flexbe-takeover: Flexbe Subdomain Takeover

日期: 2025-08-01 | 影响软件: Flexbe | POC: 已公开

漏洞描述

Flexbe takeover was detected.

PoC代码[已公开]

id: flexbe-takeover

info:
  name: Flexbe Subdomain Takeover
  author: 0x_Akoko
  severity: high
  description: Flexbe takeover was detected.
  reference:
    - https://web.archive.org/web/20211002185648/https://github.com/EdOverflow/can-i-take-over-xyz/issues/237
    - https://help.flexbe.com/domains/
  metadata:
    max-request: 1
  tags: takeover,flexbe,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}"

    matchers-condition: and
    matchers:
      - type: dsl
        dsl:
          - Host != ip

      - type: word
        condition: and
        words:
          - "Domain not configured"
          - "flexbe.com"

      - type: status
        status:
          - 404

    extractors:
      - type: dsl
        dsl:
          - cname
# digest: 490a004630440220089d348b730469be1852e3e0b8ce2c16098bfe9efd35f03b76b20d51c202903102207a205d00b303dc13ad17de16e0208046eb2f4a338a488b3cccfbd0481a55f943:922c64590222798bb761d5b6d8e72950

相关漏洞推荐