{"id":5178,"date":"2020-11-20T13:06:32","date_gmt":"2020-11-20T07:36:32","guid":{"rendered":"https:\/\/www.varutra.com\/?p=5178"},"modified":"2022-12-02T14:56:47","modified_gmt":"2022-12-02T09:26:47","slug":"subdomain-takeovers-cnames-and-cloud-services","status":"publish","type":"post","link":"https:\/\/www.varutra.com\/varutravrt3\/subdomain-takeovers-cnames-and-cloud-services\/","title":{"rendered":"Subdomain Takeovers &#8211; CNAMEs And Cloud Services"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" width=\"1920\" height=\"1080\" src=\"https:\/\/varutra-1a3b6.kxcdn.com\/wp-content\/uploads\/2020\/11\/Subdomain-takeover-01.png\"  class=\"sh-overlay-item sh-table-cell ls-is-cached lazyloaded\" data-rel=\"lightcase\" title=\"Subdomain takeover - Varutra Consulting\"><\/p>\n<h3><strong>Introduction A Subdomain Takeovers<br \/>\n<\/strong><\/h3>\n<p>A hostile takeover of a subdomain by an attacker is known as a subdomain takeover. This issue mostly arises when organizations are integrating with either third-party hosting services or cloud service providers. The DNS records referring to these service providers remain while they have stopped their services. Subdomain takeovers are considered to be an acute threat to an organization that regularly activates and deactivates resources that depend on cloud computing service providers. It is an emerging threat especially when an organization\u2019s DNS record points are discontinued or non-existent. These DNS records are referred to as dangling DNS or stale DNS. Dangling CNAME records are quite vulnerable to these threats.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Common Scenario leading to subdomain takeovers<\/strong><\/h3>\n<ol>\n<li>The CNAME record is used by domain names like greatapp.contoso.com for a different domain. Example: greatapp.contoso.com CNAME great app.third-party.hosting.<\/li>\n<li>Due to any circumstances, when domain name (great app.third-party.hosting) expires, then it will be available to others for registration by the hosting service providers.<\/li>\n<li>As the CNAME record does not get deleted from the hosting website i.e., costono.com, anyone can easily register for your previous selected domain name (great app.third-party.hosting).<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p>Note that HTTP redirects (301 or 302) could be also be used instead of CNAMEs to redirect from <em>http:\/\/www.battlinjack.buzz<\/em> to <em>http:\/\/aws.battlinjack.buzz.s3-website.ap-south-1.amazonaws.com.<\/em><\/p>\n<p><em> <img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-5187 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2020\/11\/404-not-found.png\" alt=\"\" width=\"628\" height=\"358\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2020\/11\/404-not-found.png 628w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2020\/11\/404-not-found-300x171.png 300w\" sizes=\"(max-width: 628px) 100vw, 628px\" \/><\/em><\/p>\n<p>It is a method that is not used so frequently. It replaces the domain name from the browser\u2019s URL bar while the CNAME record will not change the domain in the URL bar of your browser as DNS resolution takes place in the backend.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>What\u2019s in a CNAME?<\/strong><\/h3>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-5188 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2020\/11\/Cname.png\" alt=\"\" width=\"517\" height=\"151\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2020\/11\/Cname.png 517w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2020\/11\/Cname-300x88.png 300w\" sizes=\"(max-width: 517px) 100vw, 517px\" \/><\/p>\n<p>CNAME or Canonical Name is a category in DNS record that means alternate name to canonical domain name. For example, a CNAME record is used by domain name (greatapp.contoso.com) for a different domain (sub.example.com CNAME great app.third-party.hosting).<\/p>\n<p>Hosting service providers assign a particular subdomain for the organization on the hosting provider\u2019s domain. It is represented as organizationname.hostname.com. It is followed by a CNAME to redirect towards the customer\u2019s domain, i.e.,\u00a0<a href=\"http:\/\/www.organizationname.com\">www.organizationname.com<\/a>.