cname-misconfiguration

2 articles
sort: new top best
clear filter
0 3/10

A researcher discovered and exploited a subdomain takeover vulnerability on feedback.owncloud.com by identifying an orphaned CNAME record pointing to Fider's infrastructure, registering a Fider account, and claiming the subdomain to demonstrate cookie/IP grabbing via CSS injection. The $200 bounty was awarded despite the researcher's assessment that the vulnerability warranted higher compensation.

ownCloud HackerOne Sublist3r Fider getfider.com
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details
0 7/10

A researcher discovered a subdomain takeover vulnerability on Tokopedia by identifying a subdomain with a CNAME pointing to an expired domain, purchasing that domain for $8, and successfully taking over the subdomain to demonstrate XSS potential before reporting it for a high-severity bounty.

Tokopedia wis4nggeni Namecheap sublist3r knockpy massdns
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details