Understanding Subdomain takeover
What it is
A subdomain takeover happens when a DNS record still points at a service the organisation no longer owns — a deprovisioned bucket, a cancelled app, a removed CDN configuration. Whoever registers that service next controls a hostname the organisation still vouches for.
How you approach it
- Enumerate the subdomains and check where each one's CNAME points. One resolves to a platform that returns a 'no such site' style error.
- That error names the platform. The record is dangling because the resource behind it was deleted but the DNS entry was not.
- Registering that resource on the platform would bind the hostname to you — the flag is issued when the takeover is proven.
How it gets fixed
A CNAME still pointed at a third-party service that had been deleted, leaving the name claimable by anyone who registered it there. Doing so would let you serve trusted content from the organisation's own domain. The fix is to remove DNS records the moment the resource they point at is decommissioned.
Practise it
Every lab in the Subdomain takeover category drills exactly this. Start at Apprentice and work up.