Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Worksites vulnerable to subdomain takeover #142

Open
melbadry9 opened this issue Apr 15, 2020 · 4 comments
Open

Worksites vulnerable to subdomain takeover #142

melbadry9 opened this issue Apr 15, 2020 · 4 comments
Labels
vulnerable Someone has provided proof in the issue ticket that one can hijack subdomains on this service.

Comments

@melbadry9
Copy link

Service name

Worksites - https://worksites.net

Proof

  • Vulnerable Error Message
    poc

  • Add Vulnerable domain to your site
    poc3

  • Takeover
    poc2

  • Publish your site with ($27.00 USD per month)

Fingerprint

  • Company Not Found
  • Hello! Sorry, but the website you’re looking for doesn’t exist.
@h45h-1nclud3
Copy link

Nice Catch! @melbadry9

@EdOverflow EdOverflow added the vulnerable Someone has provided proof in the issue ticket that one can hijack subdomains on this service. label May 18, 2020
@adityathebe
Copy link

Does this not involve CNAME records ?

@melbadry9
Copy link
Author

melbadry9 commented Jul 4, 2020

@adityathebe No, It has A record pointing to IP 69.164.223.206

@superteamseo
Copy link

Is the payment address only for the United States?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
vulnerable Someone has provided proof in the issue ticket that one can hijack subdomains on this service.
Projects
None yet
Development

No branches or pull requests

5 participants