dns-misconfiguration

9 articles
sort: new top best
clear filter
0 6/10

A subdomain takeover vulnerability was discovered on live.lamborghini.com where an expired CloudFront distribution CNAME allowed an attacker to claim the subdomain by creating their own AWS S3 bucket and CloudFront distribution. The researcher demonstrated the attack by registering the subdomain and uploading malicious content, highlighting the risk of phishing and impersonation attacks.

Lamborghini live.lamborghini.com AWS CloudFront S3 Muhammad Khizer Javed
blog.securitybreached.org · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 5/10

A $2,000 bug bounty for subdomain takeover on Starbucks via an unverified Azure Traffic Manager CNAME record that pointed to a non-existent trafficmanager.net subdomain, allowing the attacker to register and control the endpoint without domain ownership verification.

Starbucks Microsoft Azure Azure Traffic Manager wfmnarptpc.starbucks.com s00149tmppcrpt.trafficmanager.net Patrik Hudak
0xpatrik.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 7/10

A subdomain takeover vulnerability in Starbucks where svcgatewayus.starbucks.com pointed to a non-existent Azure Cloud Service resource, allowing takeover via DNS NXDOMAIN verification and custom domain registration in Azure portal. The researcher demonstrates the attack methodology specific to Azure's dedicated IP architecture versus virtual host-based services.

Starbucks Microsoft Azure svcgatewayus.starbucks.com 1fd05821-7501-40de-9e44-17235e7ab48b.cloudapp.net Patrik Hudak Visual Studio
0xpatrik.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 4/10

Researcher discovered a subdomain takeover vulnerability in Bugcrowd's bugcrowdtrafficcontrol.com domain by exploiting misconfigured DNS pointing to Fastly and Pantheon services, allowing registration of the domain in his own CDN account. The vulnerability was reported to Bugcrowd and closed as N/A despite receiving a $600 bounty.

Bugcrowd bugcrowdtrafficcontrol.com Fastly CloudFront Pantheon Cloudflare MuhammadKhizerJaved
blog.securitybreached.org · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 2/10

A researcher discovered and exploited a subdomain takeover vulnerability where a subdomain (hootsuite.site.com) mapped to Netlify via CNAME record was unclaimed, allowing registration and full takeover. The researcher was rewarded $200 for the finding.

Ali Razzaq Netlify findsubdomains.com
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 6/10

A subdomain takeover vulnerability was discovered on flock.co where the subdomain newdev.flock.co had a CNAME record pointing to readme.io's infrastructure, but the custom domain was never claimed in readme.io's project settings, allowing an attacker to register a readme.io account and claim ownership of the vulnerable subdomain.

flock.com flock.co newdev.flock.co readme.io cname.readme.io
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 8/10

Technical writeup demonstrating how to identify and exploit 55,000+ subdomain takeover vulnerabilities on Shopify by analyzing CNAME records pointing to Shopify's infrastructure, including two exploitation methods (application name mapping and DNS mapping) with step-by-step methodology and large-scale scanning techniques.

Shopify buckhacker FDNS Dataset Project Sonar HackerOne
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 7/10

A researcher discovered a subdomain takeover vulnerability on Tokopedia by identifying a subdomain with a CNAME pointing to an expired domain, purchasing that domain for $8, and successfully taking over the subdomain to demonstrate XSS potential before reporting it for a high-severity bounty.

Tokopedia wis4nggeni Namecheap sublist3r knockpy massdns
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 3/10

A subdomain takeover vulnerability was discovered on a Pantheon-hosted domain where an unclaimed subdomain displaying 'Unknown Site' could be claimed by registering a Pantheon account and routing a sandbox domain to the vulnerable subdomain, allowing content injection.

Pantheon Donald J Trump
smaranchand.com.np · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details