{"id":61,"date":"2016-09-21T00:00:02","date_gmt":"2016-09-20T18:30:02","guid":{"rendered":"http:\/\/www.geekboy.ninja\/blog\/?p=61"},"modified":"2016-09-22T08:06:00","modified_gmt":"2016-09-22T02:36:00","slug":"hijacking-tons-of-instapage-expired-users-domains-subdomains","status":"publish","type":"post","link":"http:\/\/www.geekboy.ninja\/blog\/hijacking-tons-of-instapage-expired-users-domains-subdomains\/","title":{"rendered":"Hijacking tons of Instapage expired users Domains &#038; Subdomains"},"content":{"rendered":"<p><span style=\"color: #000000;\">Hello all \ud83d\ude42<\/span><\/p>\n<p><span style=\"color: #000000;\">so this post is about how I\u00a0was able to hijack ton&#8217;s of domains\/subdomains who using I<strong>nstapage<\/strong> if\u00a0there service got expired.<\/span><\/p>\n<h2><span style=\"color: #000000;\">What is instapage ?<\/span><\/h2>\n<blockquote><p><span style=\"color: #000000;\"><b><a style=\"color: #000000;\" href=\"https:\/\/instapage.com\/\">Instapage<\/a>\u00a0<\/b>is a service that lets you build landing pages for your online marketing and promotion campaigns with ease. It offers features such as A\/B Testing, multiple campaign management, easy page building, and a lot more!<\/span><\/p><\/blockquote>\n<p><strong><span style=\"color: #000000;\">it also allows users to map its\u00a0template\u00a0on\u00a0there own\u00a0domain or subdomains.<\/span><\/strong><\/p>\n<h2><span style=\"color: #000000;\">How i found it ?<\/span><\/h2>\n<p><span style=\"color: #000000;\">as am one of researchers from <a style=\"color: #000000;\" href=\"https:\/\/hackerone.com\"><strong>HackerOne<\/strong><\/a> platform , I\u00a0was trying to get something on <strong>HackerOne<\/strong> itself as I want that <strong>Hacking Hackers<\/strong>\u00a0<strong>Badge<\/strong>\u00a0of my <a style=\"color: #000000;\" href=\"https:\/\/hackerone.com\/geekboy\/badges\">profile<\/a>.<\/span><\/p>\n<p><span style=\"color: #000000;\">I found\u00a0<strong>hacker.one<\/strong> is inscope domain list which is one of the\u00a0officail\u00a0website of <strong>HackerOne<\/strong>, and when I\u00a0vistied it and\u00a0seen some error which caught in my eye and after figuring\u00a0it, I come to know it was <strong>Instapage<\/strong> error which\u00a0occurs when service\u00a0get expired or domain or subdoamin not linked properly and it takes just few mintues to figurte it out that I <strong>can publish my own template to any of misconfigured\u00a0and expired domains\/subdomains of instapage<\/strong> and luckly <strong>HackerOne<\/strong> is one of there users.<\/span><\/p>\n<h3><span style=\"color: #000000;\">Instapage error on Hacker.One :<\/span><\/h3>\n<p><a href=\"http:\/\/www.geekboy.ninja\/blog\/wp-content\/uploads\/2016\/09\/BxwVteM.jpg\"><img loading=\"lazy\" class=\"aligncenter wp-image-90 size-large\" src=\"http:\/\/www.geekboy.ninja\/blog\/wp-content\/uploads\/2016\/09\/BxwVteM-1024x452.jpg\" alt=\"bxwvtem\" width=\"634\" height=\"280\" srcset=\"http:\/\/www.geekboy.ninja\/blog\/wp-content\/uploads\/2016\/09\/BxwVteM-1024x452.jpg 1024w, http:\/\/www.geekboy.ninja\/blog\/wp-content\/uploads\/2016\/09\/BxwVteM-300x132.jpg 300w, http:\/\/www.geekboy.ninja\/blog\/wp-content\/uploads\/2016\/09\/BxwVteM-768x339.jpg 768w, http:\/\/www.geekboy.ninja\/blog\/wp-content\/uploads\/2016\/09\/BxwVteM-816x360.jpg 816w, http:\/\/www.geekboy.ninja\/blog\/wp-content\/uploads\/2016\/09\/BxwVteM.jpg 1457w\" sizes=\"(max-width: 634px) 100vw, 634px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<h3><span style=\"color: #000000;\">Vulnerable Post Request :<\/span><\/h3>\n<pre><span style=\"color: #800000;\">POST \/ajax\/builder2\/publish\/2340488 HTTP\/1.1\r\nHost: app.instapage.com\r\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; rv:36.0) Gecko\/20100101 Firefox\/36.04\r\nAccept: *\/*\r\nAccept-Language: en-US,en;q=0.5\r\nAccept-Encoding: gzip, deflate\r\nContent-Type: application\/x-www-form-urlencoded; charset=UTF-8\r\nX-Requested-With: XMLHttpRequest\r\nReferer: http:\/\/app.instapage.com\/builder2?id=2340488\r\nContent-Length: 31\r\nCookie: cookie_value\r\nConnection: close\r\n\r\nversion=1&amp;url=www.hacker.one<\/span><\/pre>\n<p><span style=\"color: #000000;\">where <strong>url<\/strong> parameter value contain vulnerable domains .