EdOverflow / can-i-take-over-xyz

"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.
Creative Commons Attribution 4.0 International
4.58k stars 690 forks source link

Subdomain Takeover via HubSpot #59

Open m7mdharoun opened 5 years ago

m7mdharoun commented 5 years ago

HubSpot

Proof

Example of https://hackerone.com/reports/38007

Doc

I do the same takeover last 2 days so The vulnerability is still exist .

codingo commented 5 years ago

@m7mdharoun I'm pretty familiar with this one and somewhat doubt your claim. Could you please provide a link to your more recent issue (if disclosed) or at minimum some further information?

m7mdharoun commented 5 years ago

@codingo I've disclosed the Bug Report but without the premssion of PayPal So someone report Hackerone Support and They warning me Poc here hubspot

FingerPrint : Domain Not found hubspot finger

codingo commented 5 years ago

Excellent, thank-you for the prompt response. I'll update the repo shortly.

m7mdharoun commented 5 years ago

@codingo Please check your twitter messages I've sent you the POC link

alanbriangh commented 4 years ago

Hi, another example here:

https://hackerone.com/reports/407355

(He didn't say it was "Hubspot", but he said "this report is same as of this one:- https://hackerone.com/reports/38007"

jub0bs commented 4 years ago

Here is a recent example, but it contains few details about the PoC: https://hackerone.com/reports/335330

soareswallace commented 4 years ago

Both examples above were reports written 2 years ago, but disclosed recently.

jub0bs commented 4 years ago

@soareswallace Ah yes, I had overlooked that. Thanks.

rohan-birtia commented 1 year ago

This is no longer possible.

image
hellsing032 commented 3 months ago

Halo, i discovered a domain connect the hubspot but went i regist it the domain i want to takeover is request the verification, is still vuln or no?