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Looking up the CNAME of a subdomain<\/strong><\/h3>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-5189 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2020\/11\/Looking-up.png\" alt=\"\" width=\"628\" height=\"243\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2020\/11\/Looking-up.png 628w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2020\/11\/Looking-up-300x116.png 300w\" sizes=\"(max-width: 628px) 100vw, 628px\" \/><\/p>\n<p>Various tools and applications are available on internet to look for a CNAME if it is available. You can use nlookup to find out whether a CNAME for a particular subdomain exists or not. The result will indicate that is the hosting provider is in use or not. In this case, you can see that the CNAME record for source domain (aws.battlinjack.buzz) is directed to the resource (aws.battlinjack.buzz.s3-website.ap-south-1.amazonaws.com) which is hosted on the AWS S3 bucket.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Is there a dangling DNS record (CNAME) for the subdomain?<\/strong><\/h3>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-5190 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2020\/11\/Dangling-in-DNS-record.png\" alt=\"\" width=\"628\" height=\"172\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2020\/11\/Dangling-in-DNS-record.png 628w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2020\/11\/Dangling-in-DNS-record-300x82.png 300w\" sizes=\"(max-width: 628px) 100vw, 628px\" \/><\/p>\n<p>In the example here, while browsing aws.battlinjack.buzz (source subdomain), you can see an error message getting displayed by the AWS S3 (cloud service provider). This message means that the resource (bucket) does not exist.<\/p>\n<p>It is a dangling DNS record issue. It means the CNAME record is directed towards the AWS S3 bucket (resource), however, aws.battlinjack.buzz.s3-website.ap-south-1.amazonaws.com (resource) no longer exists. This instance is a scenario for subdomain takeover.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Exploitation of Subdomain takeovers<\/strong><\/h3>\n<p>The exploitation of subdomain takeover is different as the service provider that was earlier present and used to host the current resource (non-existing) that was existing in the earlier case.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Taking over an AWS S3 bucket<\/strong><\/h3>\n<p>Here in AWS S3, the website hosting format for subdomain identifying the unique cloud resource (bucket) is bucket-name.s3-website.region-name.amazonaws.com. The CNAME record aws.battlinjack.buzz<em>\u00a0<\/em>(source subdomain) redirects to aws.battlinjack.buzz.s3-website.ap-south-1.amazonaws.com (resource).<em>\u00a0<\/em>The part before \u201c.<em>s3\u201d<\/em>\u00a0is known as the bucket name. To carry out a successful attack, the hacker only needs to create a bucket with the name aws.battlinjack.buzz. It is done as there is already a CNAME record for this subdomain.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-5191 size-full\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2020\/11\/Bucket.png\" alt=\"Bucket For subdomain takeovers\" width=\"628\" height=\"215\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2020\/11\/Bucket.png 628w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2020\/11\/Bucket-300x103.png 300w\" sizes=\"(max-width: 628px) 100vw, 628px\" \/><\/p>\n<p>This subdomain take-over is complete if the bucket is successfully created.<\/p>\n<p>Note: In case when aws.battlinjack.buzz (bucket name) is already in existence then AWS will show an error and exploitation will not be possible.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Taking over a github pages website<\/strong><\/h3>\n<p>GitHub is mostly used for technical blogs, project documentation, or assisting in webpages for open-source projects as it provides free web hosting services using their GitHub Pages. It will assist the default domain name as well as a custom domain name that is registered in github.io. The subdomain format for the GitHub page for a user is username.github.io.<\/p>\n<p>The appearance of the CNAME record for a source subdomain that is hosted on GitHub.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-5192 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2020\/11\/github.png\" alt=\"\" width=\"378\" height=\"178\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2020\/11\/github.png 378w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2020\/11\/github-300x141.png 300w\" sizes=\"(max-width: 378px) 100vw, 378px\" \/><\/p>\n<p>Verifying the existence of GitHub pages site on github.battlinjack.buzz.