Subdomain Takeover
Critical
P
Paragon Initiative Enterprises
Submitted None
Actions:
Reported by
kholy
Vulnerability Details
Technical details and impact analysis
Hello,
Your Subdomain engineering.github.com/paragonie is Pointing to Tumblr.com
You should immediately remove the DNS-entry for engineering.zomato.com is Pointing to Tumblr.com.. Any One Can Claim That Domain , Please Read The Advisory Below.
Remediation
Please make sure you're always going through your DNS-entries so no subdomains are pointing to external services you do not use.
We've written an advisory about this at Detectify:
http://blog.detectify.com/post/100600514143/hostile-subdomain-takeover-using-heroku-github-desk
Where you can read more about this sort of attack.
I Have Done NSLookup For POC :-
nslookup github.com/paragonie
Server: 192.168.188.1
Address: 192.168.188.2#53
Non-authoritative answer:
engineering.zomato.com canonical name = domains.tumblr.com.
Name: domains.tumblr.com
Address: 66.6.42.22
Name: domains.tumblr.com
Address: 66.6.43.22
Report Details
Additional information and metadata
State
Closed
Substate
Not-Applicable
Submitted
Weakness
Information Disclosure