Subdomain Squatting
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
Attackers will steal dangling subdomains to deliver malware and perform phishing attacks.
- Prevalence
- Occasional
- Exploitability
- Easy
- Impact
- Devastating
What is subdomain squatting?
Subdomain squatting, also called subdomain takeover, is a domain hijacking attack in which an attacker gains control of a subdomain of your site. It happens when a DNS record, usually a CNAME, still points to a cloud resource that has been deleted. The attacker claims that resource and serves malware or phishing pages under your domain.
What you'll learn
- How a dangling DNS record lets an attacker claim your subdomain
- Why a hijacked subdomain can read cookies set for the parent domain
- How to scan for dangling subdomains and restrict cookie scope
This lesson includes
-
Subdomain Squatting lab
Your company points a subdomain at a blog on medium.com, drops the blog and forgets the DNS entry. See how an attacker scanning for dangling records claims the abandoned name and hosts their own pages under your domain, where they can steal cookies.
-
How to prevent Subdomain Squatting
The prevention guide covers three approaches:
- Scan Periodically for Dangling Subdomains
- Restrict Cookie Access By Subdomain
- Avoid Wildcard Certificates If You Don't Need Them
-
Subdomain Squatting quiz
Two questions. Passing marks the lesson complete.
Sources
Related lessons
Browse all 45 lessons
DNS Poisoning
If upstream DNS caches have been poisoned, attackers may be intercepting traffic before it even gets to you.
Email Spoofing
Email spoofing is the sending of email messages with a forged "from" address.
Cross-Origin Resource Sharing
Overly permissive CORS policies can allow malicious websites to access your APIs and steal user data.
Malvertising
Embedded adverts are a common target for hackers.