Sub Domain Take over

Disclosed: 2016-02-28 18:55:19 By ketan_patil To gratipay
Medium
Vulnerability Details
Dear Team, I find bug in https://gratipay.piwik.pro/ i can take over account https://gratipay.piwik.pro/ I share with you setup 1) https://gratipay.piwik.pro/ 2) Then i see msg like this ( "THIS SUBDOMAIN IS AVAILABLE! gratipay.piwik.pro is available! Use this subdomain for your Piwik Cloud service. To activate this subdomain, simply sign up to Piwik Cloud. ") 3)Then i open http://piwik.pro/cloud 4) Put user name ans password 5) gratipay.com add in my account I share with you POC for your more information Thank you
Actions
View on HackerOne
Report Stats
  • Report ID: 111078
  • State: Closed
  • Substate: resolved
  • Upvotes: 8
Share this report