Subdomain Takeover uptime

Disclosed: 2020-05-05 20:50:32 By ahmed_alwardani To btfs
High
Vulnerability Details
Hello Team: i can't report it to the company so i hope to accept it as a valid bug , i found subdomain takeover in your subdomain ```uptime.btfs.io``` , i found this subdomain pointed to uptimerobot and not claimed so i signedup in uptimerobot and claimed it. POC: ------ 1 - open https://uptime.btfs.io/ 2 - you need a password to login ```A123456789``` 3 - {F753695} ## Impact - Subdomain takeover can be abused to do several things like : Malware distribution Phishing / Spear phishing XSS Authentication bypass Legitimate mail sending and receiving on behalf of ford subdomain
Actions
View on HackerOne
Report Stats
  • Report ID: 824909
  • State: Closed
  • Substate: resolved
  • Upvotes: 13
Share this report