Broken link for stale DNS entry may be leveraged for Phishing, Misinformation, Serving Malware
None
G
Gratipay
Submitted None
Actions:
Reported by
mehmil
Vulnerability Details
Technical details and impact analysis
Hi Team,
Page: https://gratipay.com/Breadcrumbel/
Broken link for stale DNS entry: ``` <a href="http://breadcumbry.com">Homepage</a> ```
Root domain breadcumbry.com has expiration date: Registrar Registration Expiration Date: 2018-06-10T18:18:30Z
And also from whois: Domain Status: OK https://icann.org/epp#ok
OK status means it has no protection for deletion/transfer and will be available for sale/purchase once expired.
An attacker may claim it and misuse in phishing scams or for spreading misinformation. Coming from an official source like Gratipay, users are likely to trust it.
It shall either be removed or updated to avoid the risk associated.
A similar issue @ Twitter which you might find relevant and funny :) -https://www.theverge.com/2017/2/3/14495978/belgian-hacker-trump-twitter-links
Similar H1 report: https://hackerone.com/reports/265696
Please review.
Thanks!
Report Details
Additional information and metadata
State
Closed
Substate
Informative