indianajson / can-i-take-over-dns

"Can I take over DNS?" — a list of DNS providers and how to claim vulnerable domains.
990 stars 93 forks source link

Verizon Small Business #20

Open indianajson opened 3 years ago

indianajson commented 3 years ago

Service Verizon Small Business

Status Unknown

Nameserver

yns1.yahoo.com yns2.yahoo.com

Explanation

Version acquired Yahoo and has finally begun to shut down old Yahoo websites in favor of rebranded Verizon websites. This has modified the flow for this and as of current we are unsure if it is still possible.

Old Explanation

Yahoo Small Business provides websites, domains, and hosting services. First, create a free account. Once you log in click Create a website today. Next, follow the steps to create a "free website" and click Publish. You will be asked if you want to use a Custom Domain or a free subdomain, select Custom Domain. On the next page select the Basic Plan. After this, there will be a line of text on the next page that reads Want to use your existing domain name? Click here., click it and enter your vulnerable domain. If the domain is available it will tell you and ask you to verify you own the domain. Assuming you have authorized to perform the takeover from a bug bounty program then proceed. It will then ask for your credit card and details. Once finished the DNS will begin to propagate and the takeover will be successful.

dopo123 commented 2 years ago

does this still work

dopo123 commented 2 years ago

doesn't seem to, or maybe i am doing it wrong @indianajson

breezemight commented 2 years ago

did they change all the nameserver cname prefixes from yns* to ns*?

indianajson commented 2 years ago

@dopo123 @breezemight The flow has definitely changed now that they are under Verizon, before you could "add the domain" to see if it worked and then pay for it. Now it looks like you have to pay for it first. I imagine something is still possible given you can add a "custom domain" if you pay, but don't have the time at the moment to fully investigate.

marcelo321 commented 1 year ago

I think we have to pay @indianajson, right?

indianajson commented 1 year ago

I think we have to pay @indianajson, right?

Yes, it seems you have to pay then add a custom domain to the service, but I haven't independently verified this since the merger with Verizon.