SUBDOMAIN-TAKEOVER
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Finding and confirming dangling DNS records that point to unclaimed third-party services. Report responsibly; do not host malicious content.
THE BUG IN ONE LINE#
A CNAME (or A/NS/MX) points at a service (S3, Azure, GitHub Pages, Heroku, ...) that no longer has the resource provisioned. An attacker registers that resource and controls content on the subdomain.
ENUMERATE SUBDOMAINS#
subfinder -d target.com -all -silent > subs.txt
amass enum -passive -d target.com
assetfinder --subs-only target.com
# Certificate transparency
curl -s "https://crt.sh/?q=%25.target.com&output=json" | jq -r '.[].name_value' | sort -u
RESOLVE & FIND DANGLING RECORDS#
dnsx -l subs.txt -cname -resp -silent
# Look for CNAMEs to third-party services with NXDOMAIN / no resource
for s in $(cat subs.txt); do
echo "$s -> $(dig +short CNAME $s)"; done
AUTOMATED DETECTION#
subjack -w subs.txt -t 50 -ssl -c fingerprints.json -v
nuclei -l subs.txt -t http/takeovers/
subzy run --targets subs.txt
can-i-take-over-xyz # community fingerprint reference (EdOverflow)
COMMON FINGERPRINTS#
AWS S3 "NoSuchBucket" / "The specified bucket does not exist" GitHub Pages "There isn't a GitHub Pages site here" Heroku "No such app" / herokucdn 404 Azure "404 Web Site not found" (*.azurewebsites.net, trafficmanager) Shopify "Sorry, this shop is currently unavailable" Fastly "Fastly error: unknown domain" Zendesk "Help Center Closed" Readme.io "Project doesnt exist" Unbounce "The requested URL was not found" NOTE: fingerprints change; always verify manually before claiming a finding.
CONFIRM (SAFE PROOF)#
- Register/claim the resource on the service (if scope allows) and
serve a harmless proof file, e.g. /takeover-poc-<yourhandle>.txt.
- Or document the exact dangling CNAME + the service's "unclaimed"
response as evidence WITHOUT hosting content.
- Never serve phishing, malware, or capture user data.
NS / MX / DANGLING DELEGATION#
dig NS sub.target.com # delegated to a nameserver you can register?
dig MX target.com # dangling mail provider
# Expired/parked base domains referenced in CNAMEs are also takeover-able.
IMPACT TO REPORT#
- Cookie theft / session fixation for the parent domain (scope depends
on cookie flags), phishing on a trusted subdomain, OAuth redirect
abuse, CSP bypass, SPF/DKIM/email spoofing (for MX/TXT).
PREVENTION (blue side)#
- Remove DNS records when you decommission a service (fix the order:
delete the record before releasing the resource).
- Continuous DNS + takeover monitoring; claim wildcard resources.
See also: OSINT-TECHNIQUES, SUBFINDER, AMASS, DNSRECON.