Subdomain Takeover

Hanno Böck @hanno


Why do I control a subdomain of

Subdomain Takeover

The Cloud

Let's start a project in the cloud

  • Create webpage at cloud service (Azure, AWS, GCP).
  • Redirect subdomain of your company domain to cloud service (e.g. CNAME).

Let's shutdown a project in the cloud

  • Cancel webpage at cloud service (it costs money!)
  • Forget about DNS entry (it's usually free)
  • Hacker re-registers webpage at cloud service.
  • Fun!


Don't have stale DNS entries laying around