hunt-subdomain
Hunting skill for subdomain takeover vulnerabilities. Includes modern provider fingerprints — Microsoft Azure DevOps `cloudapp.azure.com` regional-pool re-issue (1-click OAuth ATO via wildcard `reply_to`, Binary Security), Zendesk help-desk takeover → email interception → password reset chain (0xpri…
Install / Use
npx skills add elementalsouls/Claude-BugHunter --skill hunt-subdomainInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of hunt-subdomain
hunt-subdomain scores 96/100 on our quality scale, 149th of 775 Security skills we index (top 20%).
Its SKILL.md is 24 KB long, well organised into 20 sections with 8 code examples: a thorough specification that gives an agent plenty to work with.
With 4,669 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 2 days ago, so hunt-subdomain is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
hunt-subdomain compared with similar skills
All 4 of these similar skills score higher than hunt-subdomain; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| hunt-subdomain (this skill)by elementalsouls | 96 | 4.7k | 2d ago | SKILL.md |
| algorithmic-artby anthropics | 100 | 177.9k | 5d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 5d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 7d ago | SKILL.md |
| ui-ux-pro-maxby nextlevelbuilder | 100 | 130.2k | 7d ago | SKILL.md |
Frequently asked questions
- How do I install hunt-subdomain?
- Run
npx skills add elementalsouls/Claude-BugHunter --skill hunt-subdomain. The install tabs above show the steps for each supported agent. - Which AI agents does hunt-subdomain work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is hunt-subdomain safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is hunt-subdomain still maintained?
- The repository was last updated 2 days ago, so hunt-subdomain is actively maintained.
Skill content
View source on GitHubname: hunt-subdomain
description: Hunting skill for subdomain takeover vulnerabilities. Includes modern provider fingerprints — Microsoft Azure DevOps cloudapp.azure.com regional-pool re-issue (1-click OAuth ATO via wildcard reply_to, Binary Security), Zendesk help-desk takeover → email interception → password reset chain (0xprial writeup), Vercel cname.vercel-dns.com deleted-project takeover, plus general Fastly CDN service re-attach and S3 dangling-bucket cookie-scope techniques. Use when hunting subdomain takeover — emphasis on ATO-chain primitives (OAuth redirect_uri, cookie-domain, email DNS).
sources: github, hackerone_public, binarysecurity_research, can-i-take-over-xyz_research
report_count: 3
Crown Jewel Targets
Subdomain takeover is high-value because it allows an attacker to serve content from a trusted, company-owned domain — bypassing browser same-origin trust, phishing filters, and user skepticism simultaneously.
Highest payout contexts:
- Subdomains of major SaaS brands (Shopify, Snapchat, Mozilla, Yelp) where the trusted domain has user session context
- CDN-backed subdomains (Fastly, CloudFront) where CNAME points to unclaimed origins
- Third-party service integrations: UserVoice, WordPress.com, GitHub Pages, GitLab Pages, Heroku, Zendesk
- Preview/staging/dev subdomains (
new.,preview.,course.,delivery.,addons-preview.) — abandoned after feature launches - Subdomains used for OAuth redirect URIs or SSO endpoints — these pay highest
Asset types that matter most:
- CNAME records pointing to deprovisioned third-party services
- NS delegations to abandoned zones
- A records pointing to unallocated cloud IPs (less common)
- GitLab/GitHub Pages with unclaimed project namespaces
Attack Surface Signals
DNS signals:
CNAMEpointing to*.github.io,*.gitlab.io,*.fastly.net,*.herokudns.com,*.wordpress.com,*.uservoice.com,*.zendesk.com,*.s3.amazonaws.com,*.azurewebsites.net,*.netlify.app- NXDOMAIN or
SERVFAILon the CNAME target while the parent record still exists - NS records delegating to registrars where the zone is no longer registered
HTTP response signals:
"There isn't a GitHub Pages site here""NoSuchBucket"(S3)"The specified bucket does not exist""No such app"(Heroku)"Sorry, this shop is currently unavailable"(Shopify)"This UserVoice subdomain is available""Do you want to register"(any domain parking page)- HTTP 404 with provider-specific error templates
- Fastly:
"Fastly error: unknown domain" "404 Web Site not found"(Azure App Service)
Tech stack signals:
- Response headers:
X-Served-By: cache-*(Fastly),X-GitHub-Request-Id,Server: Netlify CNAMEchain resolving to provider infrastructure but returning provider 404- SSL cert issued to provider wildcard (
*.fastly.net) rather than company domain
Step-by-Step Hunting Methodology
-
Enumerate all subdomains for the target using passive + active sources:
subfinder -d target.com -allamass enum -passive -d target.comassetfinder --subs-only target.com- Certificate transparency:
crt.sh/?q=%.target.com
-
Resolve all subdomains and flag those with:
- NXDOMAIN responses
- CNAME pointing to a third-party provider
cat subdomains.txt | dnsx -a -cname -o resolved.txt -
Cross-reference CNAMEs against known vulnerable provider fingerprints using
nucleiorsubjack:subjack -w subdomains.txt -t 100 -timeout 30 -ssl -c fingerprints.json nuclei -l subdomains.txt -t takeovers/ -
Manual verification for each flagged subdomain:
dig CNAME subdomain.target.com— confirm CNAME existsdig A <cname-target>— confirm NXDOMAIN or no resolutioncurl -sk https://subdomain.target.com— check for provider error string
-
Confirm claimability — attempt to register the resource:
- GitHub Pages: check if
<username>.github.io/<repo>or org page is unclaimed - GitLab Pages: check project namespace
- S3: attempt
aws s3api create-bucket --bucket <bucketname> - UserVoice/Zendesk/WordPress: visit registration URL
- Fastly: check if origin hostname is unregistered
- GitHub Pages: check if
-
Claim the resource (only enough to prove control — do NOT serve malicious content):
- Create a minimal index page with your HackerOne username and a timestamp
- Take screenshot showing your content served on
subdomain.target.com
-
Document the chain: CNAME record → provider target → unclaimed resource → your content
-
Assess impact escalation:
- Does the subdomain appear in OAuth redirect allowlists?
