Beanstalk Notion
Beanstalk Notion
/
🪲
Bug Reports
/
BIC Notes
/
📄
Report #32006
📄

Report #32006

Report Date
June 4, 2024
Status
Confirmed
Payout
1,000

Subdomain takeover of phoenix.node.bean.money

‣
Report Info

Report ID

#32006

Report type

Websites and Applications

Has PoC?

Yes

Target

https://app.bean.money

Impacts

Subdomain takeover other than app.bean.money

Description

phoenix.node.bean.money was pointing to an unclaimed Google Cloud IP, making it vulnerable to subdomain takeover. I've managed to claim it in my GCP-account and added a simple html file as POC: http://phoenix.node.bean.money/ZDB4aW5nLWdjcC10YWtlb3Zlcgo.html

Subdomain takeovers can be used for

  • Account takeovers (cookies set to .bean.money will be shared with this subdomain and can be obtained)
  • Stored XSS (arbitrary javascript code can be executed in a users browser, see PoC)
  • Denial of Service via cookie bomb makes the root domain unavailable (see PoC)
  • Phishing
  • Hosting malicious content

Proof of concept

http://phoenix.node.bean.money/ZDB4aW5nLWdjcC10YWtlb3Zlcgo.html

BIR-15: Subdomain Takeover

BIC Response

The BIC has determined that this report is valid. The BIC determined that the impact of this issue is low given that the phoenix.node.bean.money subdomain is not in use and is easily mitigated. For these reasons, the BIC has determined that this bug report be rewarded 1,000 Beans.