Domain takeover (legalrobot.co.za)
L
Legal Robot
Submitted None
Team Summary
Official summary from Legal Robot
A security researcher discovered that an AWS S3 bucket was left unassigned after decommissioning. The bucket was previously used as a redirect to our main domain, legalrobot.com. If not for CloudFlare redirect rules already in place, the unused bucket could have allowed anyone that created an S3 bucket with the correct name and region to control the legalrobot.co.za domain.
Actions:
Reported by
todayisnew
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Authentication - Generic