-
-
Notifications
You must be signed in to change notification settings - Fork 729
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fastly is vuln #411
Comments
Really cool finding and even cooler sub-takeover page. That being said how is it possible that the main domain is not claimed? Did you just put in your own subdomain (unrelated to Pandora) and hoped it would work or did that subdomain pop-up during recon as a fastly subdomain? Edit: I tried testing the above out and I got the following error:
|
it will work if none already have it added |
i used subzy to scan many subdomains and it popped as vuln (live.pandora.com [ FASTLY ]) so i did the steps that i sent and worked |
Service name
fastly.com
Proof
http://live.pandora.com
Documentation
its only vuln when no body already claimed the main domain (pandora.com in my case)
The text was updated successfully, but these errors were encountered: