-
-
Notifications
You must be signed in to change notification settings - Fork 716
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Updated Wordpress Fingerprint and Documents #176
base: master
Are you sure you want to change the base?
Conversation
Today I just got another Scenario for wordpress subdomain takeover. I will call this Scenario-3 Scenario-3
To takeover just follow the same steps to add the domain with you account via domain mapping service ; |
Hey @codingo Thanks. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The finger print may change according to this article https://sapt.medium.com/wordpress-subdomain-takeover-on-bugcrowd-private-program-f59b5a0d74a7 |
Hi @cyb3rsalih, Thanks for your update <3 |
Is this still vulnerable with the latest fingerprint and takeover is possible? anyone who has done it recently? I have recently reported a bug but they want a POC. Please let me know if a takeover is still possible. |
From my testing I got two scenarios where subdomain takeover is possible using Wordpress.com services.
Scenario-1:
If subdomain name is
somethingtesttarget.target.com
and if it's pointing to WordPress and vulnerable to takeover then visiting the subdomain will take user to https://wordpress.com/typo/?subdomain=somethingtesttarget where error page will look like below which confirms it's vulnerable to takeoverScenario-2:
If subdomain name is
something_test.target.com
and if it's pointing to WordPress and vulnerable to takeover then visiting the subdomain will take user to https://wordpress.com/typo/?subdomain=something_test where error page will look like belowNote that it even says The address something_test.wordpress.com cannot be registered. Site names can only contain lowercase letters (a-z) and numbers. but ignore this as you can register a domain via a domain mapping upgrade of Wordpress.com and it will not matter what the underlying .wordpress.com address is.
How to Takeover and create P0C
To takeover a subdomain we need to use Domain Mapping service what is only available for Paid account so you need to buy the Personal package worth 48$ and then
Add a domain to this site
button available at top of the webpageAlready own a domain?
click on it and the select Map Your Domain option.Happy Hacking <3