heroku

1 article
sort: new top best
clear filter
0 6/10

Researcher discovered a wildcard subdomain takeover vulnerability on uber.design by identifying that the domain's wildcard DNS pointed to Heroku's unclaimed infrastructure, allowing registration of arbitrary subdomains (*.uber.design) and potential email spoofing via Google Workspace verification.

Uber HackerOne Heroku Google G-Suite Muhammad Khizer Javed uranium238
blog.securitybreached.org · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details