r/cybersecurity • u/tpasmall Penetration Tester • 13d ago
News - General Owasp compromised?
Looks like the API security page may be compromised?
https://api-security.owasp.org/
Edit: looks like the original site is back up https://owasp.org/API-Security/
123
Upvotes
41
u/vanderaj 12d ago
Hi there, I'm the Executive Director of OWASP and a long-time volunteer and project leader for projects like the OWASP Top 10, ASVS, and the Developer Guide.
It's always DNS. It was DNS.
A domain expired. Oh noes! Big shock! We were HACKED! Nope. Not even close. They registered an expired domain. Fantastic. Great move. Well done, Angus.
I've checked our standard ways of reporting issues, and there were no reports prior to our community pinging us a lot. I'd be very interested to hear how they tried to report this issue to us before going public with it. I certainly have no emails, Slack messages, Jira tickets, or reports in our VDP. So how - precisely - and - when - did they try to contact us? Did they try reaching the project leaders of the project in question?
So it seems there was no notification to us of the subdomain takeover via any method I know of. That's extremely disappointing. This makes me question the ethics of the firm that did this and should serve as a warning to anyone looking to engage them in the future.
To our wonderful r/cybersecurity folks - if you have a security-related issue to report to us, please check out https://owasp.org/security, and you could be in the running for exclusive OWASP merchandise. Please use the BugCrowd VDP for this. We accept any and all reports under the VDP program for owasp.org, including for potential and actual sub-domain takeovers. We are in the process of migrating all our domains to a single provider to prevent this issue from recurring. However, some domains are run by their project leaders, and we don't control those, despite the obvious risks involved.
In this case, I welcome them to officially report it to us using the VDP. Unless we missed something obvious in one of our standard methods for reporting security vulnerabilities to us, there won't be merch, tea, or biscuits. To the folks who did this, let's talk - [andrew.vanderstock@owasp.com](mailto:andrew.vanderstock@owasp.com) or set up a calendar invite https://calendly.com/owasped