Subdomain takeover of blog.snapchat.com
Unknown
Vulnerability Details
#Overview
The ANAME for blog.snapchat.com, which redirects to snapchat-blog.com, was pointing to tumblr for Snapchat's blog. This blog had been expired or had removed the CNAME claim. Adding "snapchat-blog.com" to the custom domain setting on tumblr allowed takeover of this subdomain.
#Repro Steps
1) Visit http://blog.snapchat.com
Result: Blog registered by my account "jreynoldsdev" displays title "Hello Snapchat - Jake Reynolds"
#Suggested Fixes
The best fix would be for Snapchat's tumblr blog to reclaim this CNAME. For resolution contact me and we can coordinate switching the domain name back under your control.
If you have any further questions please feel free to reach out.
Thanks,
Jake
Actions
View on HackerOneReport Stats
- Report ID: 171942
- State: Closed
- Substate: resolved
- Upvotes: 13