Subdomain Takeover at test.shipt.com
High
S
Shipt
Submitted None
Team Summary
Official summary from Shipt
A researcher identified a stale DNS record that pointed to an abandoned test Heroku instance. This allowed for subdomain takeover. This was not an actively used subdomain and was not linked in any of our production applications. Nonetheless, Shipt Security immediately addressed the issue and awarded the researcher with an appropriate bounty.
Actions:
Reported by
m7mdharoun
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$750.00