clever-takeover: Clever Cloud - Subdomain Takeover Detection

日期: 2025-08-01 | 影响软件: Clever Cloud | POC: 已公开

漏洞描述

Clever Cloud subdomain takeover was detected.

PoC代码[已公开]

id: clever-takeover

info:
  name: Clever Cloud - Subdomain Takeover Detection
  author: supr4s
  severity: high
  description: Clever Cloud subdomain takeover was detected.
  reference:
    - https://supras.io/new-subdomain-takeover-case-clever-cloud/
  metadata:
    max-request: 1
  tags: takeover,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}"

    matchers-condition: and
    matchers:
      - type: dsl
        dsl:
          - Host != ip

      - type: word
        part: body
        words:
          - "The application you're trying to access doesn't seem to exist"
          - "support@clever-cloud.com"
        condition: and

    extractors:
      - type: dsl
        dsl:
          - cname
# digest: 490a0046304402200404100de2f54bdb59eddba2228c1a081bad673deb878839e2df165ac7ba30a402200d32301b5c8faa13849df2096f6568f6267f43270da3e912c54be4111a3771e1:922c64590222798bb761d5b6d8e72950

相关漏洞推荐