id: meteor-takeover info: name: Meteor subdomain takeover author: rivalsec severity: high description: Meteor takeover was detected. reference: - https://rivalsec.github.io/blog/2022/12/02/meteor.html - https://github.com/EdOverflow/can-i-take-over-xyz/issues/321 metadata: max-request: 1 tags: takeover,meteor http: - method: GET path: - "{{BaseURL}}" matchers: - type: word words: - "404 Not Found: No applications registered for host '" extractors: - type: dsl dsl: - cname # digest: 490a00463044022044e9dd247d96539bc796b57ad5f64b0c1dd8e55d81a8ee635133e6ad4858151e02203b6b9c51a9381dcd8ca483156058b271dfe2d77376bcf31c526e03f380e4ac93:922c64590222798bb761d5b6d8e72950