Subdomain Takeover
Find dangling DNS records pointing to de-provisioned cloud services you can re-claim.
Tags: takeover, dns, recon
Level: beginner
Method
Gather subdomains & CNAMEs
Collect subdomains and resolve their CNAME chains - takeovers live in dangling CNAMEs.
subfinder -d target.com -all -silent | dnsx -cname -resp -silent -o cnames.txtDetect fingerprints
Scan for known takeover signatures (S3, GitHub Pages, Heroku, Azure, etc.) with nuclei's takeover templates.
httpx -l cnames.txt -silent | nuclei -t http/takeovers/ -o takeover.txtVerify manually
Confirm the service is unclaimed and the error page matches the fingerprint before claiming. Never disrupt a live service.
curl -s https://sub.target.com | grep -i 'NoSuchBucket\|There isn.t a GitHub Pages site here'
Field notes
- A CNAME to a cloud provider + a service-specific error page = candidate.
- Report responsibly - claim only enough to prove impact (a benign PoC file).