4 ms·
howdy - the hijackers didn't purchase anything. the subdomains that were compromised were * .thehousepartyapp.com // that domain had full privileges on housepar
by thezedwards 6y ago
howdy - the hijackers didn't purchase anything. the subdomains that were compromised were * .thehousepartyapp.com // that domain had full privileges on houseparty.com in their CSP policy due to it being written as https://*.thehousepartyapp.com https://*.thehousepartyapp.com // whenever a user logged into HouseParty.com or did a password reset or anything with the authentication systems, they were making requests to endpoints on thehousepartyapp.com -- the 2-domain architecture was extremely questionable from the get-go, but became outright dangerous when they lost control of the subdomains on their authentication domain. cheers~
- brianmcc 6y agoYou're the Zach Edwards behind the findings I assume? Helpful to confirm in case others miss the username implication! (Nice work!)
- thezedwards 6y agothank you! yup that's me