-
-
Notifications
You must be signed in to change notification settings - Fork 765
Open
Labels
vulnerableSomeone has provided proof in the issue ticket that one can hijack subdomains on this service.Someone has provided proof in the issue ticket that one can hijack subdomains on this service.
Description
Uptimerobot.com
There is no additional verification for add custom domain. just add cname record and pointing to stats.uptimerobot.com
https://exploit.linuxsec.org/uptimerobot-com-custom-domain-subdomain-takeover/
sorry it is indonesian language. but i add some screenshot so i think you will understand.
Metadata
Metadata
Assignees
Labels
vulnerableSomeone has provided proof in the issue ticket that one can hijack subdomains on this service.Someone has provided proof in the issue ticket that one can hijack subdomains on this service.