EC2 subdomain takeover at http://████████/
Critical
Vulnerability Details
There is a dangling DNS A record that points to an EC2 instance that no longer exists, I was able to claim the EC2 instance and host content on http://███████/.
## Steps To Reproduce:
1. Visit http://█████████/██████████.html and view the PoC: ██████
## Suggested Remediation Steps
Remove the A record pointing to the current ec2 instance.
## Impact
Hosting content on http://█████/ and potentionally fully bypassing web protections like CORS (in cases of `████████`) or redirecting users to malicious pages.
## Impact
Hosting content on http://██████/ and potentionally fully bypassing web protections like CORS (in cases of `██████████`) or redirecting users to malicious pages,
## System Host(s)
██████
## Affected Product(s) and Version(s)
## CVE Numbers
## Steps to Reproduce
Visit http://██████████/█████.html and view the PoC: █████
## Suggested Mitigation/Remediation Actions
Remove the A record pointing to the current ec2 instance.
Actions
View on HackerOneReport Stats
- Report ID: 1296366
- State: Closed
- Substate: resolved
- Upvotes: 33