Skip to content
Cosmopediaby Unity Nodes
DiscussionsSecuritySecurity Incident Report: qa.cosmos.network subdomain takeoverForum ↗

Security Incident Report: qa.cosmos.network subdomain takeover

Security1 posts1,077 views2 likesLast activity Sep 2020
AL
alessioOP
Sep 2020 2

cosmos-security-incident-report 2400×1350 344 KB On September 16th, an independent security researcher made contact with us via the [email protected] email address and reported a security breach ( subdomain takeover ) affecting our DNS. We’ve promptly filed a low-risk security incident and have completed a remediation. What happened When using external services for hosting web applications (such as Github Pages, Netlify and so on), it is common to use a custom domain/subdomain in order to allow accessing the application. This is usually achieved by indicating which domain/subdomain will be used in the service provider and then adding a DNS record (type A or CNAME) pointing at a server or another domain/subdomain provided by the external service. This is also how the ownership of the custom domain is proved. However, if the service is deleted from the external service provider, but the DNS record is left untouched, anyone can create a new service in this same provider, and use the same name and custom domain. This will result in a new web application deployed on the same domain/subdomain, which belongs to the old owner. This is what happened with the…

Excerpt (1186 of 1887 characters). Read the whole post on the forum ↗

← Back to Discussions