Subdomain Takeover - Super.so -(https://super.so) #422
sn1p3rt3s7
started this conversation in
General
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Service name - Super.so
Super.so is an online tool that allows you to convert Notion pages to a Website. The docs says it provides some advantage over Notion Webpage, as it allows JS, CSS code.
Error Message:
Exceptions
There are some things to consider.
Even if the site responds with Error: "This page doesn't seem to exist. Click anywhere to go back.". This doesn't always guarantee a takeover
e.g:
The internal directories are still accessible.
The subdomain is not available for registration which means in this case takeover is not possible.
The error at home page is due to the Notion page got deleted I believe.
If the site with error, is not pointing to a super.site subdomain. Premium subscription allow custom domain, see the below screenshot, it is not pointing to a subdomain of super.site and such case is also not possible.
Proof
super.site
with interesting texts.Checked if the subdomain available to register in super.so.
Now after some minutes, you should see your configured Notion page content.
The following filter can be used in Netlas, it seems to be helpful in finding such cases.
http.status_code:>399 AND http.body:("https://assets.super.so/")
Beta Was this translation helpful? Give feedback.
All reactions