cname-record

2 articles
sort: new top best
clear filter
0 5/10

A $2,000 bug bounty for subdomain takeover on Starbucks via an unverified Azure Traffic Manager CNAME record that pointed to a non-existent trafficmanager.net subdomain, allowing the attacker to register and control the endpoint without domain ownership verification.

Starbucks Microsoft Azure Azure Traffic Manager wfmnarptpc.starbucks.com s00149tmppcrpt.trafficmanager.net Patrik Hudak
0xpatrik.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details
0 2/10

A researcher discovered and exploited a subdomain takeover vulnerability where a subdomain (hootsuite.site.com) mapped to Netlify via CNAME record was unclaimed, allowing registration and full takeover. The researcher was rewarded $200 for the finding.

Ali Razzaq Netlify findsubdomains.com
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details