-
-
Notifications
You must be signed in to change notification settings - Fork 733
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Subdomain Takeover via Tumblr #240
Comments
Although this takeover opportunity was already mentioned in the README doc, documentation on the takeover steps was missing from this repository. Created this issue in tandem with the PR to update the README in #241. |
devs, the same on my the same error, what could be the problem???))) |
i understand, done. disabled proxy on cloudflare on https://tumblr.alexdolbun.com/ and this error is gone 🦄 |
Hi @pdelteil @diophant0x, I had originally submitted the This issue can be closed once the current information on Tumblr apex and subdomain takeover (as qualified above) has been added to the README file. I would myself make a pull request for this but I don't currently have access to a computer. Best, |
This no longer appears possible as of 9 June 2023. See this reference and this reference. According to the references, custom domains must be purchased through Tumblr's own domain service.
|
Service name
Tumblr
Fingerprint
A source domain has a DNS entry that points to Tumblr, however no active blog is associated with the domain.
DNS Record:
CNAME domains.tumblr.com.
HTTP Response Status:
404 Not Found
HTTP Response Body:
Whatever you were looking for doesn't currently exist at this address
Verification:
curl -s -N http://$SOURCE_DOMAIN_NAME | grep -E -q "Whatever you were looking for doesn't currently exist at this address" && echo "Subdomain takeover may be possible" || echo "Subdomain takeover is not possible"
Takeover Steps
Domains with CNAME to Tumblr are vulnerable to subdomain takeover.
Step-by-step process:
Some reports on H1, for Tumblr blog takeovers:
https://hackerone.com/reports/113869
https://hackerone.com/reports/221631
Documentation
Tumblr Custom Domains
https://www.tumblr.com/docs/en/custom_domains
The text was updated successfully, but these errors were encountered: