• Home
  • Contact

NARESH LAMGADE

How I Hacked Your Hostgator Account

authorNaresh LamGade
13th February, 2016
bug

Featured Posts

  • TryHackMe : SQLMAP Writeup
    TryHackMe : SQLMAP Writeup
    16th May, 2021
  • Mega.nz Vulnerability: Payment Bypass on Mega Business
    Mega.nz Vulnerability: Payment Bypass on Mega Bus…
    5th June, 2020
  • Dynamic Execution : ASP.NET with Bootstrap
    Dynamic Execution : ASP.NET with Bootstrap
    28th April, 2017

Categories

blog bug bugs security Tech Tips & Trick TryHackMe tutorial Uncategorized

Naresh LamGade

authorNaresh LamGade
13th February, 2016
bug

Hostgator is one of the biggest hosting service provider in the world but still it had some critical issue which let us to hack into any hostgator accounts with just a click i.e, CSRF.

I found a CSRF issue on their hostgator user portal ( https://portal.hostgator.com ).

While updating our account email it send the confirmation link to the particular email inbox.
Authorization Link :

 https://portal.hostgator.com/customer/email/primary/bmFyZXNoLmxhbWdhZGVAZ21haWwuY29tQEBo
L2p1dGNOYVVWQmp6d3IwYjFpV0E1WTdyeUM4Z3FtTE85aVpDNzZXMnpR

So, if we send this authorization link to the victim and if he/she clicks on the link then his/her account will be set with the new email adress.
At first it threw some error like “email already used” but still when we refresh the page and check the setting email. It will be set there.

Here’s a video POC :

 

Hostgator Vulnerability : Account Take Over ( CSRF ) from Naresh LamGade on Vimeo.

This issue was reported back in early 2015 and it has been fixed now, even though they took a long time to fix this and as a reward they offered me free of cost service on one of their any product.

Comments




Share

Twitter Facebook Google+



  • hacking hostgator account
  • hostgator vulnerabiilty

TryHackMe : SQLMAP Writeup
author Naresh LamGade 16th May, 2021
Mega.nz Vulnerability: Payment Bypass on Mega Business
author Naresh LamGade 5th June, 2020
There are no comments.

Leave a Reply
Cancel Reply

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>

Navigation
  • Home
  • Contact
Copyright © Naresh LamGade. 2025 • All rights reserved.
Proudly published with WordPress.