Skip to content

Subdomain takeover

When a subdomain points (via CNAME or another DNS record) to an external service that no longer exists or is unclaimed, the attacker can register that resource and serve their own content from the victim’s subdomain. Being a legitimate domain, it inherits its trust: credible phishing, domain-cookie theft, subdomain allow-list bypass (OAuth/CORS/CSP) and reputational damage.

  • Highly credible phishing on the real domain.
  • Cookie theft if Domain is broad (.company.tld).
  • Trust bypass: subdomains in OAuth redirect_uri allow-lists, CORS, CSP or cookies.
  • Reputation abuse (email sending, malware distribution from the domain).

A dangling DNS record: the subdomain has a CNAME (or A/NS) to a provider resource that was deleted but the DNS record remains. The provider lets you claim that resource name (bucket, app, page) → you serve your content. Vulnerable record types: dangling CNAME (most common), A/AAAA to a claimable IP (cloud), and dangling NS (takeover of the whole zone).

  1. Enumerate subdomains (see area 01) and resolve their records (dnsx, subfinder).
  2. Find those pointing to third-party services giving an “unclaimed” page (the provider’s typical error).
  3. Claim the resource at that provider (create the bucket/app/page with that name).
  4. Publish a harmless PoC (a page with your mark) to prove control.
AWS S3 "NoSuchBucket"
GitHub Pages "There isn't a GitHub Pages site here"
Heroku "No such app" / herokucdn
Azure "404 Web Site not found" (*.azurewebsites.net, *.cloudapp.net)
Fastly "Fastly error: unknown domain"
Shopify "Sorry, this shop is currently unavailable"
Zendesk "Help Center Closed"
Readthedocs, Surge, Netlify, Cargo, Tumblr, Unbounce... (see can-i-take-over-xyz)

subjack, nuclei (takeover templates), dnsx/httpx/subfinder, and the reference list can-i-take-over-xyz (which services are claimable and how).

Phishing, cookie theft, and bypass of controls that trust the subdomain: e.g. if login.company.tld is in the OAuth redirect_uri list, a takeover of another trusted subdomain can chain to ATO.

  • Continuous DNS inventory: CNAME/A/NS records to third-party services; alert on those returning “not claimed”.
  • Monitoring of subdomain responses (“resource doesn’t exist” fingerprints).
  1. Decommission process: when removing a service, remove the DNS record first.
  2. Automated monitoring of DNS and subdomains (nuclei/takeover in CI).
  3. Ownership verification and, where possible, preventive resource claiming.

Remove/fix the DNS record, claim the resource to take it from the attacker, and review abuse (phishing, stolen cookies).

  • Not a product CVE but a DNS configuration issue; one of the most frequent and high-impact bug-bounty findings, with public cases at major brands (documentation, marketing or forgotten old-environment subdomains).
  • Subdomains enumerated and records (CNAME/A/NS) resolved.
  • Dangling records to claimable services identified (by fingerprint).
  • Takeover demonstrated with a harmless PoC on the subdomain.
  • Chaining evaluated (domain cookies, OAuth/CORS allow-lists).