Subdomain takeover of blog.snapchat.com

Disclosed: 2016-10-05 18:41:02 By jreynoldsdev To snapchat
Unknown
Vulnerability Details
#Overview The ANAME for blog.snapchat.com, which redirects to snapchat-blog.com, was pointing to tumblr for Snapchat's blog. This blog had been expired or had removed the CNAME claim. Adding "snapchat-blog.com" to the custom domain setting on tumblr allowed takeover of this subdomain. #Repro Steps 1) Visit http://blog.snapchat.com Result: Blog registered by my account "jreynoldsdev" displays title "Hello Snapchat - Jake Reynolds" #Suggested Fixes The best fix would be for Snapchat's tumblr blog to reclaim this CNAME. For resolution contact me and we can coordinate switching the domain name back under your control. If you have any further questions please feel free to reach out. Thanks, Jake
Actions
View on HackerOne
Report Stats
  • Report ID: 171942
  • State: Closed
  • Substate: resolved
  • Upvotes: 13
Share this report