Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fastly is vuln #411

Open
KKonaNN opened this issue Jun 14, 2024 · 3 comments
Open

fastly is vuln #411

KKonaNN opened this issue Jun 14, 2024 · 3 comments

Comments

@KKonaNN
Copy link

KKonaNN commented Jun 14, 2024

Service name

fastly.com

Proof

http://live.pandora.com
image

Documentation

its only vuln when no body already claimed the main domain (pandora.com in my case)

@N-N33
Copy link

N-N33 commented Jun 18, 2024

Really cool finding and even cooler sub-takeover page. That being said how is it possible that the main domain is not claimed?

Did you just put in your own subdomain (unrelated to Pandora) and hoped it would work or did that subdomain pop-up during recon as a fastly subdomain?

Edit: I tried testing the above out and I got the following error:

Fastly error: unknown domain: [SubtakeoverPOC.Redacted.com] Please check that this domain has been added to a service

@KKonaNN
Copy link
Author

KKonaNN commented Jun 19, 2024

Really cool finding and even cooler sub-takeover page. That being said how is it possible that the main domain is not claimed?

Did you just put in your own subdomain (unrelated to Pandora) and hoped it would work or did that subdomain pop-up during recon as a fastly subdomain?

Edit: I tried testing the above out and I got the following error:

Fastly error: unknown domain: [SubtakeoverPOC.Redacted.com] Please check that this domain has been added to a service

  • login into your fastly account
  • go into CDN services
  • create a new service
  • go to Service configuration / Domains
  • add your vuln subdomain there (SubtakeoverPOC.Redacted.com)

it will work if none already have it added

@KKonaNN
Copy link
Author

KKonaNN commented Jun 19, 2024

Really cool finding and even cooler sub-takeover page. That being said how is it possible that the main domain is not claimed?

Did you just put in your own subdomain (unrelated to Pandora) and hoped it would work or did that subdomain pop-up during recon as a fastly subdomain?

Edit: I tried testing the above out and I got the following error:

Fastly error: unknown domain: [SubtakeoverPOC.Redacted.com] Please check that this domain has been added to a service

i used subzy to scan many subdomains and it popped as vuln (live.pandora.com [ FASTLY ]) so i did the steps that i sent and worked
ps; the takeover could be false i think when origin is not reached fastly will give same error as not claimed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants