
The hacker was able to takeover https://hackerone.engineering after a small window of misconfiguration (~10 minutes) introduced by us, where GitHub released the CNAME hold whilst the DNS records were still pointing towards GitHub, allowing them to claim the domain in their own repository. We've added Domain Verification on GitHub for this host and the GitHub Pages Domain has been transferred back since. (https://docs.github.com/en/organizations/managing-organization-settings/verifying-or-approving-a-domain-for-your-organization) Something that's different from usual reports we get is that this was an asset not considered in scope nor out of scope, so we didn't have a concrete bounty table and it brought our team to the drawing board on how we want to handle such reports. Whilst we want to encourage hackers to hack on non-listed assets belonging to us, it's also something we currently do not have clear guidelines for. We opted to give a bonus without bounty instead to speed the process along. For anyone visiting the Engineering Blog whilst it was taken over, we've confirmed no malware was hosted on that site whilst it was live. Regarding limited disclosure: There's a few comments we considered redacting but making them internal would just make the conversation look really broken, I think this summary encapsulates...
SOCIAL SHARE CARD GENERATOR