CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisHard
While performing cloud reconnaissance, a tester finds a CNAME record for dev.clientcorp.com pointing to an Azure App Service subdomain that now returns a 'Web App Not Found' error, indicating the resource was deleted but the DNS record was never removed. What vulnerability does this represent?
- ASubdomain takeover
- BOpen cloud storage bucket
- CServer-side request forgery (SSRF)
- DDNS zone transfer misconfiguration
Show answer & explanationAnswer & explanation
Correct answer: A. Subdomain takeover
This is a classic subdomain takeover scenario: a dangling DNS CNAME points to a deprovisioned cloud resource, allowing an attacker to claim the resource on the cloud provider and take control of the subdomain.
Why the other options are wrong
- B. Open storage buckets involve misconfigured object storage permissions, not DNS records.
- C. SSRF involves tricking a server into making unintended requests, unrelated to dangling DNS.
- D. Zone transfer misconfiguration allows unauthorized AXFR requests, not dangling CNAME issues.
Subdomain Takeover
A vulnerability where a DNS record points to a deprovisioned or unclaimed third-party/cloud resource, allowing an attacker to claim that resource and control the subdomain.
- Common with CNAMEs pointing to cloud services (Azure, AWS, GitHub Pages)
- Tools like Sublist3r and dnsrecon help identify dangling records
- Fix involves removing the stale DNS entry or reclaiming the resource
Memory trick: 'Dangling CNAME Dangles Danger'