Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

subdomain has been hacked? #1619

Open
kielnevec opened this issue Dec 17, 2023 · 3 comments
Open

subdomain has been hacked? #1619

kielnevec opened this issue Dec 17, 2023 · 3 comments

Comments

@kielnevec
Copy link

Dear @senorprogrammer
please kindly check this

http://wukong138.wtfutil.com/

someone using wtfutil.com subdomain for betting site

regards

@indradhanush
Copy link
Contributor

indradhanush commented Jan 3, 2024

Just checked and wtfutil.com looks okay to me.

Edit: Nevermind. I did not read the description carefully.

@senorprogrammer
Copy link
Collaborator

Thanks for catching this - somehow they've hijacked a subdomain. Any idea how they'd do that?

@Seanstoppable
Copy link
Collaborator

Looks like it is due to the usage of a wildcard, where *.wtfutil.com points to the gh pages servers.
Reading https://docs.github.com/en/pages/configuring-a-custom-domain-for-your-github-pages-site/troubleshooting-custom-domains-and-github-pages, using a wildcard is discouraged, more or less just because of this.
It lets pretty much anyone create a GH pages account and actually create an entry that will work. For example, I just set up seanstoppable.wtfutil.com on my personal gh pages, and now it is happily serving up my old blog.
Removing the wildcard, and setting up records for just www.wtfutil.com and wtfutil.com will result in these subdomains just not working.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

4 participants