A dangling record points a name at an AWS resource that no longer exists: an S3 website bucket that was deleted, a released Elastic IP, a torn-down CloudFront distribution, or a removed ELB. Because the name still resolves to the provider, anyone who can recreate a resource with the same identifier captures every request to that subdomain, which yields a trusted-origin foothold for phishing, cookie theft, and certificate issuance.
Finding dangling records#
# records whose alias/CNAME targets an AWS resource
aws route53 list-resource-record-sets --hosted-zone-id <zone-id> \
--query "ResourceRecordSets[?Type=='CNAME' || AliasTarget].[Name,Type,ResourceRecords[0].Value,AliasTarget.DNSName]"
# then resolve each target and flag NXDOMAIN / NoSuchBucket / unclaimed endpoints
Claiming the backing resource#
- S3 website origin: the target
<name>.s3-website-<region>.amazonaws.comreturningNoSuchBucketmeans you create a bucket with that exact name in that region and serve your content. - CloudFront: a CNAME to a removed distribution's
*.cloudfront.netcan be claimed by registering the alternate domain name on a distribution you own. - Elastic IP / ELB: an A record to a released EIP is captured by reallocating EIPs until you draw the same address; a dead ELB DNS name is reclaimed by creating a load balancer that is issued it.
Exploitation notes#
- A captured subdomain inherits the parent domain's trust: session cookies scoped to
.example.com, SSO redirect allow-lists, and user expectation all transfer. - Control of the name also passes ACME HTTP-01 and DNS-01 challenges, so you can mint a valid certificate for the subdomain.
- Cross-reference S3 enumeration for discovering the bucket-origin case and Route53 for the record inventory.
Tools#
- nuclei (
takeoverstemplates) and subjack / tko-subs: detect claimable fingerprints at scale. - AWS CLI: recreate the bucket, distribution alias, or EIP to claim the target.