starbucks

1 article
sort: new top best
clear filter
0 5/10

A $2,000 bug bounty for subdomain takeover on Starbucks via an unverified Azure Traffic Manager CNAME record that pointed to a non-existent trafficmanager.net subdomain, allowing the attacker to register and control the endpoint without domain ownership verification.

Starbucks Microsoft Azure Azure Traffic Manager wfmnarptpc.starbucks.com s00149tmppcrpt.trafficmanager.net Patrik Hudak
0xpatrik.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details