#subdomaintakeover — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #subdomaintakeover, aggregated by home.social.
-
@ScottHelme from https://scotthelme.co.uk/open-sourcing-passkeys-php-a-security-focused-webauthn-library-for-php/:
"It now requires an exact match or a true subdomain."
That is probably insufficient. Please read https://github.com/w3ctag/design-reviews/issues/97#issuecomment-175766580 by Dirk Balfanz (Google, screenshot of part of the entry below).
Google doesn't want potentially malicious (e.g. https://sites.google.com) or "forgotten" subdomains (https://developer.mozilla.org/en-US/docs/Web/Security/Attacks/Subdomain_takeover) to be able to handle passkeys.
As shown in Google's example, it's best to explicitly whitelist ALL subdomains thay may interact with passkeys to prevent (future) oversight.
PS this is exactly what I meant with "and in specific cases using subdomains and faulty server webauthn implementations" in https://todon.nl/@ErikvanStraten/116595157772945666.
Edited to add: many commercial websites use subdomains where third parties have access to (such as track.example.com), for example used in mass mailings. You don't want a gone rogue third party to be able to handle WebAuthn registrations and logins on your subdomain used by them.
According to the RELATIONS tab in https://www.virustotal.com/gui/domain/report-uri.com your domain has (at least) 3.2K subdomains. Do you trust each of them?
#Passkeys #SubDomainTakeOver #Subdomains #SubDomainHijacking
-
@ScottHelme from https://scotthelme.co.uk/open-sourcing-passkeys-php-a-security-focused-webauthn-library-for-php/:
"It now requires an exact match or a true subdomain."
That is probably insufficient. Please read https://github.com/w3ctag/design-reviews/issues/97#issuecomment-175766580 by Dirk Balfanz (Google, screenshot of part of the entry below).
Google doesn't want potentially malicious (e.g. https://sites.google.com) or "forgotten" subdomains (https://developer.mozilla.org/en-US/docs/Web/Security/Attacks/Subdomain_takeover) to be able to handle passkeys.
As shown in Google's example, it's best to explicitly whitelist ALL subdomains thay may interact with passkeys to prevent (future) oversight.
PS this is exactly what I meant with "and in specific cases using subdomains and faulty server webauthn implementations" in https://todon.nl/@ErikvanStraten/116595157772945666.
Edited to add: many commercial websites use subdomains where third parties have access to (such as track.example.com), for example used in mass mailings. You don't want a gone rogue third party to be able to handle WebAuthn registrations and logins on your subdomain used by them.
According to the RELATIONS tab in https://www.virustotal.com/gui/domain/report-uri.com your domain has (at least) 3.2K subdomains. Do you trust each of them?
#Passkeys #SubDomainTakeOver #Subdomains #SubDomainHijacking
-
@ScottHelme from https://scotthelme.co.uk/open-sourcing-passkeys-php-a-security-focused-webauthn-library-for-php/:
"It now requires an exact match or a true subdomain."
That is probably insufficient. Please read https://github.com/w3ctag/design-reviews/issues/97#issuecomment-175766580 by Dirk Balfanz (Google, screenshot of part of the entry below).
Google doesn't want potentially malicious (e.g. https://sites.google.com) or "forgotten" subdomains (https://developer.mozilla.org/en-US/docs/Web/Security/Attacks/Subdomain_takeover) to be able to handle passkeys.
As shown in Google's example, it's best to explicitly whitelist ALL subdomains thay may interact with passkeys to prevent (future) oversight.
PS this is exactly what I meant with "and in specific cases using subdomains and faulty server webauthn implementations" in https://todon.nl/@ErikvanStraten/116595157772945666.
Edited to add: many commercial websites use subdomains where third parties have access to (such as track.example.com), for example used in mass mailings. You don't want a gone rogue third party to be able to handle WebAuthn registrations and logins on your subdomain used by them.
According to the RELATIONS tab in https://www.virustotal.com/gui/domain/report-uri.com your domain has (at least) 3.2K subdomains. Do you trust each of them?
#Passkeys #SubDomainTakeOver #Subdomains #SubDomainHijacking
-
@ScottHelme from https://scotthelme.co.uk/open-sourcing-passkeys-php-a-security-focused-webauthn-library-for-php/:
"It now requires an exact match or a true subdomain."
That is probably insufficient. Please read https://github.com/w3ctag/design-reviews/issues/97#issuecomment-175766580 by Dirk Balfanz (Google, screenshot of part of the entry below).
Google doesn't want potentially malicious (e.g. https://sites.google.com) or "forgotten" subdomains (https://developer.mozilla.org/en-US/docs/Web/Security/Attacks/Subdomain_takeover) to be able to handle passkeys.
As shown in Google's example, it's best to explicitly whitelist ALL subdomains thay may interact with passkeys to prevent (future) oversight.
PS this is exactly what I meant with "and in specific cases using subdomains and faulty server webauthn implementations" in https://todon.nl/@ErikvanStraten/116595157772945666.