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-5193 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2020\/11\/404-22.png\" alt=\"\" width=\"628\" height=\"172\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2020\/11\/404-22.png 628w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2020\/11\/404-22-300x82.png 300w\" sizes=\"(max-width: 628px) 100vw, 628px\" \/><\/p>\n<p>In exploitation, to complete the take-over a hacker needs to insert the custom domain name (github.battlinjack.buzz) into their GitHub pages repository (battlinjack.github.io).<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-5194 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2020\/11\/Source-Github.png\" alt=\"\" width=\"628\" height=\"281\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2020\/11\/Source-Github.png 628w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2020\/11\/Source-Github-300x134.png 300w\" sizes=\"(max-width: 628px) 100vw, 628px\" \/><\/p>\n<p>Note:<\/p>\n<ul>\n<li>In case, github.battlinjack.buzz (custom domain) already exists, you will receive an error message from github, and exploitation will not take place.<\/li>\n<li>Like many cloud service providers, GitHub also uses virtual and verifies the actual subdomain name based on the host header. If there is a case of dangling CNAME record for github.battlinjack.buzz directing to anyhost.github.io, then a subdomain takeover is possible. It is possible as all GitHub pages website subdomains share a common server.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-5195 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2020\/11\/Sub.png\" alt=\"\" width=\"317\" height=\"271\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2020\/11\/Sub.png 317w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2020\/11\/Sub-300x256.png 300w\" sizes=\"(max-width: 317px) 100vw, 317px\" \/><\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Subjack<\/strong><\/h3>\n<p>Browsing a subdomain manually and analyzing its server response is a good indication regarding the possibility of subdomain takeover. However, the subjack tool is very useful to find a potentially vulnerable subdomain from bulk domains. It can simultaneously scan a list of subdomains and identify those who are vulnerable depending upon their fingerprints in the database.<\/p>\n<p>The fingerprints are the error messages associated with the respective hosting service providers when there is a request for a non-existing or deprovisioned resource.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-5196 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2020\/11\/Subjack.png\" alt=\"\" width=\"628\" height=\"174\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2020\/11\/Subjack.png 628w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2020\/11\/Subjack-300x83.png 300w\" sizes=\"(max-width: 628px) 100vw, 628px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><strong>Implications<\/strong><\/p>\n<p>If a hacker uses an authorized domain name, then it will a difficult situation for a normal user to figure out whether the content hosted on the website is controlled by a legitimate user or the hacker. When an attacker runs targeted phishing or mass phishing campaigns, they generally ask the users to log into their subdomain-controlled website so that they can acquire their login credentials. It can be said that the probability of a successful phishing attack can be amplified by taking control over legitimate domains.<\/p>\n<p>There is also a possibility of cookie stealing when a base domain (e.g.contoso.com) of the hijacked subdomain (greatapp.contoso.com) shares cookies across all its subdomains (*.contoso.com). An organization or a brand can lose its credibility due to a subdomain takeover.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Remediation to Vulnerable Subdomain Takeover<\/strong><\/h3>\n<p>Follow the steps to prevent your domain names from becoming vulnerable to subdomain takeover:<\/p>\n<ul>\n<li><strong>Removal of the dangling DNS entry\u00a0<\/strong>\u2014 The simplest way is by removing all the stale records from the DNS zone. This step will resolve the issue for an organization that has affected the source domain name.<\/li>\n<li><strong>Taking control of domain name<\/strong>\u00a0\u2014 In simple words, it means repurchasing the expired domain or registering the resource again to the cloud hosting provider or in the case of a normal internet domain.