id: zendesk-takeover info: name: Zendesk Takeover Detection author: pdteam severity: high description: Zendesk takeover was detected. reference: - https://github.com/EdOverflow/can-i-take-over-xyz/issues/23 - https://hackerone.com/reports/869605 - https://hackerone.com/reports/759454 metadata: max-request: 1 tags: takeover,zendesk,hackerone http: - method: GET path: - "{{BaseURL}}" matchers-condition: and matchers: - type: dsl dsl: - Host != ip - type: word words: - "this help center no longer exists" - "Help Center Closed" condition: or extractors: - type: dsl dsl: - cname # digest: 490a0046304402206d9420b7cd81ee2181052c35398327050fd8834af6fe245b116a08eb4437b48802202c89cd8b2f61fd56f5fd342d628f6856df3c15e503572bf5aec338f3a2d46b10:922c64590222798bb761d5b6d8e72950