Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Anima vulnerable to subdomain takeover #126

Open
TakSec opened this issue Dec 18, 2019 · 1 comment
Open

Anima vulnerable to subdomain takeover #126

TakSec opened this issue Dec 18, 2019 · 1 comment
Labels
vulnerable Someone has provided proof in the issue ticket that one can hijack subdomains on this service.

Comments

@TakSec
Copy link

TakSec commented Dec 18, 2019

Service name

Anima - https://www.animaapp.com/

Proof

Created a PoC for a bug bounty report and it worked without any issues.

Documentation

A Record:
subdomain.domain.com. 600 IN A 35.164.217.247
Error page:
Missing Website
If this is your website and you've just created it, try refreshing in a minute
https://docs.animaapp.com/v1/launchpad/08-custom-domain.html

@EdOverflow EdOverflow added the vulnerable Someone has provided proof in the issue ticket that one can hijack subdomains on this service. label Dec 19, 2019
@EdOverflow
Copy link
Owner

Thank you, @TakSec. 👍

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
vulnerable Someone has provided proof in the issue ticket that one can hijack subdomains on this service.
Projects
None yet
Development

No branches or pull requests

2 participants