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h3><strong>Further reading<\/strong><\/h3>\n<p>If you would like to delve deeper into this topic, here are a few resources I recommend:<\/p>\n<ol>\n<li><a href=\"https:\/\/github.com\/EdOverflow\/can-i-take-over-xyz\">https:\/\/github.com\/EdOverflow\/can-i-take-over-xyz<\/a> &#8211; This community driven repository maintains a list of vulnerable services and how-to steps for claiming subdomains with dangling DNS records on these services.<\/li>\n<li><a href=\"https:\/\/0xpatrik.com\/\">https:\/\/0xpatrik.com\/<\/a> &#8211; Super rich info involving subdomain discovery, enumeration, takeover, you name it!<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p>Author,<\/p>\n<p><strong>Akshay Khilari<\/strong><\/p>\n<p>Attack &amp; Pen Test Team<\/p>\n<p>Varutra Consulting Pvt. Ltd.<\/p>","protected":false},"excerpt":{"rendered":"<p>Introduction A Subdomain Takeovers A hostile takeover of a subdomain by an attacker is known as a subdomain takeover. This issue mostly arises when organizations&#8230;<\/p>\n","protected":false},"author":4,"featured_media":5198,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[290],"tags":[306,304,305,308,307,72,303],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 4.6.3 - aioseo.com -->\n\t\t<meta name=\"description\" content=\"A Subdomain takeovers refers to the hostile takeover of a subdomain by an attacker. Learn Common Scenario leading to subdomain takeovers flaw and remediation.\" \/>\n\t\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t\t<link rel=\"canonical\" href=\"https:\/\/www.varutra.com\/varutravrt3\/subdomain-takeovers-cnames-and-cloud-services\/\" \/>\n\t\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 4.6.3\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Varutra Consulting\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Subdomain Takeovers Flaw - CNAMEs And Cloud Services\" \/>\n\t\t<meta property=\"og:description\" content=\"A Subdomain takeovers refers to the hostile takeover of a subdomain by an attacker. Learn Common Scenario leading to subdomain takeovers flaw and remediation.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.varutra.com\/varutravrt3\/subdomain-takeovers-cnames-and-cloud-services\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2020\/11\/Subdomain-takeover-01.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2020\/11\/Subdomain-takeover-01.png\" \/>\n\t\t<meta property=\"og:image:width\" content=\"624\" \/>\n\t\t<meta property=\"og:image:height\" content=\"397\" \/>\n\t\t<meta property=\"article:section\" content=\"Cloud Security\" \/>\n\t\t<meta property=\"article:tag\" content=\"404\" \/>\n\t\t<meta property=\"article:tag\" content=\"cloud services\" \/>\n\t\t<meta property=\"article:tag\" content=\"cname\" \/>\n\t\t<meta property=\"article:tag\" content=\"dns\" \/>\n\t\t<meta property=\"article:tag\" content=\"github\" \/>\n\t\t<meta property=\"article:tag\" content=\"kalp blog\" \/>\n\t\t<meta property=\"article:tag\" content=\"subdomain\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-11-20T07:36:32+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-12-02T09:26:47+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Subdomain Takeovers Flaw - CNAMEs And Cloud Services\" \/>\n\t\t<meta name=\"twitter:description\" content=\"A Subdomain takeovers refers to the hostile takeover of a subdomain by an attacker. Learn Common Scenario leading to subdomain takeovers flaw and remediation.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2020\/11\/Subdomain-takeover-01.png\" \/>\n\t\t<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t\t<meta name=\"twitter:data1\" content=\"kalpblogger\" \/>\n\t\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/subdomain-takeovers-cnames-and-cloud-services\\\/#article\",\"name\":\"Subdomain Takeovers Flaw - CNAMEs And Cloud Services\",\"headline\":\"Subdomain Takeovers &#8211; CNAMEs And Cloud Services\",\"author\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Subdomain-takeover-01.png\",\"width\":624,\"height\":397,\"caption\":\"Subdomain takeover\"},\"datePublished\":\"2020-11-20T13:06:32+05:30\",\"dateModified\":\"2022-12-02T14:56:47+05:30\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/subdomain-takeovers-cnames-and-cloud-services\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/subdomain-takeovers-cnames-and-cloud-services\\\/#webpage\"},\"articleSection\":\"Cloud