domain-hijacking

2 articles
sort: new top best
clear filter
0 3/10

A researcher discovered and exploited a subdomain takeover vulnerability on feedback.owncloud.com by identifying an orphaned CNAME record pointing to Fider's infrastructure, registering a Fider account, and claiming the subdomain to demonstrate cookie/IP grabbing via CSS injection. The $200 bounty was awarded despite the researcher's assessment that the vulnerability warranted higher compensation.

ownCloud HackerOne Sublist3r Fider getfider.com
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 8/10

Technical writeup demonstrating how to identify and exploit 55,000+ subdomain takeover vulnerabilities on Shopify by analyzing CNAME records pointing to Shopify's infrastructure, including two exploitation methods (application name mapping and DNS mapping) with step-by-step methodology and large-scale scanning techniques.

Shopify buckhacker FDNS Dataset Project Sonar HackerOne
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details