Subdomain Takeover uptime
High
Vulnerability Details
Hello Team:
i can't report it to the company so i hope to accept it as a valid bug , i found subdomain takeover in your subdomain ```uptime.btfs.io``` , i found this subdomain pointed to uptimerobot and not claimed so i signedup in uptimerobot and claimed it.
POC:
------
1 - open https://uptime.btfs.io/
2 - you need a password to login ```A123456789```
3 - {F753695}
## Impact
- Subdomain takeover can be abused to do several things like :
Malware distribution
Phishing / Spear phishing
XSS
Authentication bypass
Legitimate mail sending and receiving on behalf of ford subdomain
Actions
View on HackerOneReport Stats
- Report ID: 824909
- State: Closed
- Substate: resolved
- Upvotes: 13