Security, 404, cloud services, CNAME, DNS, github, kalp blog, subdomain\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/subdomain-takeovers-cnames-and-cloud-services\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"nextItem\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/subdomain-takeovers-cnames-and-cloud-services\\\/#listItem\"},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/subdomain-takeovers-cnames-and-cloud-services\\\/#listItem\",\"position\":2,\"name\":\"Subdomain Takeovers - CNAMEs And Cloud Services\",\"previousItem\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#listItem\"}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\",\"name\":\"Varutra\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/wp-content\\\/uploads\\\/2021\\\/11\\\/Varutra-Found-e1612984024606.jpg\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/subdomain-takeovers-cnames-and-cloud-services\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/subdomain-takeovers-cnames-and-cloud-services\\\/#organizationLogo\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/#author\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/\",\"name\":\"kalpblogger\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/subdomain-takeovers-cnames-and-cloud-services\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/5e96a9b330da7c941c1e39217a2fbe38?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"kalpblogger\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/subdomain-takeovers-cnames-and-cloud-services\\\/#webpage\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/subdomain-takeovers-cnames-and-cloud-services\\\/\",\"name\":\"Subdomain Takeovers Flaw - CNAMEs And Cloud Services\",\"description\":\"A Subdomain takeovers refers to the hostile takeover of a subdomain by an attacker. Learn Common Scenario leading to subdomain takeovers flaw and remediation.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/subdomain-takeovers-cnames-and-cloud-services\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Subdomain-takeover-01.png\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/subdomain-takeovers-cnames-and-cloud-services\\\/#mainImage\",\"width\":624,\"height\":397,\"caption\":\"Subdomain takeover\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/subdomain-takeovers-cnames-and-cloud-services\\\/#mainImage\"},\"datePublished\":\"2020-11-20T13:06:32+05:30\",\"dateModified\":\"2022-12-02T14:56:47+05:30\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#website\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"name\":\"Varutra Consulting\",\"description\":\"Secure your digital world with our Cybersecurity services.\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>Subdomain Takeovers Flaw - CNAMEs And Cloud Services<\/title>\n\n","aioseo_head_json":{"title":"Subdomain Takeovers Flaw - CNAMEs And Cloud Services","description":"A Subdomain takeovers refers to the hostile takeover of a subdomain by an attacker. Learn Common Scenario leading to subdomain takeovers flaw and remediation.","canonical_url":"https:\/\/www.varutra.com\/varutravrt3\/subdomain-takeovers-cnames-and-cloud-services\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"og:locale":"en_US","og:site_name":"Varutra Consulting","og:type":"article","og:title":"Subdomain Takeovers Flaw - CNAMEs And Cloud Services","og:description":"A Subdomain takeovers refers to the hostile takeover of a subdomain by an attacker. Learn Common Scenario leading to subdomain takeovers flaw and remediation.","og:url":"https:\/\/www.varutra.com\/varutravrt3\/subdomain-takeovers-cnames-and-cloud-services\/","og:image":"https:\/\/www.varutra.com\/wp-content\/uploads\/2020\/11\/Subdomain-takeover-01.png","og:image:secure_url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2020\/11\/Subdomain-takeover-01.png","og:image:width":"624","og:image:height":"397","article:section":"Cloud Security","article:tag":["404","cloud services","cname","dns","github","kalp blog","subdomain"],"article:published_time":"2020-11-20T07:36:32+00:00","article:modified_time":"2022-12-02T09:26:47+00:00","twitter:card":"summary_large_image","twitter:title":"Subdomain Takeovers Flaw - CNAMEs And Cloud Services","twitter:description":"A Subdomain takeovers refers to the hostile takeover of a subdomain by an attacker. Learn Common Scenario leading to subdomain takeovers flaw