Subdomain takeovers aren't always straightforward! Found an old target with a subdomain pointing to CloudFront, and its Origin Domain was configured with the S3 bucket's website endpoint. Always check beyond CNAME records to avoid missing these. #BugBounty#BugBountyTips
@Bugcrowd Is considering In Scope subdomain takeover as a Basic Subdomain takeover which is a similar priority as RXSS. While attacker can do stored XSS using a subdomain takeover which is considered as P2 priority. Why this discrimination @BugcrowdSupport ?
#BugBounty
In previous days they considered subdomain takeover with proper PoC as P2 High Impact Subdomain takeover but nowadays all subdomain takeovers are accepted as Basic Subdomain takeover. This is not fair!
@gdattacker@Hacker0x01 I agree. In such case @Bugcrowd platform have done great work. They show original report title and when it was reported. This maintain good relationship with researchers and I think @Hacker0x01 can do the same with their platform too 😇