Skip to content

Subdomain Takeover BUG - scout.coinfabrik.com #135

@Dgirlwhohacks

Description

@Dgirlwhohacks

Hey Team,
I am a Security researcher and Bug Bounty Hunter,
I have found one of your domains vulnerable to subdomain takeover due to unclaimed cname pointing to GitHub which means anyone on the internet could take over the domain and can host malicious content or even a phishing campaign

kindly fix them by either removing cname pointing to GitHub or letting me know I will release the domain from here so you can take it

Vulnerable URL - http://scout.coinfabrik.com
I have taken the domain and hosted small poc text for your reference.

I've attached the image here.

Screenshot 2024-10-08 at 2 34 16 PM

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions