Subdomain takeover ██████
Critical
Vulnerability Details
The subdomain `█████` is pointing to `open-elb-prod-277276106.us-east-1.elb-amazonaws.com.`, the domain `elb-amazonaws.com` was available for registration
## Impact
Using this vulnerability an attacker can:
- host unwanted/malicious content under your domain
- receive email on subdomains mentioned above
- effectively execute cross-site scripting attacks
- in some cases, steal cookie data
- in some cases, trick password managers into filling in passwords
## System Host(s)
█████████
## Affected Product(s) and Version(s)
## CVE Numbers
## Steps to Reproduce
Visit http://████████/proof.e7437329-ab61-4f22-a049-df5b3685313a.txt
## Suggested Mitigation/Remediation Actions
Remove CNAME record █████
Actions
View on HackerOneReport Stats
- Report ID: 2552243
- State: Closed
- Substate: resolved
- Upvotes: 47