Mojira Archive
WEB-1365

Sub Domain Takeover

Vulnerable Subdomain : http://launcher-beta.mojang.com

 

CNAME : s3.amazonaws.com

 

Service Provider : Mojang (Which is takeoverable )

 

Steps to Reproduce :

 

1) Visit the http://launcher-beta.mojang.com of which bucket is under my control .

 

POC :

1) Video recording and Screenshots attached.

Fixed

pratik jagtap

[Mojang] Web Team

2019-07-23, 07:50 PM

2020-05-28, 10:09 AM

2020-05-28, 10:09 AM

1

0