Skip to content

Commit

Permalink
STO VRT Update 2024
Browse files Browse the repository at this point in the history
This PR inlcudes the changes proposed to the VRT update for the category of Subdomain Takeover:

Remove:
P2 - Server Security Misconfiguration - Misconfigured DNS - High Impact Subdomain Takeover

Change:
From:
P3 - Server Security Misconfiguration - Misconfigured DNS - Basic Subdomain Takeover

To:
P3 - Server Security Misconfiguration - Misconfigured DNS - Subdomain Takeover

bugcrowd/vulnerability-rating-taxonomy#421
  • Loading branch information
RRudder committed Oct 16, 2024
1 parent 431f8aa commit 63d74ad
Show file tree
Hide file tree
Showing 8 changed files with 4 additions and 41 deletions.
Empty file.
Empty file.

This file was deleted.

This file was deleted.

This file was deleted.

Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
A subdomain takeover is when a misconfigured Domain Name System (DNS) record is re-registered to an endpoint owned by an attacker. An attacker is then able to redirect users to the endpoint and capture data such as cookies and credentials, perform Cross-Site Scripting (XSS) attacks, and potentially take over accounts in the legitimate application.

A basic subdomain takeover vulnerability was identified which could impact the reputation and brand of the business. An attacker can register a subdomain on behalf of the target domain and use it for spamming and phishing attacks.
A subdomain takeover vulnerability was identified which could impact the reputation and brand of the business. An attacker can register a subdomain on behalf of the target domain and use it for spamming and phishing attacks.

**Business Impact**

Basic subdomain takeover could lead to data theft and indirect financial loss through the attacker’s ability to interact with legitimate users. These malicious actions could also result in reputational damage for the business through the impact to customers’ trust.
Subdomain takeover can lead to data theft and indirect financial loss through the attacker’s ability to interact with legitimate users. These malicious actions could also result in reputational damage for the business through the impact to customers’ trust.

**Steps to Reproduce**

Expand All @@ -14,5 +14,5 @@ Basic subdomain takeover could lead to data theft and indirect financial loss th
**Proof of Concept (PoC)**

The following screenshot show the success of a subdomain takeover:

{{screenshot}}
>
> {{screenshot}}

0 comments on commit 63d74ad

Please sign in to comment.