-
-
Notifications
You must be signed in to change notification settings - Fork 753
Is uservoice subdomain takeover possible? #163
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
Wondering this myself as a former UserVoice user. CC @austintaylor @attack7 @hoffoo |
@n41n4 @HammyHavoc It is not possible - subdomain cnames are unique and cannot be reused |
Thanks for that! Thought as much. I had somebody reach out asking for a bug bounty reward in exchange for this "information". |
More info https://hackerone.com/reports/269109 |
@pdelteil So is it vulnerable? |
But it can cause Broken link hijacking if the name.uservoice.com is directly embedded in a site. |
I have found a program where website its response is 404 and Its Cname is pointing to uservoice.com.
I didn't find any registration portal for that site.
Anyone Help me please
The text was updated successfully, but these errors were encountered: