Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ghost subdomain takeover not possible on 404: Page Not Found The thing you were looking for is no longer here, or never was #89

Open
gujjuboy10x00 opened this issue Apr 15, 2019 · 4 comments

Comments

@gujjuboy10x00
Copy link

Service name

This is only possible to takeover if http://vulnerabledomain.ghost.io/ghost/#/signin is redirect to https://offline.ghost.org/#/signin (where vulnerable domain is vulnerable host like adminpatel etc. )

Proof

go to https://adminpatel.ghost.org/ghost/#/signin and takeover it

@Kaue-Navarro
Copy link

Hello good afternoon!!

Is this acquisition still possible?

@Kaue-Navarro
Copy link

YES, I CONFIRME is possible acquisition!

domain.com is an alias for xxxxx.ghost.io.

image

@pdelteil
Copy link
Contributor

pdelteil commented Mar 30, 2023

In the case I was testing it was not possible, here the detail:

target.domain.com alias for target2.ghost.io

Tried to create an account/site using target2 but it was created as target2-2. And when I tried to change it manually, displayed an error message to contact support.

image

@Kaue-Navarro
Copy link

First you create a common site there you will get a pseudonym from them.

Then in the account you change it.

https://medium.com/@kauenavarro/bug-bounty-subdomain-takeover-in-target-cname-ghost-io-e5c601a2dd55

So if your case was not the same as mine in terms of configuration within the platform by the target host.

But see my article if it helps you understand the process.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants