Helpdesk Takeover at dmc.datastax.com

Disclosed: 2020-01-15 17:49:43 By matrixsoftsec To datastax
High
Vulnerability Details
## Summary: DNS record [dmc.datastax.com](dmc.datastax.com) is pointing to stale [dmc-support.zendesk.com](dmc-support.zendesk.com) domain on Zendesk which is available for takeover. DNS Stale Records: {F661014} ## Proof of Concept: There was no helpdesk configured at this address, which means that the address was available and anyone could claim it. I was able to claim dmc-support.zendesk.com. On this page, https://dmc.datastax.com/hc/en-us I haven't made the page public, I'm attaching a screenshot of the webpage: {F661004} ## Supporting Material/References: Login page: {F661021} ## Impact Subdomain takeover
Actions
View on HackerOne
Report Stats
  • Report ID: 759454
  • State: Closed
  • Substate: resolved
  • Upvotes: 189
Share this report