Closed smiegles closed 4 years ago
all the best
by any chance it is possible to take over this subdomain .. i dont want to register my credit card to create an account and try
No i think it 's not possible to claim it .
Everytime you find an long string identifier, chances you can take the domain are very low.
On Fri, 14 May 2021, 06:01 0xElmalky, @.***> wrote:
No i think it 's not possible to claim it .
— You are receiving this because you were mentioned. Reply to this email directly, view it on GitHub https://github.com/EdOverflow/can-i-take-over-xyz/issues/11#issuecomment-841145104, or unsubscribe https://github.com/notifications/unsubscribe-auth/AE2OS75WBWO3XAHHWDAIEI3TNTYIJANCNFSM4EX2LSXA .
is takeover possible here
can you bypass Unbounce's control by doing an NSLOOKUP and using the alias associated with the domain that Unbounce has blocked?
so Unbounce not a vuln ?
It's vulnerable?
no bro
is it still working ?
Does this still work, anyone ?
Does this still work, anyone ?
no
@rojan-rijal ur totally right .. last night i reported a subdomain takover and it was using unbounce. The sec team triaged it asap ..! 😅 how you exploited i mean how takeover
I confirm that Unbounce is still vulnerable to subdomain takeovers since I successfully took over a subdomain 17 days ago (23 December 2022).
Hello , I just test 3 subdomains with 404 Error Via Unbounce . i noticed that the Subdomain With CName Record Like this
Non-authoritative answer: Sub.Domain.com canonical name = 1b450602efa347e0ac14sadwa8be95d.unbouncepages.com. 1b450602efa347e0ac14c4fb0a8be95d.unbouncepages.com canonical name = unbouncepages.com. Name: unbouncepages.com Address: 18.196.95.178 Name: unbouncepages.com Address: 54.93.101.65
Is 100% Not Vulnerable And You Can't Claim it .
But if the Cname Record Was Like this :
Non-authoritative answer: Sub.Domain.com canonical name = unbouncepages.com. Name: unbouncepages.com Address: 18.195.98.178 Name: unbouncepages.com Address: 54.93.101.
it is 100% Vulnerable For Takeover And Congrats about the bounty 100
Hello, can you tell me the tool name I also have the same problem with this .Please
Thank you
Sent from Outlook for Androidhttps://aka.ms/AAb9ysg
From: Sayan Chakraborty @.> Sent: Friday, January 20, 2023 9:14:44 AM To: EdOverflow/can-i-take-over-xyz @.> Cc: fsocietyxzy @.>; Comment @.> Subject: Re: [EdOverflow/can-i-take-over-xyz] Unbounce is not vulnerable for subdomain takeover. (#11)
Hello , I just test 3 subdomains with 404 Error Via Unbounce . i noticed that the Subdomain With CName Record Like this
Non-authoritative answer: Sub.Domain.com canonical name = 1b450602efa347e0ac14sadwa8be95d.unbouncepages.com. 1b450602efa347e0ac14c4fb0a8be95d.unbouncepages.com canonical name = unbouncepages.com. Name: unbouncepages.com Address: 18.196.95.178 Name: unbouncepages.com Address: 54.93.101.65
Is 100% Not Vulnerable And You Can't Claim it .
But if the Cname Record Was Like this :
Non-authoritative answer: Sub.Domain.com canonical name = unbouncepages.com. Name: unbouncepages.com Address: 18.195.98.178 Name: unbouncepages.com Address: 54.93.101.
it is 100% Vulnerable For Takeover And Congrats about the bounty 100
Hello, can you tell me the tool name I also have the same problem with this .Please
— Reply to this email directly, view it on GitHubhttps://github.com/EdOverflow/can-i-take-over-xyz/issues/11#issuecomment-1397965468, or unsubscribehttps://github.com/notifications/unsubscribe-auth/A47PWBTRDZNJYB5GMI7JGCLWTIUNJANCNFSM4EX2LSXA. You are receiving this because you commented.Message ID: @.***>
it is 100% Vulnerable For Takeover And Congrats about the bounty 100
which command i can use to check this ?
dig subdomain.domain.com
I confirm that Unbounce is still vulnerable to subdomain takeovers since I successfully took over a subdomain 17 days ago (23 December 2022).
how you bypass the domain error?
