Subdomain takeover on healthyhackathon.khanacademy.org and hackweek.khanacademy.org
High
K
Khan Academy
Submitted None
Actions:
Reported by
katsuragicsl
Vulnerability Details
Technical details and impact analysis
#Summary :
healthyhackathon.khanacademy.org can be took over, since it points to a bucket in S3 but that bucket does not exists.
I know this domain is used to host information of healthyhackathon which is held by khanacademy, but you will not be able to do this anymore if someone is going to claim that bucket.
#Reference :
[S3_takeover](https://github.com/EdOverflow/can-i-take-over-xyz/issues/36)
## Impact
Taking control of healthyhackathon.khanacademy.org and spoof khanacademy users that healthyhackathon is reopened/"archived for you to challenge" and collect their information.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Access Control - Generic