-
-
Notifications
You must be signed in to change notification settings - Fork 782
Open
Description
Service name
GetResponse - https://www.getresponse.com/
Vulnerable domain which can be takeover
Fingerprint: "Cette landing page n'est plus disponible" (FR)
Steps to takeover
- Register an account on https://www.getresponse.com/
- Create a new domain : My Account > Manage account > Landing page domain > Add domain: declare the victim subdomain to takeover: sub.victim.com
- Do a "dig sub.victim.com" to get the CNAME. There should be a CNAME for any of the getresponse tool domains: gr8.com, subscribemenow.com, getresponsepages.com
- Create a new landing page that will be displayed. In the Edit settings > landging page url settings > put the subdomain you saw previously like: test.gr8.com to make your landing page response to the sub.victim.com
pdelteil
Metadata
Metadata
Assignees
Labels
No labels
