Subdomain Takeover
A DNS record that outlived its target is anyone's to claim.
What Is Subdomain Takeover?
Retiring a cloud resource without deleting the DNS record aimed at it leaves a name you own pointing at a target anyone can claim. Whoever claims it serves their content from your genuine subdomain, over HTTPS, with a valid certificate. None of the signals people are trained to spot appear. You'll find a marketing subdomain whose target returns a no-such-bucket error, claim it, host a sign-in page, and phish an employee whose address-bar check finds nothing wrong. You'll delete the dangling record and put DNS removal in the decommissioning checklist.
What You'll Learn in Subdomain Takeover
- A record that outlives its resource points at a target anyone can claim.
- The result is attacker content on the organization's real domain with a valid certificate, so none of the usual lookalike signals appear.
- The cause is a decommissioning process that retires resources without removing DNS.
- Fix the process for new work and scan for dangling records to find the backlog it will not catch.
Subdomain Takeover — Training Steps
-
A name that outlived its target
Bob does not hunt for typos. He hunts for the company's own subdomains still pointing at cloud resources that were switched off but never unhooked from DNS. He checks one of Dunwrell's marketing names.
-
The target is nobody's
The name points at an S3 bucket. Bob asks S3 whether that bucket still exists.
-
Claim the name
Bob creates a bucket with the exact name the dangling record points at. From this moment, Dunwrell's own subdomain serves whatever he puts in it.
-
Upload the trap
Bob uploads a page built to look exactly like Dunwrell's attendee sign-in. He does not need to fake the brand convincingly, because it will be served from the brand's real address.
-
Send the bait
The page is live on the real subdomain. Now Bob needs someone to sign into it. He emails a Dunwrell staff member, Alice, with a routine-looking account-confirmation notice and the link to his page.
-
A message from IT
Alice gets an account-confirmation notice from IT. It looks routine, and the link is to a Dunwrell address, so she opens it.
-
Nothing looks wrong
The page asks Alice to sign in to confirm her account. She does what she was taught: she checks the address bar first.
-
Sign in to confirm
Reassured by the domain, Alice enters her Dunwrell login to confirm her account. It goes straight to Bob's collector.
-
Her password lands
Back on his own machine, Bob tails his collector. Alice's sign-in is right there, in cleartext.
-
Log in as Alice
Bob opens the genuine Dunwrell app and signs in with Alice's stolen credentials. To Dunwrell, this is just Alice logging in - her real email and password, from a browser.
Security Framework Coverage
CWE
- CWE-672 Operation on a Resource after Expiration or Release
MITRE ATT&CK
- T1584.001 Compromise Infrastructure: Domains
CIS Controls
- CIS 12 Network Infrastructure Management
- CIS 2 Inventory and Control of Software Assets
NIST CSF
- PR.AT-02 Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind
- PR.IR Technology Infrastructure Resilience
- ID.AM Asset Management