DcentWallet / dcent-provider

ethereum web3 provider of D'CENT Biometric Wallet wrapping dcent-web-connector
MIT License
5 stars 6 forks source link

Subdomain takeover vulnerablity #17

Closed Amanzv closed 2 years ago

Amanzv commented 3 years ago

I tried contacting you with the mail address but it has been longer than expected to you to respond as the domain iotrust.dcentwallet.com is vulnerable to GitHub subdomain takeover attackers can host malicious content there & also can host a phishing campaign on it I have made a proof of concept over the site kindly check & remove the CNAME pointing to GitHub or ask me to release the domain & takeover it

If possible kindly check the mail Best, Amannoobda

Amanzv commented 2 years ago

resolved