Webupdated Oct 1, 2026

Domain / Subdomain Takeover

Finding dangling DNS records pointing at unclaimed services like S3, GitHub Pages, and Heroku, then proving takeover safely.

toolbox:digsubfinder

A subdomain takeover runbook for authorized pentests / bug bounty on in-scope targets only. Goal: find DNS records pointing at unclaimed third-party resources and prove the fingerprint without claiming anything you do not own.

1. Collect candidate hostnames

subfinder -d target.com -silent -o subs.txt
assetfinder --subs-only target.com >> subs.txt
sort -u subs.txt -o subs.txt
wc -l subs.txt

2. Resolve and capture CNAME chains

A dangling CNAME to a third-party service is the core indicator.

# Show the full CNAME chain and final A record
while read -r host; do
  echo "== $host"
  dig +short CNAME "$host"
  dig +short A "$host"
done < subs.txt | tee dns_dump.txt

# Faster bulk variant
dnsx -l subs.txt -cname -a -resp -silent -o dnsx.txt

3. Fingerprint unclaimed services

Match the CNAME target against known takeover fingerprints (S3, GitHub Pages, Heroku, Azure, Fastly, etc.).

# Common "unclaimed" response markers
while read -r host; do
  body=$(curl -s -m 8 "http://$host/")
  code=$(curl -s -o /dev/null -w "%{http_code}" -m 8 "http://$host/")
  case "$body" in
    *"NoSuchBucket"*|*"There isn't a GitHub Pages site here"*|*"No such app"*|*"404 Web Site not found"*)
      echo "CANDIDATE $code $host" ;;
  esac
done < subs.txt

4. Automate with subzy and nuclei

subzy run --targets subs.txt --hide_fails

# Nuclei takeover templates
nuclei -l subs.txt -t http/takeovers/ -silent -o takeovers.txt
cat takeovers.txt

5. Prove safely

Do not register the resource unless you own it or have written authorization. A safe proof is the unclaimed fingerprint plus a banner that shows the service is unconfigured.

# Capture the exact unclaimed response as evidence
curl -s -D - "http://candidate.target.com/" -o evidence.html
curl -s "http://candidate.target.com/" | grep -ioE "NoSuchBucket|GitHub Pages|No such app|404 Web Site not found"

If the program explicitly authorizes claiming the dangling resource, use a throwaway account and an inert page.

6. Verify NS and MX dangling records too

dig +short NS dangling.target.com
dig +short MX target.com

An unclaimed NS record can allow full zone delegation, which is higher impact than a CNAME.

Full pipeline

# 1. Collect subdomains
subfinder -d target.com -silent -o subs.txt
assetfinder --subs-only target.com >> subs.txt
sort -u subs.txt -o subs.txt

# 2. Resolve CNAMEs
dnsx -l subs.txt -cname -a -resp -silent -o dnsx.txt

# 3. Fingerprint unclaimed services
while read -r host; do
  body=$(curl -s -m 8 "http://$host/")
  case "$body" in
    *"NoSuchBucket"*|*"There isn't a GitHub Pages site here"*|*"No such app"*|*"404 Web Site not found"*)
      echo "CANDIDATE $host" ;;
  esac
done < subs.txt | tee candidates.txt

# 4. Automated confirmation
subzy run --targets subs.txt --hide_fails
nuclei -l subs.txt -t http/takeovers/ -silent -o takeovers.txt

# 5. Evidence
curl -s -D - "http://candidate.target.com/" -o evidence.html

Ethics & legality

  • Only test hostnames within the authorized scope; do not scan unrelated domains.
  • Never claim a dangling resource unless the program explicitly allows it; use a screenshot of the unclaimed fingerprint otherwise.
  • If you do claim, use a throwaway account, an inert page, and release it promptly.
  • Save DNS traces, HTTP responses, and tool output as evidence.