8F
Ghost subdomain takeover not possible on 404: Page Not Found The thing you were looking for is no longer here, or never was · Issue #89 · EdOverflow/can-i-take-over-xyz · GitHub
You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
In the case I was testing it was not possible, here the detail:
target.domain.com alias for target2.ghost.io
Tried to create an account/site using target2 but it was created as target2-2. And when I tried to change it manually, displayed an error message to contact support.
Service name
This is only possible to takeover if http://vulnerabledomain.ghost.io/ghost/#/signin is redirect to https://offline.ghost.org/#/signin (where vulnerable domain is vulnerable host like adminpatel etc. )
Proof
go to https://adminpatel.ghost.org/ghost/#/signin and takeover it
The text was updated successfully, but these errors were encountered: