Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Smartling Takeover #67

Open
Regala opened this issue Nov 16, 2018 · 19 comments
Open

Smartling Takeover #67

Regala opened this issue Nov 16, 2018 · 19 comments
Labels
edge case An edge case was discovered where it is possible to hijack a subdomain on this service.

Comments

@Regala
Copy link

Regala commented Nov 16, 2018

Service name

Smartling is a translation service.

Proof

If the vulnerable domain has a CNAME pointing to e.g. *.smartling.com - open that domain and check for the string:

"Domain is not configured"

This means it should be possible to takeover.

Documentation

Problem here is I can't actually be sure this works. A couple of subdomain takeover tools mention this service as well as this fingerprint, but I can't actually look up any report or blog post specifying this. Furthermore, to have access to smartling it seems you actually have to go through a manual register / validation process (I might be wrong).

The best reference so far is actually smartling documentation here. Reading the article, it doesn't seem any kind of ownership verification is done so, in theory, should be possible to just register a domain and complete the takeover.

If anyone can dig a bit more on this, would be awesome.

@codingo codingo added the edge case An edge case was discovered where it is possible to hijack a subdomain on this service. label Nov 16, 2018
@Regala
Copy link
Author

Regala commented Nov 16, 2018

No idea how to test this, so happy if you can do the ground work.

Where's an example domain:
http://cn.atlassian.sl.smartling.com/

This comes from cn.atlassian.com - there's a CNAME pointing there. However, because there A records, it never reaches the CNAME. I think. Who knows, this is unicorns stuff for me.

@K4r1it0
Copy link

K4r1it0 commented Feb 21, 2019

is this still takeover-able

@shubham4500
Copy link

paid service :(

@knc331
Copy link

knc331 commented Apr 20, 2020

I was able to signup, however i was unable to access the Smartling dashboard where we can perform the subdomain configurations. I am yet to explore more. If any of you guys know about this please through some light. If it is a paid service, I am ok to purchase but this should work.

@knc331
Copy link

knc331 commented Apr 20, 2020

paid service :(

Any more information you have on the Shubam?

@swethasridevi
Copy link

@knc331 How did you signup?

@ankushgoel27
Copy link

Any more information on this?

@jah-cyber
Copy link

anything ??

@ms-geeky
Copy link

nah nothing!

@edoardottt
Copy link

Any info?

@pdelteil
Copy link
Contributor

pdelteil commented Apr 4, 2021

It seams that you can't create a new account.

@pdelteil
Copy link
Contributor

pdelteil commented May 7, 2021

It seams that you can't create a new account.

I've tried many times to request a demo in order to create an account but no success in the last 6 months.

I think it should be declared 'Not Vulnerable'

@0xcrypto
Copy link

Completely manual process, should be Not Vulnerable. @knc331 I think all you did was signed in with Google. You won't be able to do anything with that account aside from logout.

pdelteil added a commit to pdelteil/nuclei-templates that referenced this issue Jun 5, 2021
There's no evidence the takeover is possible. Is not possible to create an account or request for a demo. 

EdOverflow/can-i-take-over-xyz#67
@vsanjay
Copy link

vsanjay commented Jun 27, 2021

its not vulnerable :(

@TheJulfikarpoc
Copy link

I was able to signup, however i was unable to access the Smartling dashboard where we can perform the subdomain configurations. I am yet to explore more. If any of you guys know about this please through some light. If it is a paid service, I am ok to purchase but this should work.

How did you sign up?

@xmrstickers
Copy link

is this still a non-issue? still finding smartling domains with the "Domain is not configured" text

@khaled4android
Copy link

I can't sign up in smartling? how can I do?

@m-tabarik
Copy link

It's the same issue discussed above. I think it's not vulnerable ;)

@elvish-saurabh
Copy link

Has anyone created an account on Smartling? if yes then please share the process

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
edge case An edge case was discovered where it is possible to hijack a subdomain on this service.
Projects
None yet
Development

No branches or pull requests