博客
关于我
强烈建议你试试无所不能的chatGPT,快点击我
Hijacking tons of Instapage expired users Domains & Subdomains
阅读量:6138 次
发布时间:2019-06-21

本文共 2245 字,大约阅读时间需要 7 分钟。

Hello all ?

so this post is about how I was able to hijack ton’s of domains/subdomains who using Instapage if there service got expired.

What is instapage ?

 is a service that lets you build landing pages for your online marketing and promotion campaigns with ease. It offers features such as A/B Testing, multiple campaign management, easy page building, and a lot more!

it also allows users to map its template on there own domain or subdomains.

How i found it ?

as am one of researchers from  platform , I was trying to get something on HackerOne itself as I want that Hacking Hackers Badge of my .

I found hacker.one is inscope domain list which is one of the officail website of HackerOne, and when I vistied it and seen some error which caught in my eye and after figuring it, I come to know it wasInstapage error which occurs when service get expired or domain or subdoamin not linked properly and it takes just few mintues to figurte it out that I can publish my own template to any of misconfigured and expired domains/subdomains of instapage and luckly HackerOne is one of there users.

Instapage error on Hacker.One :

 

Vulnerable Post Request :

POST /ajax/builder2/publish/2340488 HTTP/1.1 Host: app.instapage.com User-Agent: Mozilla/5.0 (Windows NT 6.3; rv:36.0) Gecko/20100101 Firefox/36.04 Accept: */* Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate Content-Type: application/x-www-form-urlencoded; charset=UTF-8 X-Requested-With: XMLHttpRequest Referer: http://app.instapage.com/builder2?id=2340488 Content-Length: 31 Cookie: cookie_value Connection: close  version=1&url=www.hacker.one

where url parameter value contain vulnerable domains .

Hacker.One domain Takeover : 

 

Here is the Video POC :

and with help of Google dork and error of instapage I found tons of websites are Vulnerable for this and anyone can takeover it with own content on it, I contacted Instapage via HackerOne.

HackerOne fixed it next of report by removing the cname entry pointing to instapage and later Instapage fixed in completely and got confirmation of fix via HackerOne report thread.

Thanks to HackerOne to being a mediator for contacting Instapage and fixing the things in correct way.

转载于:https://www.cnblogs.com/hackforfun/p/5930118.html

你可能感兴趣的文章
[置顶] POJO的解释
查看>>
Openfiler之一:Openfiler的安装
查看>>
我的友情链接
查看>>
Java内存管理
查看>>
Gulp安装及配合组件构建前端开发一体化
查看>>
216小时学会Python
查看>>
【Pyspider】 windows 下 pyspider 环境搭建
查看>>
Scala-IDE构建Maven项目(eclipse)
查看>>
saltstack 源码安装tengine
查看>>
再谈幂等机制
查看>>
spring boot.2x 启用拦截器配置 静态资源不能访问
查看>>
2018年上半年软考各科目真题及答案下载
查看>>
CentOS7添加永久静态路由
查看>>
Java基础学习总结(19)——Java环境变量配置
查看>>
笨方法学习Python31-40
查看>>
Java基础学习总结(8)——super关键字
查看>>
我的友情链接
查看>>
centos 7 + mysql 5.7.13 重置数据库的root密码
查看>>
gRPC快速入门(一)——Protobuf简介
查看>>
python socket 网络编程selector用法 实用
查看>>