dom-access

1 article
sort: new top best
clear filter
0 8/10

Researcher demonstrates escalation of a subdomain takeover on impact.postmates.com (GitHub pages vulnerability) into session cookie theft by leveraging document.domain relaxation in the parent domain postmates.com, enabling account takeover despite the subdomain being out-of-scope. The technique exploits the fact that if the main domain explicitly sets document.domain, a compromised subdomain can set it to match and access sensitive cookies via JavaScript.

Postmates HackerOne Synack impact.postmates.com raster-static.postmates.com GitHub
blog.takemyhand.xyz · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details