-
-
Notifications
You must be signed in to change notification settings - Fork 766
Closed
Labels
edge caseAn edge case was discovered where it is possible to hijack a subdomain on this service.An edge case was discovered where it is possible to hijack a subdomain on this service.
Description
Service name
Vercel
Proof
Successful subdomain takeover on a harvard.edu subdomain (screenshot).
Documentation
- Create a new repository on Github and upload an index.html
- Visit https://vercel.com/ and sign up using your Github account
- Create a new project and point it to the previously created Github repository
- Open the "Domains" tab on Vercel and add the vulnerable domain
- Boom! Exploited!
Metadata
Metadata
Assignees
Labels
edge caseAn edge case was discovered where it is possible to hijack a subdomain on this service.An edge case was discovered where it is possible to hijack a subdomain on this service.