delicious

Hostile Subdomain Takeover using Heroku/Github/Desk + more

A murb'ed feed, posted about 7 years ago filed in security, service, github, heroku, trust & ssl.

Neglecting DNS settings can make it easy to claim valid looking (sub)domains. Subdomains in particular, are easy to neglect when a contract with a service like Heroku ends. When the contract ends another party can claim your (sub)domain with the service and start running their own software on it. And SSL certificates won’t protect you here. This article explains in more depth how that works.

Go to the original link.