and remediation.","twitter:image":"https:\/\/www.varutra.com\/wp-content\/uploads\/2020\/11\/Subdomain-takeover-01.png","twitter:label1":"Written by","twitter:data1":"kalpblogger","twitter:label2":"Est. reading time","twitter:data2":"6 minutes","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.varutra.com\/varutravrt3\/subdomain-takeovers-cnames-and-cloud-services\/#article","name":"Subdomain Takeovers Flaw - CNAMEs And Cloud Services","headline":"Subdomain Takeovers &#8211; CNAMEs And Cloud Services","author":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/#author"},"publisher":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2020\/11\/Subdomain-takeover-01.png","width":624,"height":397,"caption":"Subdomain takeover"},"datePublished":"2020-11-20T13:06:32+05:30","dateModified":"2022-12-02T14:56:47+05:30","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/subdomain-takeovers-cnames-and-cloud-services\/#webpage"},"isPartOf":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/subdomain-takeovers-cnames-and-cloud-services\/#webpage"},"articleSection":"Cloud Security, 404, cloud services, CNAME, DNS, github, kalp blog, subdomain"},{"@type":"BreadcrumbList","@id":"https:\/\/www.varutra.com\/varutravrt3\/subdomain-takeovers-cnames-and-cloud-services\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/#listItem","position":1,"name":"Home","item":"https:\/\/www.varutra.com\/varutravrt3\/","nextItem":"https:\/\/www.varutra.com\/varutravrt3\/subdomain-takeovers-cnames-and-cloud-services\/#listItem"},{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/subdomain-takeovers-cnames-and-cloud-services\/#listItem","position":2,"name":"Subdomain Takeovers - CNAMEs And Cloud Services","previousItem":"https:\/\/www.varutra.com\/varutravrt3\/#listItem"}]},{"@type":"Organization","@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization","name":"Varutra","url":"https:\/\/www.varutra.com\/varutravrt3\/","logo":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/11\/Varutra-Found-e1612984024606.jpg","@id":"https:\/\/www.varutra.com\/varutravrt3\/subdomain-takeovers-cnames-and-cloud-services\/#organizationLogo"},"image":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/subdomain-takeovers-cnames-and-cloud-services\/#organizationLogo"}},{"@type":"Person","@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/#author","url":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/","name":"kalpblogger","image":{"@type":"ImageObject","@id":"https:\/\/www.varutra.com\/varutravrt3\/subdomain-takeovers-cnames-and-cloud-services\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/5e96a9b330da7c941c1e39217a2fbe38?s=96&d=mm&r=g","width":96,"height":96,"caption":"kalpblogger"}},{"@type":"WebPage","@id":"https:\/\/www.varutra.com\/varutravrt3\/subdomain-takeovers-cnames-and-cloud-services\/#webpage","url":"https:\/\/www.varutra.com\/varutravrt3\/subdomain-takeovers-cnames-and-cloud-services\/","name":"Subdomain Takeovers Flaw - CNAMEs And Cloud Services","description":"A Subdomain takeovers refers to the hostile takeover of a subdomain by an attacker. Learn Common Scenario leading to subdomain takeovers flaw and remediation.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#website"},"breadcrumb":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/subdomain-takeovers-cnames-and-cloud-services\/#breadcrumblist"},"author":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/#author"},"creator":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2020\/11\/Subdomain-takeover-01.png","@id":"https:\/\/www.varutra.com\/varutravrt3\/subdomain-takeovers-cnames-and-cloud-services\/#mainImage","width":624,"height":397,"caption":"Subdomain takeover"},"primaryImageOfPage":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/subdomain-takeovers-cnames-and-cloud-services\/#mainImage"},"datePublished":"2020-11-20T13:06:32+05:30","dateModified":"2022-12-02T14:56:47+05:30"},{"@type":"WebSite","@id":"https:\/\/www.varutra.com\/varutravrt3\/#website","url":"https:\/\/www.varutra.com\/varutravrt3\/","name":"Varutra Consulting","description":"Secure your digital world with our Cybersecurity services.","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization"}}]}},"aioseo_meta_data":{"post_id":"5178","title":"Subdomain Takeovers Flaw - CNAMEs And Cloud Services","description":"A Subdomain takeovers refers to the hostile takeover of a subdomain by an attacker. Learn Common Scenario leading to subdomain takeovers flaw and remediation.","keywords":[],"keyphrases":"{\"focus\":{\"keyphrase\":\"Subdomain Takeovers\",\"analysis\":{\"keyphraseInTitle\":{\"title\":\"Focus keyphrase in SEO title\",\"description\":\"Focus keyphrase found in SEO title.