Subdomain Takeover in http://assets.goubiquiti.com/

Disclosed: 2016-02-14 23:30:37 By c1231665 To ui
Unknown
Vulnerability Details
Hi there, Its urgent issue about your subdomain http://assets.goubiquiti.com pointing to AWS S3 but no such website configuration is made. This unused subdomain can claim by anyone and fully take over it. An attacker can fully takeover this subdomain and do whatever he wants. this can cause huge damage to the website's main domain as well as to the company. I Recommend to remove the Cname and Dns connecting to it. PoC is attached to this report. You can read about this sort of attacks here : http://labs.detectify.com/post/109964122636/hostile-subdomain-takeover-using Please Consider my report to Support my study cheers, Karl
Actions
View on HackerOne
Report Stats
  • Report ID: 109699
  • State: Closed
  • Substate: resolved
  • Upvotes: 19
Share this report