Skip to content

Security Report: Subdomain Takeover of https://go.polymath.network Pointing to unbounce #884

@aparcekarl

Description

@aparcekarl

Hi Polymath Security Team,

I found that your website is suffering from subdomain takeover pointing to Unbounce pages but no such page is connected to the external server which is very dangerous.

https://go.polymath.network/

Steps to Takeover:

  1. Log in to Unbounce.
  2. Select the sub-account where you want to add your custom domain.
  3. Open the Domains tab from the side navigation bar.
  4. Click Add a Domain.
  5. Select the type of custom domain, either a root domain or a sub-domain.
  6. Enter your domain name.
  7. Add Domain to confirm.

This unused subdomain can claim by anyone and fully take over it.

And attacker can fully takeover this subdomain and do whatever he wants. this can cause huge damage to the website's main domain as well as to the company.
Impact
This vulnerability is rated as severe due to the increased impact that can be escalated

I can escalate this issue to a more severe vulnerability where I can create an email address that act as admin or support team
for example:

admin@go.polymath.network
support@go.polymath.network

I Recommend to remove the Cname and Dns connecting to it.
You can read about this sort of attacks here : http://labs.detectify.com/post/109964122636/hostile-subdomain-takeover-using

Please Consider my report to Support my study

Thank you,

Karl

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions