Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Subdomain Takeover via Airee.ru #104

Open
r0hack opened this issue Jun 26, 2019 · 6 comments
Open

Subdomain Takeover via Airee.ru #104

r0hack opened this issue Jun 26, 2019 · 6 comments
Labels
vulnerable Someone has provided proof in the issue ticket that one can hijack subdomains on this service.

Comments

@r0hack
Copy link

r0hack commented Jun 26, 2019

Service name

Airee.ru (Russian service) for accelerate and protect website

Proof

  1. Check subdomain
    image
    the service was unpaid

  2. Create account in Airee and add subdomain cdn.site.ru
    image
    successfully added and the service now works and you can see the traffic

  3. We can change and add DNS-records and forwarding to another website and add new subdomain etc.
    image

@wargg
Copy link

wargg commented Jun 26, 2019

What is the CNAME for this provider?

@r0hack
Copy link
Author

r0hack commented Jun 26, 2019

What is the CNAME for this provider?

image

@r0hack
Copy link
Author

r0hack commented Jul 16, 2019

@EdOverflow, can add to the table.

@marcelo321
Copy link

fingerprint?

@tpirneci
Copy link

Fingerprint:

  • Ошибка 402. Сервис Айри.рф не оплачен

  • Сайт xyz.xyz.ru. , на который вы заходите, не оплатил сервис Айри.рф. Доступ к сайту временно невозможен.

@EdOverflow
Copy link
Owner

@r0hack, please feel free to submit a pull request for this entry. Thanks!

@EdOverflow EdOverflow added the vulnerable Someone has provided proof in the issue ticket that one can hijack subdomains on this service. label May 18, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
vulnerable Someone has provided proof in the issue ticket that one can hijack subdomains on this service.
Projects
None yet
Development

No branches or pull requests

5 participants