15–25 min Updated

Subdomain Squatting

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

Attackers will steal dangling subdomains to deliver malware and perform phishing attacks.

Prevalence
Occasional
Exploitability
Easy
Impact
Devastating

What is subdomain squatting?

Subdomain squatting, also called subdomain takeover, is a domain hijacking attack in which an attacker gains control of a subdomain of your site. It happens when a DNS record, usually a CNAME, still points to a cloud resource that has been deleted. The attacker claims that resource and serves malware or phishing pages under your domain.

What you'll learn

  • How a dangling DNS record lets an attacker claim your subdomain
  • Why a hijacked subdomain can read cookies set for the parent domain
  • How to scan for dangling subdomains and restrict cookie scope
  • Subdomain Squatting lab

    Your company points a subdomain at a blog on medium.com, drops the blog and forgets the DNS entry. See how an attacker scanning for dangling records claims the abandoned name and hosts their own pages under your domain, where they can steal cookies.

  • How to prevent Subdomain Squatting

    The prevention guide covers three approaches:

    • Scan Periodically for Dangling Subdomains
    • Restrict Cookie Access By Subdomain
    • Avoid Wildcard Certificates If You Don't Need Them
  • Subdomain Squatting quiz

    Two questions. Passing marks the lesson complete.

Sources

  • DNS Poisoning

    If upstream DNS caches have been poisoned, attackers may be intercepting traffic before it even gets to you.

  • Email Spoofing

    Email spoofing is the sending of email messages with a forged "from" address.

  • Cross-Origin Resource Sharing

    Overly permissive CORS policies can allow malicious websites to access your APIs and steal user data.

  • Malvertising

    Embedded adverts are a common target for hackers.