfeel asked of users does not reach the exposure: passwords rotate, image IDs do not, and a free account can see only its 10 most recent captures on the site to prune the older ones.
  • capability Because each image ID sits beside OCR text taken from inside the capture, an attacker can pick targets by keyword before requesting a single URL.
  • contradiction Gyazo's help pages still tell users a capture link "can't be guessed," while Helpfeel's own notice says the leaked IDs can be used to view images without permission.

Every Gyazo capture link is built from a 32-character image ID. Gyazo's help pages say a capture stays private until its link is shared, that anyone holding the link can see it, and that the ID is long enough that a link "can't be guessed" [11]. At the default setting the link is the only thing protecting the file, and the leaked records hold the part of the link that made it unguessable [12].

The set can be filtered before anything is fetched. Helpfeel's list of exposed metadata fields includes the image ID, the upload IP address, the User-Agent, EXIF location data where the image carried it, the image title, the source URL, and OCR text extracted from the image [16]. That OCR text comes from a paid feature users switch on themselves, which then scans every image on the account [20]. Search the dump for a hostname, then request only the URLs that match. Retrieval is an ordinary GET against a live link.

Helpfeel put the affected records at about 14.4% of its image-related data [14]. That makes the full set roughly 3.4 billion records [21]. The affected ones are mostly images registered in January 2019 or earlier [2]. Metadata for a further 2.4 million images was pulled using what the company called "specific filtering criteria" [15].

Helpfeel asked every Gyazo user to change their password, and to change it anywhere else the same or a similar one is in use [5]. That closes the account. It does nothing to a 2018 capture whose ID is in the dump and whose URL still resolves. A free account can browse only its 10 most recent captures on Gyazo's site, and Gyazo says older captures are not deleted and stay reachable by anyone with the URL [13].

The attacker also obtained a list identifying private images. Helpfeel said it "cannot rule out the possibility that the third party may have viewed some private images" [18]. On Gyazo a private capture is either one set to "Only me," which the help pages say cannot be viewed even by someone who knows the link, or one locked with a password, and both settings are paid-plan only [19]. The exposed metadata fields include a hashed passphrase for private images [16].

On the credential side, the user records can include device IDs, login session IDs, X integration tokens and the email address used for Google single sign-on [6]. Helpfeel said it reviewed the exposed authentication data and took "the necessary measures, including invalidation and restrictions" [9]. Gyazo's verification code for logins from a new IP address is a login-time check [10]. No payment card data was exposed [7].

The company did not say which images it disabled, what the second filter selected for, which authentication items it invalidated, or whether the exposed session IDs remain valid [3][15][9][10].

The 23.62 million figure counts records, not people. It includes anonymous accounts with no registered email address, and Helpfeel said it is still working out how many people had personal information exposed [8].

What to watch

  • Whether Helpfeel identifies the upload-server flaw and the dates the attacker had command execution.
  • Whether the 2.4 million records pulled with "specific filtering criteria" include images newer than January 2019.
  • Whether Helpfeel gives users a way to check which of their captures are in the affected sets, and when the disabled images come back online.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories