Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Updated Statuspage Takeover Status #171

Merged
merged 2 commits into from
Sep 24, 2020
Merged

Conversation

0xPrial
Copy link

@0xPrial 0xPrial commented Sep 21, 2020

As I said in PR #105 Status page pushed a DNS verification in order to prevent malicious takeovers what they mentioned in https://support.atlassian.com/statuspage/docs/configure-your-dns/

However when I created PR #105 Pull request I was able to bypass this DNS verification as there was no mechanism what verifies if the expected value for customers CNAME record matches with the statuspage account what was fixed later after my report to their program.

So no more takeover here until any genius find any other way :D

Happy hacking <3

@codingo codingo merged commit 4d5e021 into EdOverflow:master Sep 24, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants