Haqtify Haqtify Haqtify Haqtify
  • Home
  • About
  • Pricing
  • BBP ManagementNew
  • BBP Writeups
  • Contact
Haqtify
  • Writeups

    • All
    • Broken Access Control
    • CSRF
    • RCE
    • Subdomain Takeover
    • XSS
    • SQLi

Subdomain Takeover via Heroku

  • Reported to Private
  • Reported by Haqtify
  • Medium (6)
  • No Likes

URL :

http://napagetaway.redacted.com/

Possible To Takeover Hint:

Steps To Reproduce:

1.Create a new app. New App name same as expire domain name DNS.

https://dashboard.heroku.com/new-app

 

2. After created goto APP and then settings.

https://dashboard.heroku.com/apps/[APP-NAME]/settings

3. Now goto Domain section and Add Domain.

4. Now Add Expired Domain in it.

5. Domain Takeover Successfully.

  • 0
Leave a Reply Cancel Reply

Get your security assessed today

Schedule A Free Consultation Call

Free Security Assessment Trial

Fill the form below and we’ll analyze your website/web application and find security gaps for free. Our free trial gives you a taste of how we protect your site from threats.

    © 2025 Haqtify. All rights reserved. Website by

    • Facebook
    • Twitter
    • LinkedIn
    • Home
    • About
    • Pricing
    • BBP ManagementNew
    • BBP Writeups
    • Contact
    Start Typing