-
-
Notifications
You must be signed in to change notification settings - Fork 735
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Uptimerobot.com Custom Domain Takeover #45
Comments
What is the error on browser? Page not found? 404? page not found? I cannot seem to find a sample not found page. |
yes. it say "page not found" |
Thank you. |
@linuxsec Hey, how does the cname look like? and the fingerprint only says "page not found"? |
What is the impact of this takeover ? |
There's nothing much we can do by setting up a "Public Status Page" in uptimerobot |
Take a look in the impact
😂 Just for Phishing i guess. |
Not sure how we can do phishing either since we have absolute no control over the uptimerobot subdomain. Sorry if I am not understanding correctly |
I mean:
Not means a bug hunter will do a phishing attack of course. |
I meant to say it's not possible to perform a phishing attack even for a malicious user. Even if a subdomain |
That example show everything UP, right? lets say you properly set a server DOWN just to TRICK (LIE) the company... now you have convinced some staff they have a server down, so now you have a person in panic in the other side, now you can try use that in your favour to do something you need, like click in other poisoned link, or something. Again, its not something impactful i tried to say its only what an blackhat attacker can do, which in BugBounty it means nothing. |
The service is similar to statuspage.io and may not be considered impactful. |
I have a message like |
I got a 404 page and did not find how to take over the page. |
Can anyone help me that do I have to buy premium for the custom domain? |
Hello this is need premium account ?? add for custom domain |
@0xAsuka Can you please help me out. |
i find a page of 404 from uptimes robot can any body give me steps to take over it |
what is the step of subdomain takeover on uptimerobot |
hey |
hey, can you help me |
Uptimerobot.com
There is no additional verification for add custom domain. just add cname record and pointing to stats.uptimerobot.com
https://exploit.linuxsec.org/uptimerobot-com-custom-domain-subdomain-takeover/
sorry it is indonesian language. but i add some screenshot so i think you will understand.
The text was updated successfully, but these errors were encountered: