Subdomain Takeover PoC

Domain: api-finance-portal-qa.rapyd.org

Claimed by: 89p13 (Bugcrowd authorized security testing)

Program: rapyd-og on Bugcrowd

Contact: 89p13@bugcrowdninja.com

Date: 2026-04-07

This page demonstrates that an external party has taken control of this subdomain due to a dangling CNAME record pointing to an unclaimed Cloudflare Pages project.


Bearer Token Interception

All /api/v1/* requests from the finance portal frontend are captured by this server. Any request with an Authorization: Bearer header is logged below.

To test: log in at finance-portal-qa.rapyd.org — the React app will send API requests here automatically.

Self-test