CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisHard

While performing cloud reconnaissance, a tester finds a CNAME record for dev.clientcorp.com pointing to an Azure App Service subdomain that now returns a 'Web App Not Found' error, indicating the resource was deleted but the DNS record was never removed. What vulnerability does this represent?

  1. ASubdomain takeover
  2. BOpen cloud storage bucket
  3. CServer-side request forgery (SSRF)
  4. DDNS zone transfer misconfiguration
Show answer & explanation

Correct answer: A. Subdomain takeover

This is a classic subdomain takeover scenario: a dangling DNS CNAME points to a deprovisioned cloud resource, allowing an attacker to claim the resource on the cloud provider and take control of the subdomain.

Why the other options are wrong

  • B. Open storage buckets involve misconfigured object storage permissions, not DNS records.
  • C. SSRF involves tricking a server into making unintended requests, unrelated to dangling DNS.
  • D. Zone transfer misconfiguration allows unauthorized AXFR requests, not dangling CNAME issues.

Subdomain Takeover

A vulnerability where a DNS record points to a deprovisioned or unclaimed third-party/cloud resource, allowing an attacker to claim that resource and control the subdomain.

  • Common with CNAMEs pointing to cloud services (Azure, AWS, GitHub Pages)
  • Tools like Sublist3r and dnsrecon help identify dangling records
  • Fix involves removing the stale DNS entry or reclaiming the resource

Memory trick: 'Dangling CNAME Dangles Danger'

More Vulnerability Discovery and Analysis questions