Tag: subdomain-takeover
Finding Hidden Threats: How I Found Leaked AWS Credentials in an Android App API Using DAST
Found a critical vulnerability involving leaked AWS credentials within an Android App API during a bug bounty hunt. by utilizing Dynamic Application Security Testing (DAST) and the…
Subdomain Takeover via Unsecured S3 Bucket Connected to the Website
This Blog is about an issue i found in a web where an Unsecured S3 Bucket connected to the website gave way to Takeover teh Subdoamin.
UBER Wildcard Subdomain Takeover | BugBounty POC
one of ubers domain was vulnerable to Wildcard subdomain takeover, Basically as heroku wildcard is Opened and i can register any subdomain & takeover it.
What is Subdomain Hijack/Takeover Vulnerability? How to Identify? & Exploit It?
The post explains the basic of subdomain takeover vulnerability, how to identify and exploit the issue, post contains 5 diff services step to step guide.
Bugcrowd’s Domain & Subdomain Takeover vulnerability!
Bugcrowd's Domain & Subdomain takeover vulnerability Due to Expired/Misconfigured Fastly & Pantheon Services.. A small writeup about how i did it?
Subdomain Takeover Through Expired Cloudfront Distribution | live.lamborghini.com
I found an Expired Cloudfront distribution on one of the lamborghini.com Subdomains! The Post explains how easy it is to takeover a subdomain!

