Skip to content

Subdoamin Takeover Possible via Intercom Help Center #69

@MuhammadKhizerJaved

Description

@MuhammadKhizerJaved

Intercom Help Center

Proof

If you get an Error Similar to this one that gives 404 Error simply go to https://www.intercom.com/customer-support-software create a new account buy the service or get a free demo for 14 days

Then visit https://app.intercom.io/a/apps/pr1twx7u/articles/site/settings and add the subdomain that's giving error in custom domain field

screenshot 2018-11-20 at 3 40 08 pm

Turn On the Help Center and Publish a test article also otherwise you won't be able to turn on the help center

after you turn on successfully you'll be the admin of the help center

screenshot 2018-11-20 at 3 42 23 pm

Documentation

https://www.intercom.com/help/

Thanks 😉

Metadata

Metadata

Assignees

No one assigned

    Labels

    vulnerableSomeone has provided proof in the issue ticket that one can hijack subdomains on this service.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions