Subdomain Takeover
High
G
GSA Bounty
Submitted None
Team Summary
Official summary from GSA Bounty
@picklepwns discovered a subdomain takeover attack. Technically, the domain was out of scope for our Vulnerability Disclosure Policy. We want to remind hackers to please limit their testing to domains explicitly listed in that scope (which is repeated on our HackerOne program page for convenience). This is for your own safety: we want to be sure that everyone's on the same page about your activities being authorized. That said, this was a legitimate vulnerability, which we fixed with other government partners. Thanks for the find, @picklepwns - we really appreciate it!
Actions:
Reported by
nevertoolate
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Privilege Escalation