EdOverflow / can-i-take-over-xyz

"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.
Creative Commons Attribution 4.0 International
4.88k stars 716 forks source link

Subdomain Takeover Pointing to Blogger #236

Closed StefanTobler closed 1 year ago

StefanTobler commented 3 years ago

Blogger

Proof

Screen Shot 2021-09-19 at 2 38 30 AM

Documentation

Dangling (sub)domains that point to ghs.google.com usually point to a Blogger instance. However, this subdomain cannot be taken over because Blogger requires a security CNAME record for a domain to point to the blogger instance, not just the fact that ghs.google.com is registered as a CNAME.

Steiner-254 commented 2 years ago

Haha, interesting!