What problem does it solve?
Subdomain takeover testing finds and verifies dangling DNS records and unclaimed cloud resources that can allow attackers to serve content from trusted subdomains, enabling phishing, cookie/CORS pivot, OAuth redirect abuse, and CDN cache poisoning.
Core Features & Use Cases
- Comprehensive Reconnaissance: Aggregate subdomain inventories, CT logs, passive DNS, and infrastructure outputs to find candidate targets.
- Record & Provider Fingerprinting: Resolve A/AAAA/CNAME/NS/MX/TXT chains, collapse CNAME graphs, and fingerprint HTTP/TLS responses for provider-specific "unclaimed" messages.
- Safe Claim Validation: Guidance for authorized proof-of-control attempts, evidence collection (HTTP/TLS proof, unique payloads, optional DV certs), and post-claim validation.
- Use Case: During a security assessment, enumerate a target's subdomains, identify dangling CNAMEs to cloud providers, and validate exploitability with minimal, authorized proofs.
Quick Start
Scan the target domain sub.example.com to enumerate dangling DNS records, fingerprint provider responses, and perform an authorized claim validation to gather proof of takeover.