Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Gumfury subdomain takeover #154

Open
khaledibnalwalid opened this issue Jun 24, 2020 · 10 comments
Open

Gumfury subdomain takeover #154

khaledibnalwalid opened this issue Jun 24, 2020 · 10 comments
Labels
vulnerable Someone has provided proof in the issue ticket that one can hijack subdomains on this service.

Comments

@khaledibnalwalid
Copy link

Service name

Gumfury

Proof

https://khaledibnalwalid.wordpress.com/2020/06/25/gemfury-subdomain-takeover/

Documentation

adiffpirate added a commit to adiffpirate/can-i-take-over-xyz that referenced this issue Jul 19, 2020
Added:

- Gemfury EdOverflow#154
- Uberfilp EdOverflow#150
- Agile CRM EdOverflow#145
- Pingdom EdOverflow#144
- Worksites EdOverflow#142
@EdOverflow EdOverflow added the vulnerable Someone has provided proof in the issue ticket that one can hijack subdomains on this service. label Feb 3, 2021
@th3r4id
Copy link

th3r4id commented Aug 26, 2022

Looks like edge case now getting an error "Name already exists" @EdOverflow

@0xAm225
Copy link

0xAm225 commented Dec 27, 2022

Looks like edge case now getting an error "Name already exists" @EdOverflow

Looks like edge case now getting an error "Name already exists" @EdOverflow

true, i just got the same, but also the page looks differecent then @khaledibnalwalid shared, looks something like http request logging, i tried to claim it but it said "Name Already Exists"

@ZishanAdThandar
Copy link

LOOKS LIKE NOT VULNERABLE

I scanned with subzy. Result showed like that. And during takeover it shows "Name already exists".

1
2

@0xAm225
Copy link

0xAm225 commented Jan 4, 2023

LOOKS LIKE NOT VULNERABLE

I scanned with subzy. Result showed like that. And during takeover it shows "Name already exists".

1 2

Exactly same with me lol, i also used subzy and then tried to claim it but it says the name is already taken

@bhataasim1
Copy link

I think this is NOT VULNERABLE

@wadethrillson
Copy link

i added names to my domains but now it says dns validation issue. how to fix that?

@itsryuku
Copy link

Thu May 23 10:32:27 AM EDT 2024, didn't work for me.

@khaledibnalwalid
Copy link
Author

I think it has been resolved from the vendor

@ceylanb
Copy link

ceylanb commented Nov 25, 2024

Not vulnerable. I tried 10+ subdomains matching the vulnerability conditions, but "Name already exists" returned.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
vulnerable Someone has provided proof in the issue ticket that one can hijack subdomains on this service.
Projects
None yet
Development

No branches or pull requests

10 participants