EdOverflow / can-i-take-over-xyz

"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Worksites vulnerable to subdomain takeover

melbadry9 opened this issue · comments

Service name

Worksites - https://worksites.net

Proof

  • Vulnerable Error Message
    poc

  • Add Vulnerable domain to your site
    poc3

  • Takeover
    poc2

  • Publish your site with ($27.00 USD per month)

Fingerprint

  • Company Not Found
  • Hello! Sorry, but the website you’re looking for doesn’t exist.

Nice Catch! @melbadry9

Does this not involve CNAME records ?

@adityathebe No, It has A record pointing to IP 69.164.223.206

Is the payment address only for the United States?