Dangling DNS Record docs.jitsi.net (unsuccessful GSuite takeover)

Disclosed: 2023-04-03 00:36:41 By bababounty99 To 8x8-bounty
Low
Vulnerability Details
HI Team , it is possible for a Attacker to do Sub-domain takeover - http://docs.jitsi.net/ As we can see in the Screenshot it is 404 and belongs to ghs google As I tried claiming the domain it was possible for me to claim it by using workspace . Hence it is possible to do Sub-domain Takeover ## Impact An attacker can claim this subdomain by requesting a process of registering this abandoned subdomain to his name. And attacker can fully take over this subdomain and do whatever he wants. this can cause huge damage to the website's main domain as well as to the company. I Recommend removing the Cname and DNS connecting to it. You can read about this sort of attacks here : https://www.siteground.com/tutorials/googleapps/google_calendar.htm
Actions
View on HackerOne
Report Stats
  • Report ID: 1354066
  • State: Closed
  • Substate: resolved
  • Upvotes: 7
Share this report