Subdomain takeover on healthyhackathon.khanacademy.org and hackweek.khanacademy.org

Disclosed: 2019-08-25 07:02:41 By katsuragicsl To khanacademy
High
Vulnerability Details
#Summary : healthyhackathon.khanacademy.org can be took over, since it points to a bucket in S3 but that bucket does not exists. I know this domain is used to host information of healthyhackathon which is held by khanacademy, but you will not be able to do this anymore if someone is going to claim that bucket. #Reference : [S3_takeover](https://github.com/EdOverflow/can-i-take-over-xyz/issues/36) ## Impact Taking control of healthyhackathon.khanacademy.org and spoof khanacademy users that healthyhackathon is reopened/"archived for you to challenge" and collect their information.
Actions
View on HackerOne
Report Stats
  • Report ID: 474798
  • State: Closed
  • Substate: resolved
  • Upvotes: 28
Share this report