Ausnahme gefangen: SSL certificate problem: certificate is not yet valid ๐Ÿ“Œ Sifchain: Subdomain Takeover At the Main Domain Of Your Site

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š Sifchain: Subdomain Takeover At the Main Domain Of Your Site


๐Ÿ’ก Newskategorie: Sicherheitslรผcken
๐Ÿ”— Quelle: vulners.com


image
Hello, I Know that isn't in the Scope But this The Only Way I can Report With And This Issue Is Very High It Belongs to the Main Domain this is pretty serious security issue in some context, so please act as fast as possible. overview the Main Domain [sifchain.finance] is pointing to wix.com, which has unclaimed CNAME record. ANYONE is able to own http://sifchain.finance domain at the moment. This vulnerability is called subdomain takeover. You can read more about it here: https://blog.sweepatic.com/subdomain-takeover-principles/ https://hackerone.com/reports/32825 https://hackerone.com/reports/175070 https://hackerone.com/reports/172137 Steps To Reproduce: Visit >> https://sifchain.finance when you open the above Link you will find wix.com subdomain error if you have an account in wix.com "premium" you can take over this subdomain I don't try it manually because I haven't permission to test this issue and i haven't the Premuim Account . Mitigation: Remove the CNAME record from sifchain.finance DNS zone completely. Or renew the Subscription . Regards, Ahmed Elmalky Impact Very Critical It is In the Main Domain . Subdomain takeover is abused for several purposes: Authentication bypass Malware distribution Phishing / Spear phishing... ...



๐Ÿ“Œ Sifchain: Subdomain Takeover At the Main Domain Of Your Site


๐Ÿ“ˆ 79.25 Punkte

๐Ÿ“Œ Domain-Protect - OWASP Domain Protect - Prevent Subdomain Takeover


๐Ÿ“ˆ 47.26 Punkte

๐Ÿ“Œ Domain-Protect - OWASP Domain Protect - Prevent Subdomain Takeover


๐Ÿ“ˆ 47.26 Punkte

๐Ÿ“Œ Sifchain: Possibility of DoS attack at https://sifchain.finance// via CVE-2018-6389 exploitation


๐Ÿ“ˆ 45.72 Punkte

๐Ÿ“Œ Sifchain: Information disclosure on Sifchain


๐Ÿ“ˆ 45.72 Punkte

๐Ÿ“Œ Sifchain: Clickjacking Vulnerability in sifchain.finance


๐Ÿ“ˆ 45.72 Punkte

๐Ÿ“Œ Sifchain: Email Spoofing on sifchain.finance


๐Ÿ“ˆ 45.72 Punkte

๐Ÿ“Œ Sifchain: Wordpress Users Disclosure (/wp-json/wp/v2/users/) on sifchain.finance


๐Ÿ“ˆ 45.72 Punkte

๐Ÿ“Œ Sifchain: Information Disclosure on https://rpc.sifchain.finance/


๐Ÿ“ˆ 45.72 Punkte

๐Ÿ“Œ Subdomain Takeover: Sicherheitsfirmen รผbernehmen Subdomain von EA


๐Ÿ“ˆ 44.83 Punkte

๐Ÿ“Œ Subdomain Takeover: Sicherheitsfirmen รผbernehmen Subdomain von EA


๐Ÿ“ˆ 44.83 Punkte

๐Ÿ“Œ SubScraper โ€“ Subdomain Enum Tool For Takeover Subdomain


๐Ÿ“ˆ 44.83 Punkte

๐Ÿ“Œ Mozilla Core Services: Subdomain takeover on one of the subdomain under mozaws.net


๐Ÿ“ˆ 44.83 Punkte

๐Ÿ“Œ Mozilla Core Services: Subdomain takeover on one of the subdomain under mozaws.net


๐Ÿ“ˆ 44.83 Punkte

๐Ÿ“Œ Mozilla Core Services: Subdomain takeover on one of the subdomain under mozgcp.net


๐Ÿ“ˆ 44.83 Punkte

๐Ÿ“Œ Mozilla Core Services: Subdomain takeover on one of the subdomain under mozgcp.net


๐Ÿ“ˆ 44.83 Punkte

๐Ÿ“Œ Mozilla Core Services: Subdomain takeover on one of the subdomain under mozgcp.net


๐Ÿ“ˆ 44.83 Punkte

๐Ÿ“Œ Mozilla Core Services: Subdomain takeover on one of the subdomain under mozaws.net


๐Ÿ“ˆ 44.83 Punkte

๐Ÿ“Œ Mozilla Core Services: Subdomain takeover on one of the subdomain under mozaws.net


๐Ÿ“ˆ 44.83 Punkte

๐Ÿ“Œ Mozilla Core Services: Subdomain takeover on one of the subdomain under mozaws.net


๐Ÿ“ˆ 44.83 Punkte

๐Ÿ“Œ Mozilla Core Services: Subdomain takeover on one of the subdomain under mozaws.net


๐Ÿ“ˆ 44.83 Punkte

๐Ÿ“Œ Taken - Takeover AWS Ips And Have A Working POC For Subdomain Takeover


๐Ÿ“ˆ 40.38 Punkte

๐Ÿ“Œ Surge Domain/Subdomain Takeover


๐Ÿ“ˆ 37.84 Punkte

๐Ÿ“Œ Sifchain: Wrong Url in Main Page


๐Ÿ“ˆ 35.08 Punkte

๐Ÿ“Œ Adobe: Main Domain Takeover at https://www.marketo.net/


๐Ÿ“ˆ 33.62 Punkte

๐Ÿ“Œ Takeover v0.2 - Sub-Domain TakeOver Vulnerability Scanner


๐Ÿ“ˆ 33.38 Punkte

๐Ÿ“Œ Censys Subdomain Finder - Perform Subdomain Enumeration Using The Certificate Transparency Logs From Censys


๐Ÿ“ˆ 32.86 Punkte

๐Ÿ“Œ Implementing Wildcard Subdomain (Part 2) - Creating subdomain programmatically


๐Ÿ“ˆ 32.86 Punkte

๐Ÿ“Œ Basecamp: SSL expired subdomain leads to API swap with main and flagged cookies. Unable to log device ids and certain session tokens.


๐Ÿ“ˆ 28.65 Punkte

๐Ÿ“Œ Subdomain Takeover: Microsoft verliert Kontrolle รผber Windows-Kacheln


๐Ÿ“ˆ 28.41 Punkte

๐Ÿ“Œ Starbucks: Subdomain takeover of mydailydev.starbucks.com


๐Ÿ“ˆ 28.41 Punkte

๐Ÿ“Œ Twitter: Subdomain takeover on dev-admin.periscope.tv


๐Ÿ“ˆ 28.41 Punkte

๐Ÿ“Œ Subdomain Takeover: Angreifer hรคtten EA-Spielerkonten รผbernehmen kรถnnen


๐Ÿ“ˆ 28.41 Punkte

๐Ÿ“Œ Mail.ru: [iot-hackathon.geekbrains.ru] Tilda Subdomain Takeover


๐Ÿ“ˆ 28.41 Punkte

๐Ÿ“Œ Stripo Inc: subdomain takeover at status0.stripo.email


๐Ÿ“ˆ 28.41 Punkte











matomo