vulns.co
/
GKData.io MCP

Back to Playbooks

Subdomain Takeover

Find dangling DNS records pointing to de-provisioned cloud services you can re-claim.

Tags: takeover, dns, recon

Level: beginner

Method

  1. Gather subdomains & CNAMEs

    Collect subdomains and resolve their CNAME chains - takeovers live in dangling CNAMEs.

    subfinder -d target.com -all -silent | dnsx -cname -resp -silent -o cnames.txt

    Tools: subfinder, dnsx

  2. Detect fingerprints

    Scan for known takeover signatures (S3, GitHub Pages, Heroku, Azure, etc.) with nuclei's takeover templates.

    httpx -l cnames.txt -silent | nuclei -t http/takeovers/ -o takeover.txt

    Tools: nuclei, httpx

  3. Verify manually

    Confirm the service is unclaimed and the error page matches the fingerprint before claiming. Never disrupt a live service.

    curl -s https://sub.target.com | grep -i 'NoSuchBucket\|There isn.t a GitHub Pages site here'

Field notes

  • A CNAME to a cloud provider + a service-specific error page = candidate.
  • Report responsibly - claim only enough to prove impact (a benign PoC file).

References