Dangling-DNS takeover

A dangling record points a name at an AWS resource that no longer exists: an S3 website bucket that was deleted, a released Elastic IP, a torn-down CloudFront distribution, or a removed ELB. Because the name still resolves to the provider, anyone who can recreate a resource with the same identifier captures every request to that subdomain, which yields a trusted-origin foothold for phishing, cookie theft, and certificate issuance.

Finding dangling records#

bash
# records whose alias/CNAME targets an AWS resource
aws route53 list-resource-record-sets --hosted-zone-id <zone-id> \
  --query "ResourceRecordSets[?Type=='CNAME' || AliasTarget].[Name,Type,ResourceRecords[0].Value,AliasTarget.DNSName]"
# then resolve each target and flag NXDOMAIN / NoSuchBucket / unclaimed endpoints

Claiming the backing resource#

  • S3 website origin: the target <name>.s3-website-<region>.amazonaws.com returning NoSuchBucket means you create a bucket with that exact name in that region and serve your content.
  • CloudFront: a CNAME to a removed distribution's *.cloudfront.net can be claimed by registering the alternate domain name on a distribution you own.
  • Elastic IP / ELB: an A record to a released EIP is captured by reallocating EIPs until you draw the same address; a dead ELB DNS name is reclaimed by creating a load balancer that is issued it.

Exploitation notes#

  • A captured subdomain inherits the parent domain's trust: session cookies scoped to .example.com, SSO redirect allow-lists, and user expectation all transfer.
  • Control of the name also passes ACME HTTP-01 and DNS-01 challenges, so you can mint a valid certificate for the subdomain.
  • Cross-reference S3 enumeration for discovering the bucket-origin case and Route53 for the record inventory.

Tools#

  • nuclei (takeovers templates) and subjack / tko-subs: detect claimable fingerprints at scale.
  • AWS CLI: recreate the bucket, distribution alias, or EIP to claim the target.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more