Hello , I just test 3 subdomains with 404 Error Via Unbounce . i noticed that the Subdomain With CName Record Like this
Non-authoritative answer: Sub.Domain.com canonical name = 1b450602efa347e0ac14sadwa8be95d.unbouncepages.com. 1b450602efa347e0ac14c4fb0a8be95d.unbouncepages.com canonical name = unbouncepages.com. Name: unbouncepages.com Address: 18.196.95.178 Name: unbouncepages.com Address: 54.93.101.65
Is 100% Not Vulnerable And You Can't Claim it . But if the Cname Record Was Like this :
Non-authoritative answer: Sub.Domain.com canonical name = unbouncepages.com. Name: unbouncepages.com Address: 18.195.98.178 Name: unbouncepages.com Address: 54.93.101.
it is 100% Vulnerable For Takeover And Congrats about the bounty 100
Are you sure ?
Found a case just like you said and this is what I got
this is the same error I am facing, anybody knows if it is still possible to bypass it and take over?
I confirm that Unbounce is still vulnerable to subdomain takeovers since I successfully took over a subdomain 17 days ago (23 December 2022).
how you bypass the domain error?
There was no error, for me at least. I guess it was pure luck, I guess?
I confirm that Unbounce is still vulnerable to subdomain takeovers since I successfully took over a subdomain 17 days ago (23 December 2022).
how you bypass the domain error?
There was no error, for me at least. I guess it was pure luck, I guess?
maybe, good for you. What about the txt record entry thing mentioned above, aren't we need to have access to the target's root domain for this? btw I just contacted the support team and they also provide me with an entry to add as Txt record, can I add this in any domain I owned?
Hello , I just test 3 subdomains with 404 Error Via Unbounce . i noticed that the Subdomain With CName Record Like this
Non-authoritative answer: Sub.Domain.com canonical name = 1b450602efa347e0ac14sadwa8be95d.unbouncepages.com. 1b450602efa347e0ac14c4fb0a8be95d.unbouncepages.com canonical name = unbouncepages.com. Name: unbouncepages.com Address: 18.196.95.178 Name: unbouncepages.com Address: 54.93.101.65
Is 100% Not Vulnerable And You Can't Claim it . But if the Cname Record Was Like this :
Non-authoritative answer: Sub.Domain.com canonical name = unbouncepages.com. Name: unbouncepages.com Address: 18.195.98.178 Name: unbouncepages.com Address: 54.93.101.
it is 100% Vulnerable For Takeover And Congrats about the bounty 100
Hello, can you tell me the tool name I also have the same problem with this .Please
Yes you are right
Hi, is there any special indication other than cname, for example from the protocol whether SSL is available, error or not?
still vulnerable ?
still vulnerable ?
Unfortunately not possible.
It's still vulnerable but only as a rare edge case, I exploited a valid one a few days ago - see https://github.com/Stratus-Security/Subdominator/issues/1#issuecomment-1868153929
Hello @coj337 I recently saw on Unbounce account giving an 404 Status code. Could you please help me confirm if its vulnerable for subdomain takeover with your account? I don't have funds to purchase one. Thank you very much sir.
If it is, then well share the outcome. Am a bug bounty hunter by the way :)
I was able to add a domain but it says "Error Finding CNAME" How can i resolve this anyone?
Hello, even after when you add your domain, It is not vulnerable. Just shift your attention to something else.
Not true.
If you manage to add a custom domain then there's a complete subdomain take over.
Not true.
If you manage to add a custom domain then there's a complete subdomain take over.
Yeah i think so, it's possible, The domain was pointing at a random ip address while using dig command and when i can subzy it was vulnerable to unbounce subdomain takeover and also when i claimed the subdomain it got claimed but after that it was asking for a cname to go live i guess. So, if anyone knows how to do that please help
Ok. No challenge. I'll be glad to learn how you will do that. Thanks and regards
The attacker here used an un-ethical way to exploit Unbounce which is resolved now as far as I believe.
https://github.com/EdOverflow/can-i-take-over-xyz#unbounce