Open 0xAsuka opened 6 years ago
What is the error on browser? Page not found? 404? page not found? I cannot seem to find a sample not found page.
yes. it say "page not found"
Thank you.
@linuxsec Hey, how does the cname look like? and the fingerprint only says "page not found"?
What is the impact of this takeover ?
There's nothing much we can do by setting up a "Public Status Page" in uptimerobot
Take a look in the impact
:joy:
Just for Phishing i guess.
Just for Phishing i guess.
Not sure how we can do phishing either since we have absolute no control over the uptimerobot subdomain.
Sorry if I am not understanding correctly
I mean:
Not means a bug hunter will do a phishing attack of course.
I meant to say it's not possible to perform a phishing attack even for a malicious user.
Even if a subdomain abc.example.com
that is pointing to stats.uptimerobot.com
is vulnerable to takeover then all an attacker can do is register abc.example.com
in uptimerrobot. But that's just it. Visiting the subdomain will show the stats of some site (the attacker has the freedom to choose which site) but there's nothing much one can do beyond that.
That example show everything UP, right? lets say you properly set a server DOWN just to TRICK (LIE) the company... now you have convinced some staff they have a server down, so now you have a person in panic in the other side, now you can try use that in your favour to do something you need, like click in other poisoned link, or something.
Again, its not something impactful i tried to say its only what an blackhat attacker can do, which in BugBounty it means nothing.
The service is similar to statuspage.io and may not be considered impactful.
I have a message like 404 PAGE NOT FOUND on a website how can I take over that subdomain
I got a 404 page and did not find how to take over the page.
Can anyone help me that do I have to buy premium for the custom domain?
Hello
this is need premium account ?? add for custom domain
@0xAsuka Can you please help me out. I found a page 404 after using tool subzy i got to know that it's pointing towards UptimeerRobot. I created the account. Added the target name in monitor but not understanding now what to do. Please help.
i find a page of 404 from uptimes robot can any body give me steps to take over it
what is the step of subdomain takeover on uptimerobot
hey
hey, can you help me what is the step of subdomain takeover on uptimerobot
Uptimerobot.com
There is no additional verification for add custom domain. just add cname record and pointing to stats.uptimerobot.com
https://exploit.linuxsec.org/uptimerobot-com-custom-domain-subdomain-takeover/
sorry it is indonesian language. but i add some screenshot so i think you will understand.