Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Heroku-takeover.yaml #201

Closed
wants to merge 1 commit into from
Closed

Conversation

ManasHarsh
Copy link
Contributor

Handy for Heroku subdomain takeovers

Handy for Heroku subdomain takeovers
@ManasHarsh ManasHarsh changed the title Create Heroku-takeover.yaml Heroku-takeover.yaml Jul 6, 2020
Copy link
Member

@dwisiswant0 dwisiswant0 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Or if you don't mind, can you provide proof of the screenshot?

- type: word
words:
- There's nothing here, yet.
- 'Location: https://*.herokudns.com/
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi, but here you use words type instead of regex.

- 307
- type: word
words:
- There's nothing here, yet.
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Refer to EdOverflow/can-i-take-over-xyz#38, it is part of the iframe HTML tag, which means it won't match if it doesn't use the redirects key.
See this part https://github.com/projectdiscovery/nuclei-templates/blob/master/GUIDE.md#redirects.

@ManasHarsh
Copy link
Contributor Author

ManasHarsh commented Jul 6, 2020 via email

@ehsandeep
Copy link
Member

Hi @manasjha7,

This is a duplicate as well, please check this

@dwisiswant0 thank you for the review.

@ehsandeep ehsandeep closed this Jul 6, 2020
@dwisiswant0
Copy link
Member

Hi @manasjha7,

This is a duplicate as well, please check this

@dwisiswant0 thank you for the review.

It's dup too, should be taking out?
subdomain-takeover/pantheon.io.yaml

@ManasHarsh
Copy link
Contributor Author

ManasHarsh commented Jul 6, 2020 via email

@Sy3Omda
Copy link
Contributor

Sy3Omda commented Sep 3, 2020

is heroku still vulnerable to subdomain takeover ?

@NagliNagli
Copy link
Contributor

Can we remove Heroku? as it's not vulnerable anymore.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants