Subdomain takeover
When a subdomain points (via CNAME or another DNS record) to an external service that
no longer exists or is unclaimed, the attacker can register that resource and serve
their own content from the victim’s subdomain. Being a legitimate domain, it inherits
its trust: credible phishing, domain-cookie theft, subdomain allow-list bypass
(OAuth/CORS/CSP) and reputational damage.
Threat model
Section titled “Threat model”- Highly credible phishing on the real domain.
- Cookie theft if
Domainis broad (.company.tld). - Trust bypass: subdomains in OAuth
redirect_uriallow-lists, CORS, CSP or cookies. - Reputation abuse (email sending, malware distribution from the domain).
Anatomy
Section titled “Anatomy”A dangling DNS record: the subdomain has a CNAME (or A/NS) to a provider resource
that was deleted but the DNS record remains. The provider lets you claim that
resource name (bucket, app, page) → you serve your content. Vulnerable record types:
dangling CNAME (most common), A/AAAA to a claimable IP (cloud), and dangling NS
(takeover of the whole zone).
Red Team
Section titled “Red Team”Process
Section titled “Process”- Enumerate subdomains (see area 01) and resolve their records (
dnsx,subfinder). - Find those pointing to third-party services giving an “unclaimed” page (the provider’s typical error).
- Claim the resource at that provider (create the bucket/app/page with that name).
- Publish a harmless PoC (a page with your mark) to prove control.
Common fingerprints
Section titled “Common fingerprints”AWS S3 "NoSuchBucket"GitHub Pages "There isn't a GitHub Pages site here"Heroku "No such app" / herokucdnAzure "404 Web Site not found" (*.azurewebsites.net, *.cloudapp.net)Fastly "Fastly error: unknown domain"Shopify "Sorry, this shop is currently unavailable"Zendesk "Help Center Closed"Readthedocs, Surge, Netlify, Cargo, Tumblr, Unbounce... (see can-i-take-over-xyz)Tooling
Section titled “Tooling”subjack, nuclei (takeover templates), dnsx/httpx/subfinder, and the reference
list can-i-take-over-xyz (which services are claimable and how).
Impact and chaining
Section titled “Impact and chaining”Phishing, cookie theft, and bypass of controls that trust the subdomain: e.g. if
login.company.tld is in the OAuth redirect_uri list, a takeover of another trusted
subdomain can chain to ATO.
Blue Team
Section titled “Blue Team”Detection
Section titled “Detection”- Continuous DNS inventory:
CNAME/A/NSrecords to third-party services; alert on those returning “not claimed”. - Monitoring of subdomain responses (“resource doesn’t exist” fingerprints).
Hardening
Section titled “Hardening”- Decommission process: when removing a service, remove the DNS record first.
- Automated monitoring of DNS and subdomains (nuclei/takeover in CI).
- Ownership verification and, where possible, preventive resource claiming.
Response
Section titled “Response”Remove/fix the DNS record, claim the resource to take it from the attacker, and review abuse (phishing, stolen cookies).
CVEs and real-world cases
Section titled “CVEs and real-world cases”- Not a product CVE but a DNS configuration issue; one of the most frequent and high-impact bug-bounty findings, with public cases at major brands (documentation, marketing or forgotten old-environment subdomains).
Testing checklist
Section titled “Testing checklist”- Subdomains enumerated and records (
CNAME/A/NS) resolved. - Dangling records to claimable services identified (by fingerprint).
- Takeover demonstrated with a harmless PoC on the subdomain.
- Chaining evaluated (domain cookies, OAuth/CORS allow-lists).