Skip to content
Security
Skill

/hunt-subdomain

Hunting skill for subdomain takeover vulnerabilities. Includes modern provider fingerprints — Microsoft Azure DevOps `cloudapp.azure.com` regional-pool re-issue (1-click OAuth ATO via wildcard `reply_to`, Binary Security), Zendesk help-desk takeover → email interception →

From plugin
claude-bughunter
3.3k82 skills15 commands
Install
$ npx -y skills add elementalsouls/Claude-BugHunter --skill hunt-subdomain --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/hunt-subdomain

Context preview

The summary Claude sees to decide when to auto-load this skill.

Hunting skill for subdomain takeover vulnerabilities. Includes modern provider fingerprints — Microsoft Azure DevOps `cloudapp.azure.com` regional-pool re-issue (1-click OAuth ATO via wildcard `reply_to`, Binary Security), Zendesk help-desk takeover → email interception →

SKILL.md

hunt-subdomain.SKILL.md
name: hunt-subdomain
description: Hunting skill for subdomain takeover vulnerabilities. Includes modern provider fingerprints — Microsoft Azure DevOps `cloudapp.azure.com` regional-pool re-issue (1-click OAuth ATO via wildcard `reply_to`, Binary Security), Zendesk help-desk takeover → email interception → password reset chain (0xprial writeup), Vercel `cname.vercel-dns.com` deleted-project takeover, plus general Fastly CDN service re-attach and S3 dangling-bucket cookie-scope techniques. Use when hunting subdomain takeover — emphasis on ATO-chain primitives (OAuth `redirect_uri`, cookie-domain, email DNS).
sources: github, hackerone_public, binarysecurity_research, can-i-take-over-xyz_research
report_count: 3

Crown Jewel Targets

Subdomain takeover is high-value because it allows an attacker to serve content from a **trusted, company-owned domain** — bypassing browser same-origin trust, phishing filters, and user skepticism simultaneously.

**Highest payout contexts:**

  • Subdomains of major SaaS brands (Shopify, Snapchat, Mozilla, Yelp) where the trusted domain has user session context
  • CDN-backed subdomains (Fastly, CloudFront) where CNAME points to unclaimed origins
  • Third-party service integrations: UserVoice, WordPress.com, GitHub Pages, GitLab Pages, Heroku, Zendesk
  • Preview/staging/dev subdomains (`new.`, `preview.`, `course.`, `delivery.`, `addons-preview.`) — abandoned after feature launches
  • Subdomains used for OAuth redirect URIs or SSO endpoints — these pay highest

**Asset types that matter most:**

  • CNAME records pointing to deprovisioned third-party services
  • NS delegations to abandoned zones
  • A records pointing to unallocated cloud IPs (less common)
  • GitLab/GitHub Pages with unclaimed project namespaces

---

Attack Surface Signals

**DNS signals:**

  • `CNAME` pointing to `*.github.io`, `*.gitlab.io`, `*.fastly.net`, `*.herokudns.com`, `*.wordpress.com`, `*.uservoice.com`, `*.zendesk.com`, `*.s3.amazonaws.com`, `*.azurewebsites.net`, `*.netlify.app`
  • NXDOMAIN or `SERVFAIL` on the CNAME target while the parent record still exists
  • NS records delegating to registrars where the zone is no longer registered

**HTTP response signals:**

  • `"There isn't a GitHub Pages site here"`
  • `"NoSuchBucket"` (S3)
  • `"The specified bucket does not exist"`
  • `"No such app"` (Heroku)
  • `"Sorry, this shop is currently unavailable"` (Shopify)
  • `"This UserVoice subdomain is available"`
  • `"Do you want to register"` (any domain parking page)
  • HTTP 404 with provider-specific error templates
  • Fastly: `"Fastly error: unknown domain"`
  • `"404 Web Site not found"` (Azure App Service)

**Tech stack signals:**

  • Response headers: `X-Served-By: cache-*` (Fastly), `X-GitHub-Request-Id`, `Server: Netlify`
  • `CNAME` chain resolving to provider infrastructure but returning provider 404
  • SSL cert issued to provider wildcard (`*.fastly.net`) rather than company domain

---

Step-by-Step Hunting Methodology

1. **Enumerate all subdomains** for the target using passive + active sources:

  • `subfinder -d target.com -all`
  • `amass enum -passive -d target.com`
  • `assetfinder --subs-only target.com`
  • Certificate transparency: `crt.sh/?q=%.target.com`

2. **Resolve all subdomains** and flag those with:

  • NXDOMAIN responses
  • CNAME pointing to a third-party provider
   cat subdomains.txt | dnsx -a -cname -o resolved.txt

3. **Cross-reference CNAMEs** against known vulnerable provider fingerprints using `nuclei` or `subjack`:

   subjack -w subdomains.txt -t 100 -timeout 30 -ssl -c fingerprints.json
   nuclei -l subdomains.txt -t takeovers/

4. **Manual verification** for each flagged subdomain:

  • `dig CNAME subdomain.target.com` — confirm CNAME exists
  • `dig A <cname-target>` — confirm NXDOMAIN or no resolution
  • `curl -sk https://subdomain.target.com` — check for provider error string

5. **Confirm claimability** — attempt to register the resource:

  • GitHub Pages: check if `<username>.github.io/<repo>` or org page is unclaimed
  • GitLab Pages: check project namespace
  • S3: attempt `aws s3api create-bucket --bucket <bucketname>`
  • UserVoice/Zendesk/WordPress: visit registration URL
  • Fastly: check if origin hostname is unregistered

6. **Claim the resource** (only enough to prove control — do NOT serve malicious content):

  • Create a minimal index page with your HackerOne username and a timestamp
  • Take screenshot showing your content served on `subdomain.target.com`

7. **Document the chain**: CNAME record → provider target → unclaimed resource → your content

8. **Assess impact escalation**:

  • Does the subdomain appear in OAuth redirect allowlists?
  • Does it share cookies with parent domain (`domain=.target.com`)?
  • Is it referenced in the app's CSP?
  • Can it receive authenticated API calls?

9. **Write report** before releasing the claim (some programs want to verify first)

---

Payload & Detection Patterns

**Bulk CNAME extraction and NXDOMAIN detection:**

# Extract CNAMEs and check if target resolves
while read sub; do
  cname=$(dig +short CNAME "$sub" | head -1)
  if [ -n "$cname" ]; then
    result=$(dig +short A "$cname")
    if [ -z "$result" ]; then
      echo "[POTENTIAL] $sub -> $cname (NXDOMAIN)"
    fi
  fi
done < subdomains.txt

**Nuclei takeover scan:**

nuclei -l subdomains.txt -t ~/nuclei-templates/http/takeovers/ -severity medium,high,critical

**subjack with SSL:**

subjack -w subdomains.txt -t 100 -timeout 30 -ssl -c $GOPATH/src/github.com/haccer/subjack/fingerprints.json -v

**Provider fingerprint grep patterns:**

curl -sk "https://$subdomain" | grep -iE \
  "there isn't a github pages|no such bucket|no such app|this uservoice|fastly error: unknown domain|do you want to register|sorry, this shop|project not found|404 not found|unclaimed"

**Check if subdomain is in scope for cookies (shared parent domain):**

curl -Isk
Read more
Ships withclaude-bughunter

A self-contained Claude skill bundle for bug hunting and external red-team work · 82 skills · 15 slash commands · 681 disclosed-report patterns across 24 core vulnerability classes · enterprise identity + infrastructure attack matrices · engagement-folder

Get the whole plugin

Other skills on claude-bughunter.