Closed Bug 1635655 Opened 5 years ago Closed 5 years ago

Subdomain takeover of vmimages.mozilla.net

Categories

(Infrastructure & Operations :: DNS and Domain Registration, task)

task
Not set
normal

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: leo.sta.ls, Unassigned)

Details

(Keywords: reporter-external, sec-moderate, wsec-takeover, Whiteboard: [reporter-external] [web-bounty-form] [verif?])

Hi!

I discovered that vmimages.mozilla.net was pointing to an unclaimed s3 bucket, making it vulnerable to subdomain takeover.

I've claimed the s3 bucket in my aws account and added a simple POC file:
http://vmimages.mozilla.net/takeover.html

Mitigations:

  • Remove CNAME to vmimages.mozilla.net.s3-website-us-west-2.amazonaws.com.

Impact:

Subdomain takeovers can be abused for bad things such as:

  • account takeovers
  • phishing
  • hosting malicious content

Best regards,
Leo S

Flags: sec-bounty?

Confirmed - thanks for reporting this.

Assignee: nobody → infra
Status: UNCONFIRMED → NEW
Component: Other → DNS and Domain Registration
Ever confirmed: true
Keywords: wsec-takeover
Product: Websites → Infrastructure & Operations
QA Contact: cshields
Version: unspecified → ---

This was marked invalid in bug 1608019. :ericz, any idea what's going on with that? Did we incorrectly mark it invalid there?

Flags: needinfo?(eziegenhorn)
Flags: needinfo?(eziegenhorn)

No that actually was invalid then and is unfortunately valid now. The s3 bucket was deleted yesterday. We will clean up the dangling DNS.

Ed cleaned it up. We discussed the need for DNS cleanup in the decomm process and we're working to be more proactive on catching these. Thanks!

Status: NEW → RESOLVED
Closed: 5 years ago
Resolution: --- → FIXED

Leo, how would you like to be credited for this one?

Group: websites-security
Flags: sec-bounty?
Flags: sec-bounty-hof+
Flags: sec-bounty+

Hi! You can use my name "Leo Starcevic" for the HoF.
Thank you!

Keywords: sec-moderate
You need to log in before you can comment on or make changes to this bug.