PHASE: The Mechanism33% COMPLETION
MODULE 15
Subdomain Takeovers
Identifying and verifying subdomain takeover vulnerabilities.
The Mechanism
1. Company creates `promo.target.com` pointing to `target.github.io`.
2. Promotion ends. Company deletes the GitHub page.
3. DNS record `promo.target.com` -> `target.github.io` still exists.
4. Attacker claims `target.github.io` on GitHub.
5. Attacker now controls content on `promo.target.com`.