Subdomain Takeover

Subdomain Takeover

A DNS record left pointing at a deprovisioned resource lets anyone claim the target and serve content from your real domain, with a valid certificate and no typo to notice. Take it over, then remove the record and fix the retirement process.

What Is Subdomain Takeover?

Decommissioning a resource without removing the DNS record that points at it leaves a name you still own aimed at a target anyone can claim. The result is attacker content served from your real domain, with a valid certificate and no typo for anyone to notice. This exercise covers the takeover and the hygiene that prevents it.

What You'll Learn in Subdomain Takeover

Subdomain Takeover — Training Steps

  1. A name that outlived its target

    Bob does not hunt for typos. He hunts for the company's own subdomains still pointing at cloud resources that were switched off but never unhooked from DNS. He checks one of Dunwrell's marketing names.

  2. The target is nobody's

    The name points at an S3 bucket. Bob asks S3 whether that bucket still exists.

  3. Claim the name

    Bob creates a bucket with the exact name the dangling record points at. From this moment, Dunwrell's own subdomain serves whatever he puts in it.

  4. Upload the trap

    Bob uploads a page built to look exactly like Dunwrell's attendee sign-in. He does not need to fake the brand convincingly, because it will be served from the brand's real address.

  5. Send the bait

    The page is live on the real subdomain. Now Bob needs someone to sign into it. He emails a Dunwrell staff member, Alice, with a routine-looking account-confirmation notice and the link to his page.

  6. A message from IT

    Alice gets an account-confirmation notice from IT. It looks routine, and the link is to a Dunwrell address, so she opens it.

  7. Nothing looks wrong

    The page asks Alice to sign in to confirm her account. She does what she was taught: she checks the address bar first.

  8. Sign in to confirm

    Reassured by the domain, Alice enters her Dunwrell login to confirm her account. It goes straight to Bob's collector.

  9. Her password lands

    Back on his own machine, Bob tails his collector. Alice's sign-in is right there, in cleartext.

  10. Log in as Alice

    Bob opens the genuine Dunwrell app and signs in with Alice's stolen credentials. To Dunwrell, this is just Alice logging in - her real email and password, from a browser.