Skip to content

H3-2021-0002

Subdomain Takeover

Category SECURITY_MISCONFIGURATION
Base Score 7.5

Description

The DNS record for a subdomain has a CNAME record that points to another subdomain that is not in use. Attackers may be able to claim the subdomain that is the CNAME for this subdomain.

Impact

By taking over a legitimate looking company domain, attackers can trick users through phishing campaigns, attempt to steal user cookies and passwords, deface the company web site and damage the company brand.

References