EC2 subdomain takeover at http://████████/

Disclosed: 2022-02-14 21:24:17 By dreyand_ To deptofdefense
Critical
Vulnerability Details
There is a dangling DNS A record that points to an EC2 instance that no longer exists, I was able to claim the EC2 instance and host content on http://███████/. ## Steps To Reproduce: 1. Visit http://█████████/██████████.html and view the PoC: ██████ ## Suggested Remediation Steps Remove the A record pointing to the current ec2 instance. ## Impact Hosting content on http://█████/ and potentionally fully bypassing web protections like CORS (in cases of `████████`) or redirecting users to malicious pages. ## Impact Hosting content on http://██████/ and potentionally fully bypassing web protections like CORS (in cases of `██████████`) or redirecting users to malicious pages, ## System Host(s) ██████ ## Affected Product(s) and Version(s) ## CVE Numbers ## Steps to Reproduce Visit http://██████████/█████.html and view the PoC: █████ ## Suggested Mitigation/Remediation Actions Remove the A record pointing to the current ec2 instance.
Actions
View on HackerOne
Report Stats
  • Report ID: 1296366
  • State: Closed
  • Substate: resolved
  • Upvotes: 33
Share this report