Loading HuntDB...

Bypass subdomain limits using race condition

Low
C
Chaturbate
Submitted None

Team Summary

Official summary from Chaturbate

The hacker found that it was possible to add more than the limit of 5 whitelabel subdomains. The 5 limit is a soft limit, however we resolved this.

Reported by encrypt

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$100.00

Submitted

Weakness

Time-of-check Time-of-use (TOCTOU) Race Condition