Code Monkey home page Code Monkey logo

Comments (27)

kishoretrommer avatar kishoretrommer commented on May 29, 2024 6

Not able to takeover a subdomain pointing to GitHub.io. Error with CNAME is already taken.

snapshot attached.

Is GitHub takeover still working for anyone?

Screenshot 2019-03-23 at 1 41 20 PM

Facing the same issue.

from can-i-take-over-xyz.

sumgr0 avatar sumgr0 commented on May 29, 2024 2

Not able to takeover a subdomain pointing to GitHub.io. Error with CNAME is already taken.

snapshot attached.

Is GitHub takeover still working for anyone?

Screenshot 2019-03-23 at 1 41 20 PM

from can-i-take-over-xyz.

sumgr0 avatar sumgr0 commented on May 29, 2024 2

I've experienced the same with Github takeovers in the last couple of days. Looks like github has implemented it across the board.

from can-i-take-over-xyz.

h3cksamrat avatar h3cksamrat commented on May 29, 2024 1

CNAME already taken error occurs in once already created repo and attached cname, so as my understanding *.github.io is not available for takeover.
https://github.community/t/the-cname-is-already-taken/149785

from can-i-take-over-xyz.

akincibor avatar akincibor commented on May 29, 2024 1

Capture d’écran 2022-04-21 à 21 52 19

https://docs.github.com/en/enterprise-cloud@latest/organizations/managing-organization-settings/verifying-or-approving-a-domain-for-your-organization

from can-i-take-over-xyz.

pdelteil avatar pdelteil commented on May 29, 2024 1

@akincibor As mentioned, I ran into this specific issue where it required me to verify the domain by inserting a domain txt entry for verification on my account before I could add the custom domain to a repo.
Do we know if this is always the case for subdomain takeovers via github.io, or only specific domains with a feature enabled?

I found a subdomain pointing to xyz.github.io, and it is vulnerable, but when trying to set the vulnerable subdomain as the custom domain it asks to insert a txt entry for verification. Is there any way to takeover such a domain?

Then, it's not vulnerable.

from can-i-take-over-xyz.

corneliusroemer avatar corneliusroemer commented on May 29, 2024 1

I confirm that the vulnerability still exists, at least for domains without domain verification. Example: turakhia.ucsd.edu

from can-i-take-over-xyz.

PatrikHudak avatar PatrikHudak commented on May 29, 2024

Official GitHub Pages docs: https://help.github.com/articles/using-a-custom-domain-with-github-pages/

from can-i-take-over-xyz.

codingo avatar codingo commented on May 29, 2024

Closing as now available on main readme.

from can-i-take-over-xyz.

sumgr0 avatar sumgr0 commented on May 29, 2024

Is it possible to takeover githubapp.com subdomains with github.io CNAME?

from can-i-take-over-xyz.

ravkishu avatar ravkishu commented on May 29, 2024

Hi @sumgr0

I'm not quite sure but you should be able to, because it's not allowed only in case of github.io, github.com, or github.page as per official error I'm currently getting.
image

There isn't any such notice regarding githubapp.com. So, I suppose you should be able to takeover if it's available.

For more you can head over to https://docs.github.com/articles/setting-up-your-pages-site-repository/

from can-i-take-over-xyz.

netanmangal avatar netanmangal commented on May 29, 2024

Hi @EdOverflow
I am trying to takeover subdomain .github.io but when I create a repo and try to serve it via the Github Pages, I get a URL like netanmangal.github.io/.

Github has started to appending the username to the github.io/

I have done something wrong or I think github pages are no longer vulnerable unless the user/organization have totally deleted their account.

from can-i-take-over-xyz.

monikasharma47 avatar monikasharma47 commented on May 29, 2024

anything.github.io like this github account can we takeover or not

from can-i-take-over-xyz.

monikasharma47 avatar monikasharma47 commented on May 29, 2024

anything.github.io like this github account can we takeover or not ?

from can-i-take-over-xyz.

Abhaysoft-inc avatar Abhaysoft-inc commented on May 29, 2024

I was still able to takeover a domain

from can-i-take-over-xyz.

Notselwyn avatar Notselwyn commented on May 29, 2024

Still works. +1

Looks like it's kind of conditional because it can say that the domain is claimed

from can-i-take-over-xyz.

Elgllad99 avatar Elgllad99 commented on May 29, 2024

I was still able to takeover a domain

how you can takeover yet I have some of the vulnerable URLs, if you can help me..

from can-i-take-over-xyz.

akincibor avatar akincibor commented on May 29, 2024

There is a new beta feature, every custom domain need to be verified. So Github is no more vulnerable.

from can-i-take-over-xyz.

jbreed avatar jbreed commented on May 29, 2024

@akincibor As mentioned, I ran into this specific issue where it required me to verify the domain by inserting a domain txt entry for verification on my account before I could add the custom domain to a repo.

Do we know if this is always the case for subdomain takeovers via github.io, or only specific domains with a feature enabled?

from can-i-take-over-xyz.

Irresistible-K avatar Irresistible-K commented on May 29, 2024

@akincibor As mentioned, I ran into this specific issue where it required me to verify the domain by inserting a domain txt entry for verification on my account before I could add the custom domain to a repo.

Do we know if this is always the case for subdomain takeovers via github.io, or only specific domains with a feature enabled?

I found a subdomain pointing to xyz.github.io, and it is vulnerable, but when trying to set the vulnerable subdomain as the custom domain it asks to insert a txt entry for verification.
Is there any way to takeover such a domain?

from can-i-take-over-xyz.

A7BIL avatar A7BIL commented on May 29, 2024

i found a vulnerable xx.github.io subdmain but when i try to add the domain to a new repository, i get this message
The custom domain xxxxx.domain.com is already taken.
any solution ?

from can-i-take-over-xyz.

sa1tama0 avatar sa1tama0 commented on May 29, 2024

⚠️⚠️ GitHub's pages are now secure and no longer vulnerable. ⚠️⚠️
GitHub has implemented DNS verification to confirm the legitimacy of domains.

GitHub

from can-i-take-over-xyz.

EdOverflow avatar EdOverflow commented on May 29, 2024

⚠️⚠️ GitHub's pages are now secure and no longer vulnerable. ⚠️⚠️ GitHub has implemented DNS verification to confirm the legitimacy of domains.

GitHub

This does not apply to retrospective custom domains, right?

from can-i-take-over-xyz.

akincibor avatar akincibor commented on May 29, 2024

I thought Github was no longer vulnerable to STO but actually I managed to take a subdomain.

from can-i-take-over-xyz.

pdelteil avatar pdelteil commented on May 29, 2024

I thought Github was no longer vulnerable to STO but actually I managed to take a subdomain.

How?

from can-i-take-over-xyz.

dadsgone0 avatar dadsgone0 commented on May 29, 2024

What if there is a 404 no pages site here error, but the account that owns it still exists? like if example30.github.io would 404, but the example30 account still existed, would it be vulnerable?

from can-i-take-over-xyz.

cyberduck404 avatar cyberduck404 commented on May 29, 2024

Confirmed, still be vuln.

from can-i-take-over-xyz.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.