\",\"score\":9,\"maxScore\":9,\"error\":0},\"keyphraseInDescription\":{\"title\":\"Focus keyphrase in meta description\",\"description\":\"Focus keyphrase found in meta description.\",\"score\":9,\"maxScore\":9,\"error\":0},\"keyphraseLength\":{\"title\":\"Focus keyphrase length\",\"description\":\"Good job!\",\"score\":9,\"maxScore\":9,\"error\":0,\"length\":2},\"keyphraseInURL\":{\"title\":\"Focus keyphrase in URL\",\"description\":\"Focus keyphrase used in the URL.\",\"score\":5,\"maxScore\":5,\"error\":0},\"keyphraseInIntroduction\":{\"title\":\"Focus keyphrase in introduction\",\"description\":\"Your Focus keyphrase does not appear in the first paragraph. Make sure the topic is clear immediately.\",\"score\":3,\"maxScore\":9,\"error\":1},\"keyphraseInSubHeadings\":{\"title\":\"Focus keyphrase in Subheadings\",\"description\":\"Use more focus keyphrases in your H2 and H3 subheadings!\",\"score\":3,\"maxScore\":9,\"error\":1},\"keyphraseInImageAlt\":{\"title\":\"Focus keyphrase in image alt attributes\",\"description\":\"Focus keyphrase found in image alt attribute(s).\",\"score\":9,\"maxScore\":9,\"error\":0}},\"score\":80},\"additional\":[{\"keyphrase\":\"Subdomain\",\"score\":83,\"analysis\":{\"keyphraseInDescription\":{\"title\":\"Keyphrase in meta description\",\"description\":\"Keyphrase found in meta description.\",\"score\":9,\"maxScore\":9,\"error\":0},\"keyphraseLength\":{\"title\":\"Keyphrase length\",\"description\":\"Good job!\",\"score\":9,\"maxScore\":9,\"error\":0,\"length\":1},\"keyphraseInIntroduction\":{\"title\":\"Keyphrase in introduction\",\"description\":\"Your Keyphrase does not appear in the first paragraph. Make sure the topic is clear immediately.\",\"score\":3,\"maxScore\":9,\"error\":1},\"keyphraseInImageAlt\":{\"title\":\"Keyphrase in image alt attributes\",\"description\":\"Keyphrase found in image alt attribute(s).\",\"score\":9,\"maxScore\":9,\"error\":0}}}]}","primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"featured","og_image_url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2020\/11\/Subdomain-takeover-01.png","og_image_width":"624","og_image_height":"397","og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":"Cloud Security","og_article_tags":[],"twitter_use_og":true,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":"{\"article\":{\"articleType\":\"BlogPosting\"},\"course\":{\"name\":\"\",\"description\":\"\",\"provider\":\"\"},\"faq\":{\"pages\":[]},\"product\":{\"reviews\":[]},\"recipe\":{\"ingredients\":[],\"instructions\":[],\"keywords\":[]},\"software\":{\"reviews\":[],\"operatingSystems\":[]},\"webPage\":{\"webPageType\":\"WebPage\"}}","pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"limit_modified_date":false,"open_ai":null,"created":"2021-10-27 15:12:31","updated":"2022-12-02 09:27:35"},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.varutra.com\/varutravrt3\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.varutra.com\/varutravrt3\/category\/cloud-security\/\" title=\"Cloud Security\">Cloud Security<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tSubdomain Takeovers \u2013 CNAMEs And Cloud Services\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.varutra.com\/varutravrt3"},{"label":"Cloud Security","link":"https:\/\/www.varutra.com\/varutravrt3\/category\/cloud-security\/"},{"label":"Subdomain Takeovers &#8211; CNAMEs And Cloud Services","link":"https:\/\/www.varutra.com\/varutravrt3\/subdomain-takeovers-cnames-and-cloud-services\/"}],"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/5178"}],"collection":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/comments?post=5178"}],"version-history":[{"count":5,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/5178\/revisions"}],"predecessor-version":[{"id":20333,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/5178\/revisions\/20333"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/media\/5198"}],"wp:attachment":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/media?parent=5178"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/categories?post=5178"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/tags?post=5178"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}