What problem does it solve?
This Skill addresses the risk of attackers exploiting dangling CNAME records that point to unclaimed third-party cloud services to take over a target's subdomains, which can enable phishing, cookie theft, and full origin impersonation of the target's web properties.
Core Features & Use Cases
- CNAME Record Filtering: Extracts and filters CNAME records for common user-registrable cloud services including Heroku, S3, Azure, GitHub Pages, and Shopify from subdomain enumeration results.
- Automated Vulnerability Scanning: Integrates with standard security tools like subzy, subjack, and nuclei to rapidly scan large subdomain lists for takeover indicators.
- Manual Verification & Fingerprinting: Provides service-specific error page checks and a reference table of 16 common cloud services to confirm claimable resources and reduce false positives.
- Use Case: During an authorized penetration test, after generating a list of alive subdomains for a target, use this Skill to quickly identify any subdomains at risk of takeover by unclaimed cloud resources.
Quick Start
Use the subdomain-takeover-hunt skill to scan your list of alive subdomains and identify any that are vulnerable to takeover via unclaimed cloud service CNAMEs.