readme.io

1 article
sort: new top best
clear filter
0 6/10

A subdomain takeover vulnerability was discovered on flock.co where the subdomain newdev.flock.co had a CNAME record pointing to readme.io's infrastructure, but the custom domain was never claimed in readme.io's project settings, allowing an attacker to register a readme.io account and claim ownership of the vulnerable subdomain.

flock.com flock.co newdev.flock.co readme.io cname.readme.io
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details