4 ms·
Sub-domain takeover attack. The sub-domain was CNAME'ed to a S3 bucket and the S3 bucket had likely been deleted. The porn purveyor, re-created a new S3 bucket
by Firefishy 5y ago
Sub-domain takeover attack. The sub-domain was CNAME'ed to a S3 bucket and the S3 bucket had likely been deleted. The porn purveyor, re-created a new S3 bucket with pr0n.
A scanner that would have caught the vulnerability:
https://tech.ovoenergy.com/how-we-prevented-subdomain-takeovers-and-saved-000s/ https://tech.ovoenergy.com/how-we-prevented-subdomain-takeov...
Or a grey hat scanner for finding sub-domains vulnerable to takeover:
https://github.com/m4ll0k/takeover https://github.com/m4ll0k/takeover
- ackbar03 5y agoYes. These are pretty much standard fodder for bugs reported on somewhere like hackerone. I guess someone who knew what he was doing just decided to take advantage of it lol