Subdomain misconfiguration [mail.legalrobot.com]

Disclosed: 2017-07-31 01:46:28 By dilip_prakash To legalrobot
Unknown
Vulnerability Details
Hi Team, You subdomain mail.legalrobot.com has a CNAME record that resolved to ghs.google.com and shows error when navigating to subdomain, should remove CNAME entry for that subdomain pointing towards ghs.google.com.I couldn't verify the domain ownership process to fully takeover subdomain. mail.legalrobot.com canonical name = ghs.google.com For POC i have claim the domain of gsuite account using mail.legalrobot.com Fix: To fully resolve the issue you need to remove the CNAME record and put in place a web forwarding rule for mail.legalrobot.com towards new web landing page. Please find the attachment of POC. Thanks _prakash
Actions
View on HackerOne
Report Stats
  • Report ID: 250766
  • State: Closed
  • Substate: informative
Share this report