-
-
Notifications
You must be signed in to change notification settings - Fork 795
Open
Labels
vulnerableSomeone has provided proof in the issue ticket that one can hijack subdomains on this service.Someone has provided proof in the issue ticket that one can hijack subdomains on this service.
Description
Service name
Uberflip
Proof
https://hackerone.com/reports/863551
Documentation
If the subdomain shows error "Non-hub domain, The URL you've accessed does not provide a hub. Please check the URL and try again." and is pointing toward read.uberflip.com then it is vulnerable to takeover because according to uberflip "The only protection is the customer’s proper management of their subdomains.
For this reason, we do not recommend customers point wildcards to us, and that they follow DNS management best practices by periodically reviewing all their hostnames and subdomains."
Thanks,
Aman Shahid
https://twitter.com/amansmughal
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
vulnerableSomeone has provided proof in the issue ticket that one can hijack subdomains on this service.Someone has provided proof in the issue ticket that one can hijack subdomains on this service.