Broken like Hijacking earned me $150
断链劫持指攻击者利用网站失效链接(如过期域名、停用社交媒体账号)获取控制权,用于篡改网站内容、钓鱼攻击或注入恶意脚本。检测时可点击链接查看是否返回404错误。 2025-9-9 05:6:37 Author: infosecwriteups.com(查看原文) 阅读量:8 收藏

Canonminibeast

hey hi guys its been a while am writing a blog .

Broken link hijacking

Attackers exploit broken external links—such as expired domains, inactive social media handles, or discontinued third-party services—still referenced by websites. By acquiring control of these expired resources, attackers can:

Press enter or click to view image in full size

broken link hijacking
  • Deface websites by serving offensive or deceptive content.
  • Impersonate organizations or individuals to conduct phishing attacks or damage reputations.
  • Inject malicious scripts (e.g., JavaScript) for cross-site scripting (XSS) or malware distribution

how to reproduce this steps

  • go to the bottom of the website

Press enter or click to view image in full size

  • click each social media handles and look for the 404 found reponses

文章来源: https://infosecwriteups.com/broken-like-hijacking-earned-me-150-d67fc0571582?source=rss----7b722bfd1b8d--bug_bounty
如有侵权请联系:admin#unsafe.sh