-
-
Notifications
You must be signed in to change notification settings - Fork 795
Closed
Labels
edge caseAn edge case was discovered where it is possible to hijack a subdomain on this service.An edge case was discovered where it is possible to hijack a subdomain on this service.
Description
AWS finally started mitigating subdomain takeovers on CloudFront. When you try to register Alias (CNAME) for your CloudFront distribution, it refuses to do so if the DNS zone file has CNAME to different CloudFront domain.
This is a type of verification from cloudfront that you can't takeover any subdomain even both (http OR https) port (80 and 443) shows error.
If the DNS zone file has CNAME to different CloudFront domain.
so,from cloudfront bye bye bug bounty
When you try to takeover subdomain you will get this as a further alert!
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
edge caseAn edge case was discovered where it is possible to hijack a subdomain on this service.An edge case was discovered where it is possible to hijack a subdomain on this service.
