How I took over several Stanford subdomains. Also, let me explain you the pain to report it!

4 years ago 266
BOOK THIS SPACE FOR AD
ARTICLE AD

Philippe Delteil

While using nuclei and the template detect-all-takeovers.yaml, I found several (over 20) subdomains of Stanford (stanford.edu) what were pointing to this error page:

Image for post

Image for post

Pantheon 404 Error Page

That was a clear indicator that those subdomains were susceptible to be taken over. The site I usually use to gather information about this type of attacks is Can I take Over XYZ?. But, this post also helped me to get started.

These are the steps I follow in order to take over the subdomains:

Create a Pantheon account (here).Create a Sandboxed domain using Wordpress (or Drupal)

Image for post

Image for post

After selecting Wordpress, it takes a while to deploy:

Image for post

Image for post

3. Added a credit card, then subscribed as ‘Professional’ to setup the sandboxed domain.

4. Added the subdomains

One example

Image for post

Image for post

Adding ksp.stanford.eu

All of them

Image for post

Image for post

Now, the content of the subdomains are controlled by me!

One example: https://foodsecurity.stanford.edu

Image for post

Image for post

What a beautiful new web site.

What’s the reason of this issue?

I tried to find out if those sites were ever properly linked to a pantheon account, but according to Waybackmachine they were not. So I guess they created the subdomain, pointed the DNS registry to Pantheon's, but never configure them properly.

The DNS registry of one of the subdomains was the following:

Image for post

Image for post

Did you think the difficult part was the take over? Stanford has a private bug bounty program, only for students and employees. That's weird. First rule of the game is:

Right away I knew I was not getting paid a bounty for this subdomain take over (another one I accomplish, got paid $500). But still wanted to report the issue, I never imagine it would have taken me so much time just to send a report!

First wall

After clicking here:

Image for post

Image for post

Please let me submit! I don't care about the bounty.

This is where I ended up.

Image for post

Image for post

You are correct! I can't find what I was looking for.

Many hackers publish their discoveries on Twitter, sometimes corporations are faster and more reliable on Twitter. I was wrong. Maybe Facebook would work better?

Image for post

Image for post

No answer :(

Tickets, please give me a ticket!

After heavy googling, I ended up submitting a ticket. A ticket.

Image for post

Image for post

Wasn't quick, that's for sure.

After 6 days, no answer, no thanks, no bounty. I will update this post if something change.

Read Entire Article