Sub Domain Take over
Medium
Vulnerability Details
Dear Team,
I find bug in https://gratipay.piwik.pro/ i can take over account https://gratipay.piwik.pro/
I share with you setup
1) https://gratipay.piwik.pro/
2) Then i see msg like this ( "THIS SUBDOMAIN IS AVAILABLE!
gratipay.piwik.pro is available! Use this subdomain for your Piwik Cloud service. To activate this subdomain, simply sign up to Piwik Cloud. ")
3)Then i open http://piwik.pro/cloud
4) Put user name ans password
5) gratipay.com add in my account
I share with you POC for your more information
Thank you
Actions
View on HackerOneReport Stats
- Report ID: 111078
- State: Closed
- Substate: resolved
- Upvotes: 8