Subdomain Takeover

Advanced subdomain takeover testing methodology for bug bounty and application security work. Use when testing or reviewing dangling DNS records, unclaimed cloud/CDN/storage/app-service resources, CloudFront/Heroku/GitHub Pages/Azure/S3/Fastly-style takeovers, authentication bypass through trusted subdomains, cookie scope abuse, OAuth redirect allowlist abuse, staging subdomain takeover, and chains where a controlled subdomain can steal tokens, host trusted content, bypass auth, or affect users.

yafet-dev Updated

File contents

yafet-dev/bugbounty-codex-skills/tree/main/bug-type-skills/subdomain-takeover commit 4dae1f6eab

Frequently asked questions

npx skillmds@latest add yafet-dev/subdomain-takeover