Loading HuntDB...

Subdomain takeover at segway.shipt.com

Medium
S
Shipt
Submitted None

Team Summary

Official summary from Shipt

A security researcher identified a stale DNS record that pointed to a legacy 3rd party service. This allowed for a subdomain takeover, which the researcher provided a well written and detailed Proof of Concept (POC). Shipt's security team acted immediately to validate the vulnerability and remove the DNS record, remediating the issue. Researcher confirmed that the issue was resolved. Thank you @plenum for helping keep Shipt secure!

Reported by plenum

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$300.00

Submitted