Domain Takeover [3737signals.com]

Disclosed: 2021-08-13 18:23:31 By mrmax4o4 To basecamp
Low
Vulnerability Details
Hi, While i was analyzing the `Basecamp3` Android app i found `3737signals.com` on the source code as i understand you are passing it to the `intent`to view it on some case. {F1368921} When I opened it on the browser I got DNS error says `the domain name does not exist` {F1368922} As you can see at the bottom of the page `webmaster` is the domain name provider so I navigated to [webmaster.com](https://www.webmasters.com) and searched for `3737sihttps://www.webmasters.com/domains/new.php?domain=3737signals.com&Action=Submit&Domain=3737signals&Suffix=.com&x=0&y=0gnals.com` and found that it's available to [register](https://www.webmasters.com/domains/new.php?domain=3737signals.com&Action=Submit&Domain=3737signals&Suffix=.com&x=0&y=0) {F1368920} I am not sure if it's yours but if it's not just notify me to self close the report ## Impact - Fake website - Malicious code injection - Users tricking - Company impersonation This issue can have really huge impact on the companies reputation someone could post malicious content on the compromised site and then your users will think it's official but it's not. Best Wishes, MrMax
Actions
View on HackerOne
Report Stats
  • Report ID: 1253926
  • State: Closed
  • Substate: resolved
  • Upvotes: 43
Share this report