← All cheat sheets

SUBDOMAIN-TAKEOVER

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Finding and confirming dangling DNS records that point to unclaimed
third-party services. Report responsibly; do not host malicious content.

THE BUG IN ONE LINE#

  A CNAME (or A/NS/MX) points at a service (S3, Azure, GitHub Pages,
  Heroku, ...) that no longer has the resource provisioned. An attacker
  registers that resource and controls content on the subdomain.

ENUMERATE SUBDOMAINS#

    subfinder -d target.com -all -silent > subs.txt
    amass enum -passive -d target.com
    assetfinder --subs-only target.com
    # Certificate transparency
    curl -s "https://crt.sh/?q=%25.target.com&output=json" | jq -r '.[].name_value' | sort -u

RESOLVE & FIND DANGLING RECORDS#

    dnsx -l subs.txt -cname -resp -silent
    # Look for CNAMEs to third-party services with NXDOMAIN / no resource
    for s in $(cat subs.txt); do
      echo "$s -> $(dig +short CNAME $s)"; done

AUTOMATED DETECTION#

    subjack -w subs.txt -t 50 -ssl -c fingerprints.json -v
    nuclei -l subs.txt -t http/takeovers/
    subzy run --targets subs.txt
    can-i-take-over-xyz            # community fingerprint reference (EdOverflow)

COMMON FINGERPRINTS#

  AWS S3         "NoSuchBucket" / "The specified bucket does not exist"
  GitHub Pages   "There isn't a GitHub Pages site here"
  Heroku         "No such app" / herokucdn 404
  Azure          "404 Web Site not found" (*.azurewebsites.net, trafficmanager)
  Shopify        "Sorry, this shop is currently unavailable"
  Fastly         "Fastly error: unknown domain"
  Zendesk        "Help Center Closed"
  Readme.io      "Project doesnt exist"
  Unbounce       "The requested URL was not found"

  NOTE: fingerprints change; always verify manually before claiming a finding.

CONFIRM (SAFE PROOF)#

  - Register/claim the resource on the service (if scope allows) and
    serve a harmless proof file, e.g. /takeover-poc-<yourhandle>.txt.
  - Or document the exact dangling CNAME + the service's "unclaimed"
    response as evidence WITHOUT hosting content.
  - Never serve phishing, malware, or capture user data.

NS / MX / DANGLING DELEGATION#

    dig NS sub.target.com          # delegated to a nameserver you can register?
    dig MX target.com              # dangling mail provider
    # Expired/parked base domains referenced in CNAMEs are also takeover-able.

IMPACT TO REPORT#

  - Cookie theft / session fixation for the parent domain (scope depends
    on cookie flags), phishing on a trusted subdomain, OAuth redirect
    abuse, CSP bypass, SPF/DKIM/email spoofing (for MX/TXT).

PREVENTION (blue side)#

  - Remove DNS records when you decommission a service (fix the order:
    delete the record before releasing the resource).
  - Continuous DNS + takeover monitoring; claim wildcard resources.

  See also: OSINT-TECHNIQUES, SUBFINDER, AMASS, DNSRECON.