id: zendesk-takeover info: name: Zendesk Takeover Detection author: pdteam severity: high description: Zendesk takeover was detected. reference: - https://github.com/EdOverflow/can-i-take-over-xyz/issues/23 - https://hackerone.com/reports/869605 - https://hackerone.com/reports/759454 metadata: max-request: 1 tags: takeover,zendesk,hackerone http: - method: GET path: - "{{BaseURL}}" matchers-condition: and matchers: - type: dsl dsl: - Host != ip - type: word words: - "this help center no longer exists" - "Help Center Closed" condition: or # digest: 4a0a0047304502207f13a85b5f36efa57d0417babbb39d81e6573465eb6125f2ea3f06bdedfd3b7702210082fd4d63db637fc0ce9dd06c534393dfdd113a06b4b1408dcb348d941ead9c2a:922c64590222798bb761d5b6d8e72950