-
-
Notifications
You must be signed in to change notification settings - Fork 796
Readme.io proofs #41
Copy link
Copy link
Closed
Labels
vulnerableSomeone has provided proof in the issue ticket that one can hijack subdomains on this service.Someone has provided proof in the issue ticket that one can hijack subdomains on this service.
Metadata
Metadata
Assignees
Labels
vulnerableSomeone has provided proof in the issue ticket that one can hijack subdomains on this service.Someone has provided proof in the issue ticket that one can hijack subdomains on this service.
Service name
Readme.io (https://readme.io/)
Proof
The subdomains reside on
*.readme.io. It is a classic virtual hosting scenario like in other similar services.To verify whether subdomain takeover may be possible, run:
(Assuming you have Readme.io account created.)
Documentation
https://readme.readme.io/docs/setting-up-custom-domain