Skip to content

Getresponse.com vulnerable to subdomain takeover #235

@darkpills

Description

@darkpills

Service name

GetResponse - https://www.getresponse.com/

Vulnerable domain which can be takeover

image

Fingerprint: "Cette landing page n'est plus disponible" (FR)

Steps to takeover

  1. Register an account on https://www.getresponse.com/
  2. Create a new domain : My Account > Manage account > Landing page domain > Add domain: declare the victim subdomain to takeover: sub.victim.com
  3. Do a "dig sub.victim.com" to get the CNAME. There should be a CNAME for any of the getresponse tool domains: gr8.com, subscribemenow.com, getresponsepages.com
  4. Create a new landing page that will be displayed. In the Edit settings > landging page url settings > put the subdomain you saw previously like: test.gr8.com to make your landing page response to the sub.victim.com

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions