-
-
Notifications
You must be signed in to change notification settings - Fork 718
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Subdomain Takeover via HubSpot #59
Comments
@m7mdharoun I'm pretty familiar with this one and somewhat doubt your claim. Could you please provide a link to your more recent issue (if disclosed) or at minimum some further information? |
@codingo I've disclosed the Bug Report but without the premssion of PayPal So someone report Hackerone Support and They warning me Poc here |
Excellent, thank-you for the prompt response. I'll update the repo shortly. |
@codingo Please check your twitter messages I've sent you the POC link |
Hi, another example here: https://hackerone.com/reports/407355 (He didn't say it was "Hubspot", but he said "this report is same as of this one:- https://hackerone.com/reports/38007" |
Here is a recent example, but it contains few details about the PoC: https://hackerone.com/reports/335330 |
Both examples above were reports written 2 years ago, but disclosed recently. |
@soareswallace Ah yes, I had overlooked that. Thanks. |
Halo, i discovered a domain connect the hubspot but went i regist it the domain i want to takeover is request the verification, is still vuln or no? |
HubSpot
Proof
Example of https://hackerone.com/reports/38007
Doc
I do the same takeover last 2 days so The vulnerability is still exist .
The text was updated successfully, but these errors were encountered: