← All concepts
Subdomain takeover

Understanding Subdomain takeover

What it is

A subdomain takeover happens when a DNS record still points at a service the organisation no longer owns — a deprovisioned bucket, a cancelled app, a removed CDN configuration. Whoever registers that service next controls a hostname the organisation still vouches for.

How you approach it

  1. Enumerate the subdomains and check where each one's CNAME points. One resolves to a platform that returns a 'no such site' style error.
  2. That error names the platform. The record is dangling because the resource behind it was deleted but the DNS entry was not.
  3. Registering that resource on the platform would bind the hostname to you — the flag is issued when the takeover is proven.

How it gets fixed

A CNAME still pointed at a third-party service that had been deleted, leaving the name claimable by anyone who registered it there. Doing so would let you serve trusted content from the organisation's own domain. The fix is to remove DNS records the moment the resource they point at is decommissioned.

Practise it

Every lab in the Subdomain takeover category drills exactly this. Start at Apprentice and work up.

Practise it

PractitionerSubdomain takeover

A CNAME pointing at a deleted bucket

Claim a dangling DNS record that points at an unclaimed host.

25 pts · 45 minStart →
PractitionerSubdomain takeover

The pages site that was never published

Claim a dangling DNS record that points at an unclaimed host.

25 pts · 45 minStart →
ExpertSubdomain takeover

The cancelled SaaS that left a dangling record

Claim a dangling DNS record that points at an unclaimed host.

50 pts · 90 minStart →
ExpertSubdomain takeover

An expired CDN configuration still referenced

Claim a dangling DNS record that points at an unclaimed host.

50 pts · 90 minStart →
MasterSubdomain takeover

Chaining a takeover into cookie theft

Claim a dangling DNS record that points at an unclaimed host.

100 pts · 180 minStart →