Subs or Top level Domain
for take-overs is to query a list of domains and check for any that are either:
1. attached to a third party domain or destination via the use of a cname record
2.return a 404 not found error.
example : domain that resolved to a CloudFront domain which gave the following error: "Error the request could not be satisfied, generated by CloudFront (CloudFront)"Technical Detail
Heroku, Github, Bitbucket, Squarespace, Shopify, Desk, Teamwork, Unbounce, Helpjuice, HelpScout, Pingdom, Tictail, Campaign Monitor, CargoCollective, [StatusPage.io](http://statuspage.io/) and Tumblr.Impact
1. A Domain Owner points their * (wildcard) DNS-entry to e.g. Heroku.
2. They forget to add the wildcard-entry to their Heroku-app.
3. Attacker can now claim any subdomain they want from the Domain Owner.
4. A Domain Owner will be unaware of the subdomain being exploited.Exploit
Remediation
Reference
POC
Analysis
Author:
Last updated
Was this helpful?