Skip to content
REDMAW

Applications

Subdomain Takeover

A DNS record still points at a third-party resource nobody controls any more, letting someone else claim it and serve content from a trusted subdomain.

RedMaw

Definition

A subdomain takeover becomes possible when a DNS record references a third-party service resource that has been released, while the record itself remains published.

How the gap opens

  1. 01A subdomain is pointed at a hosting, CDN or SaaS resource
  2. 02The project ends, or the resource is deleted or renamed
  3. 03The DNS record is left in place
  4. 04Another party registers the released resource name on that provider
  5. 05Content served from the trusted subdomain is now under their control

Why it matters more than it looks

The subdomain still carries organizational trust. Depending on configuration, that can affect cookie scope, content-security and authentication assumptions, and it makes phishing considerably more convincing because the domain is genuine.

This is fundamentally an inventory problem. Records outlive the projects that created them, and nobody owns the cleanup.

Where it leads
  1. DNS Record
  2. Unclaimed Service
  3. Attacker-Controlled Resource
  4. Trusted Subdomain

Each hop validated by successful exploitation

Tags

  • dns
  • attack surface
  • brand abuse

Validation

How RedMaw validates this attack

Validation runs only inside authorized scope, with agreed exploitation limits.

  1. 01Enumerate DNS records across authorized zones
  2. 02Identify records pointing at third-party resources
  3. 03Establish whether the backing resource is unclaimed
  4. 04Report the exposure without claiming resources outside authorization

Stop assuming you are secure. Prove it.

Continuously test what an attacker can actually reach across your applications, SaaS identities, internal infrastructure and AI systems.