Edited to add: many commercial websites use subdomains where third parties have access to (such as track.example.com), for example used in mass mailings. You don't want a gone rogue third party to be able to handle WebAuthn registrations and logins on your subdomain used by them.
According to the RELATIONS tab in https://www.virustotal.com/gui/domain/report-uri.com your domain has (at least) 3.2K subdomains. Do you trust each of them?
#Passkeys #SubDomainTakeOver #Subdomains #SubDomainHijacking
-
Subdomain Takeover Vulnerabilities and Prevention
In this article, I cover:
* How subdomain takeover vulnerabilities occur
* Real-world exploitation scenarios
Reconnaissance and detection techniques
* Practical prevention and DNS hygiene strategieshttps://denizhalil.com/2026/02/16/subdomain-takeover-vulnerabilities-prevention/
#CyberSecurity #SubdomainTakeover #DNS #AttackSurface #BugBounty #RedTeam #BlueTeam #InfoSec #CloudSecurity #WebSecurity #EthicalHacking
-
Subdomain Takeover Vulnerabilities and Prevention
In this article, I cover:
* How subdomain takeover vulnerabilities occur
* Real-world exploitation scenarios
Reconnaissance and detection techniques
* Practical prevention and DNS hygiene strategieshttps://denizhalil.com/2026/02/16/subdomain-takeover-vulnerabilities-prevention/
#CyberSecurity #SubdomainTakeover #DNS #AttackSurface #BugBounty #RedTeam #BlueTeam #InfoSec #CloudSecurity #WebSecurity #EthicalHacking
-
Jo @LidlUS @lidl @LidlGB, didn't knew you now also host fake versions of the New-York Times:
hxxps[:]//baustandards-qs[.]lidl[.]com
Seems a solid subdomain takeover?
Pointing to AWS: 72.144.31[.]24 -
"A Guide To Subdomain Takeovers 2.0"
https://www.hackerone.com/community/guide-subdomain-takeovers
-
"A Guide To Subdomain Takeovers 2.0"
https://www.hackerone.com/community/guide-subdomain-takeovers
-
Found a great #opensource tool to scan sites for a laundry list of vulnerabilities https://github.com/h4r5h1t/webcopilot.
Just used it to scan all my company domains, works great!
The tools integrated into this single app are the same tools "security researchers" use to scan sites for #xss #SQLi #ssrf #crlf #lfi #subdomaintakeover #openredirect, etc. vulnerabilities - into a single CLI tool.
Can also help avoid/confirm those "beg-bounty" situations where a simple misconfiguration is touted as a "critical vulnerability" because someone use a quick scanning tool to determine that sub-domain take-over is possible (very common, not critical, easy to fix), or missing DMARC records are present (which 98% of all Internet sites have issues with, and is very easy to fix) to demand a cash reward so they can "share additional critical vulnerabilities" that aren't a thing - they just want money.
Have fun!
-
Found a great #opensource tool to scan sites for a laundry list of vulnerabilities https://github.com/h4r5h1t/webcopilot.
Just used it to scan all my company domains, works great!
The tools integrated into this single app are the same tools "security researchers" use to scan sites for #xss #SQLi #ssrf #crlf #lfi #subdomaintakeover #openredirect, etc. vulnerabilities - into a single CLI tool.
Can also help avoid/confirm those "beg-bounty" situations where a simple misconfiguration is touted as a "critical vulnerability" because someone use a quick scanning tool to determine that sub-domain take-over is possible (very common, not critical, easy to fix), or missing DMARC records are present (which 98% of all Internet sites have issues with, and is very easy to fix) to demand a cash reward so they can "share additional critical vulnerabilities" that aren't a thing - they just want money.
Have fun!
-
Infection Method – Sub-Domain Takeover
A subdomain takeover is a type of cybersecurity vulnerability that occurs when an attacker gains control of a subdomain of a website or a domain name. This attack can seriously affect the security and functionality of a web application or website. In this explanation, we'll look at subdomain takeovers, how they work, the r
https://svenruppert.com/2023/11/20/infection-method-sub-domain-takeover/
#Security #cybersecurity #security #SubdomainTakeover -
Infection Method – Sub-Domain Takeover
A subdomain takeover is a type of cybersecurity vulnerability that occurs when an attacker gains control of a subdomain of a website or a domain name. This attack can seriously affect the security and functionality of a web application or website. In this explanation, we'll look at subdomain takeovers, how they work, the r
https://svenruppert.com/2023/11/20/infection-method-sub-domain-takeover/
#Security #cybersecurity #security #SubdomainTakeover -
MDEASM is a tool used by Microsoft Defender to detect expired subdomains which can be vulnerable to takeover. It continuously maps the external-facing resources across an organization's attack surface to identify, classify and prioritize risks, including subdomain expiration and takeover. https://techcommunity.microsoft.com/t5/microsoft-defender-external/identify-digital-assets-vulnerable-to-subdomain-takeover/ba-p/3700773 #MDEASM #MicrosoftDefender #SubdomainTakeover