Domain.com
indianajson opened this issue · comments
Indiana JSON commented
Service
Domain.com
Status
Vulnerable
Nameserver
ns1.domain.com
ns2.domain.com
Explanation
Per Domain.com's Knowledge Base you can add external domains if you have an existing account or if you purchase something (like hosting). As it turns out Domain.com owns 000domains.com
and dotster.com
, which means creating a zone on domain.com
will active a zone automatically on the other two services as well.
Needs Verification?
Yes
While the documentation supports the belief that takeover is possible and their system uses the same backend as Bizland and MyDomain (which are vulnerable). We do need someone to verify that takeover is possible.