IK-NJS-6 — Infomaniak H3 vhost_route alias hijack

You navigated to node.hkosec2.fun, but your traffic landed on a different IK customer's pod.

Root cause: POST /proxy/1/hostings/{H}/vhost_route/{F}/aliases on manager.infomaniak.com accepts arbitrary FQDNs (including other customers' domains and arbitrary third-party hostnames) without DNS ownership challenge. Envoy Gateway routes any matching Host header to the attacker's pod.

host_header_received: node.hkosec2.fun
path: /sitemap.xml
served_by: acct B (user_id 2848337, KH02848)
served_at: 2026-06-10T22:59:54.144Z
envoy_via: 216.73.216.175
x_request_id: 7c69e8f5-af38-4f97-9039-52fbde7c4651

Authorized YesWeHack security research. This pod operated by hko-ywh-c70c8a9c02d08079@yeswehack.ninja intercepts only Host headers explicitly claimed as aliases on this hosting. Real customer FQDNs not in this hosting's aliases table receive TLS handshake reset (Envoy default). Aliases are removed immediately after evidence capture.