EdOverflow/can-i-take-over-xyz

Subdomain Takeover through Kinsta

Avileox opened this issue · 7 comments

Service name

Kinsta

Website

https://kinsta.com/

Credential

screenshot 45 _li

Condition

Subdomain takeover through Kinsta is possible but for creating POC you need a paid account because kinsta need a paid account for creating subdomains and using web hosting through kinsta.

@Cyberdolt have you performed one of these already or do you have a reference writeup so I can add this to the main repository?

I reported this issue but the organization didn't fix the issue yet so, I am waiting for them to resolve after that I will provide the full description.

@Avileox
How it possible to take a subdomain over as long as it has an A record for a kinsta dedicated IP ?

Most Probably, It is impossible to takeover subdomain with A record through Kinsta.
Here is the response from kinsta for orphan CNAME.
404 Not Found
Content-Length=[33604]
Server = kinsta-nginx

I met the same response with an A record

So does that mean, if a vulnerable subdomain has the A record pointing to an IP, it's impossible to takeover the subdomain?

This is no longer possible, requires TXT verification.