Subdomain takeover on *.apachecn.org
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 25/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- github
- Domain
- infrastructure, security
Research direction
Start by reviewing the wildcard CNAME configuration described in the issue and the linked proof of concept at what-i-want.apachecn.org. Confirm whether apachecn.org still routes arbitrary subdomains to apachecn.github.io; done means the wildcard CNAME record is removed and the proof-of-concept subdomain no longer serves attacker-controlled content.
Written by the indexing model from the issue text.
Description
Summary
The domain apachecn.org.io has a subdomain wildcard CNAME record pointing to apachecn.github.io. This allows an attacker to use any subdomain he wants on apachecn.org with Github pages.
Security issue
An attacker could create it's own repository and configure it to use any subdomain he wants, allowing him to serve it's own content.
POC
I have made a POC.

Remediation
Remove the wildcard CNAME record for apachecn.org.
Impact
This issue make it possible for an attacker to carry out several type of attacks like XSS, phishing campaign or session hijacking.
- Dominant language
- HTML
- Stars
- 1
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Similar issues
-
Difficulty 1/5 Under an hour Newbie friendliness 92/100
vicharanashala/fln#564 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
haskell-actions/setup#152 ·
-
feature-request helm
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
gravitational/teleport#69785 ·
-
A cancelled tests run makes the coverage comment workflow fail and reports it as a red check on main Openarea: ci bug perceived difficulty: 3
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Nitjsefnie-Harness-Commons/daedalus#921 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
TencentCloud/Octop#1007 ·