<\/span><\/p>\n<h3><span style=\"color: #000000;\">Hacker.One domain Takeover :\u00a0<\/span><\/h3>\n<p><a href=\"http:\/\/www.geekboy.ninja\/blog\/wp-content\/uploads\/2016\/09\/insta-0day.jpg\"><img loading=\"lazy\" class=\"aligncenter size-large wp-image-93\" src=\"http:\/\/www.geekboy.ninja\/blog\/wp-content\/uploads\/2016\/09\/insta-0day-1024x344.jpg\" alt=\"insta-0day\" width=\"634\" height=\"213\" srcset=\"http:\/\/www.geekboy.ninja\/blog\/wp-content\/uploads\/2016\/09\/insta-0day-1024x344.jpg 1024w, http:\/\/www.geekboy.ninja\/blog\/wp-content\/uploads\/2016\/09\/insta-0day-300x101.jpg 300w, http:\/\/www.geekboy.ninja\/blog\/wp-content\/uploads\/2016\/09\/insta-0day-768x258.jpg 768w, http:\/\/www.geekboy.ninja\/blog\/wp-content\/uploads\/2016\/09\/insta-0day-816x274.jpg 816w, http:\/\/www.geekboy.ninja\/blog\/wp-content\/uploads\/2016\/09\/insta-0day.jpg 1918w\" sizes=\"(max-width: 634px) 100vw, 634px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<h3><span style=\"color: #000000;\">Here is the Video POC :<\/span><\/h3>\n<p><iframe loading=\"lazy\" src=\"https:\/\/www.youtube.com\/embed\/ZjdAj3KcPco\" width=\"560\" height=\"315\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/p>\n<p>and with help of <span style=\"color: #000000;\"><strong>Google dork<\/strong><\/span> and error of\u00a0instapage I\u00a0found <span style=\"color: #000000;\"><strong>tons<\/strong><\/span> of websites are\u00a0Vulnerable for this and anyone can takeover it with own content on it, I <span style=\"color: #000000;\"><strong>contacted Instapage via HackerOne<\/strong><\/span>.<\/p>\n<p><span style=\"color: #000000;\"><strong>HackerOne<\/strong> fixed it next of report by removing the cname entry pointing to instapage and later Instapage fixed in completely and got confirmation of fix via <strong>HackerOne report thread<\/strong>.<\/span><\/p>\n<p><span style=\"color: #000000;\">Thanks to <strong>HackerOne<\/strong> to being a mediator\u00a0for\u00a0contacting <strong>Instapage<\/strong> and fixing the things\u00a0in correct\u00a0way.<\/span><\/p>\n<h4>HackerOne report thread :\u00a0<a href=\"https:\/\/hackerone.com\/reports\/159156\">#159156<\/a><\/h4>\n","protected":false},"excerpt":{"rendered":"<p>Hello all \ud83d\ude42 so this post is about how I\u00a0was able to hijack ton&#8217;s of domains\/subdomains who using Instapage if\u00a0there service got expired. What is instapage ? Instapage\u00a0is a service that lets you build landing pages for your online marketing and promotion campaigns with ease. It offers features such as A\/B Testing, multiple campaign management, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":121,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[1],"tags":[4,6,5],"_links":{"self":[{"href":"http:\/\/www.geekboy.ninja\/blog\/wp-json\/wp\/v2\/posts\/61"}],"collection":[{"href":"http:\/\/www.geekboy.ninja\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.geekboy.ninja\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.geekboy.ninja\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.geekboy.ninja\/blog\/wp-json\/wp\/v2\/comments?post=61"}],"version-history":[{"count":47,"href":"http:\/\/www.geekboy.ninja\/blog\/wp-json\/wp\/v2\/posts\/61\/revisions"}],"predecessor-version":[{"id":118,"href":"http:\/\/www.geekboy.ninja\/blog\/wp-json\/wp\/v2\/posts\/61\/revisions\/118"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.geekboy.ninja\/blog\/wp-json\/wp\/v2\/media\/121"}],"wp:attachment":[{"href":"http:\/\/www.geekboy.ninja\/blog\/wp-json\/wp\/v2\/media?parent=61"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.geekboy.ninja\/blog\/wp-json\/wp\/v2\/categories?post=61"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.geekboy.ninja\/blog\/wp-json\/wp\/v2\/tags?post=61"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}