Domain Takeover [3737signals.com]

Program: basecamp Bug Type: Subdomain takeover Bounty: Unspecified Date: 2021-08-13
subdomain-takeover

Summary

The researcher on reviewing the android source code, came across a referenced domain - 3737signals[.]com which was similar to the domain used by the application - 37signals[.]com, on checking the website, it returned a response saying requested url could not be retrieved and it was a webmasters error page. On checking the domain availability, it was on sale in webmasters.com.

References