- Does it share cookies with parent domain (
domain=.target.com)? - Is it referenced in the app's CSP?
- Can it receive authenticated API calls?
-
Write report before releasing the claim (some programs want to verify first)
Payload & Detection Patterns
Bulk CNAME extraction and NXDOMAIN detection:
# Extract CNAMEs and check if target resolves
while read sub; do
cname=$(dig +short CNAME "$sub" | head -1)
if [ -n "$cname" ]; then
result=$(dig +short A "$cname")
if [ -z "$result" ]; then
echo "[POTENTIAL] $sub -> $cname (NXDOMAIN)"
fi
fi
done < subdomains.txt
Nuclei takeover scan:
nuclei -l subdomains.txt -t ~/nuclei-templates/http/takeovers/ -severity medium,high,critical
subjack with SSL:
subjack -w subdomains.txt -t 100 -timeout 30 -ssl -c $GOPATH/src/github.com/haccer/subjack/fingerprints.json -v
Provider fingerprint grep patterns:
curl -sk "https://$subdomain" | grep -iE \
"there isn't a github pages|no such bucket|no such app|this uservoice|fastly error: unknown domain|do you want to register|sorry, this shop|project not found|404 not found|unclaimed"
Check if subdomain is in scope for cookies (shared parent domain):
curl -Isk "https://target.com" | grep -i "set-cookie" | grep "domain=.target.com"
Fastly-specific detection:
curl -sI "https://subdomain.target.com" -H "Host: subdomain.target.com" | grep -i "fastly\|x-served-by\|x-cache"
curl -sk "https://subdomain.target.com" | grep -i "fastly error"
S3 unclaimed bucket check:
aws s3api head-bucket --bucket <extracted-bucket-name> 2>&1 | grep -i "NoSuchBucket\|403\|404"
GitLab Pages specific:
dig CNAME sub.target.com
# If pointing to *.gitlab.io — visit the gitlab.io URL directly
# 404 from gitlab.io project = claimable
Common Root Causes
-
Service offboarding without DNS cleanup — Developer removes a Heroku app, UserVoice account, or WordPress site but never deletes the CNAME record. DNS lives forever; service does not.
-
Staging/preview infrastructure abandoned post-launch —
course.,new.,preview.,beta.subdomains provisioned for a product launch, pointed at a third-party, then forgotten when the campaign ends. -
Subdomain provisioned by a third-party team — Marketing sets up a UserVoice or Zendesk subdomain via IT, product sunset kills it, but DNS is owned by engineering who doesn't know.
-
CDN misconfiguration without origin validation — Fastly and similar CDNs historically allowed any domain to "claim" a backend hostname by creating a service pointing to it. Unregistered origin hostnames become claimable.
-
GitHub/GitLab Pages namespace not reserved — Organization renames, user accounts deleted, or repos made private/deleted while the Pages CNAME still points to the old namespace.
-
Wildcard DNS entries —
*.target.compointing to a cloud provider means any unclaimed subdomain potentially resolves to claimable infrastructure. -
Acquired/divested company DNS not cleaned — Post-acquisition, former brand subdomains (like
oberlo.comunder Shopify) retain CNAMEs to services that are no longer paid for.
Bypass Techniques
Defense: Manual fingerprint review before publishing
- Bypass: Use alternative error strings — providers change their 404 pages. Maintain an up-to-date fingerprint list. Some providers show different errors on HTTP vs HTTPS. Test both.
Defense: Scope restrictions (only main domain in scope)
- Bypass: Check program's asset list carefully —
*.target.comwildcards often include subdomains implicitly. Escalate impact to get it in scope.
Defense: "Can't reproduce" responses due to timing
- Bypass: Screenshot immediately after claiming. Record a video walkthrough. The window can be short for popular subdomains.
Defense: HTTPS certificate mismatch blocking proof
- Bypass: Some providers (GitHub Pages, Netlify) auto-provision TLS for claimed domains. Others don't — show HTTP takeover and note TLS would be resolved by provider on claim.
Defense: Provider-side validation (Fastly verifying domain ownership)
- Bypass: Some Fastly configurations don't validate origin hostnames. Check if the CNAME target is a generic Fastly backend hostname vs. a customer-verified one. Try claiming anyway and observe behavior.
Defense: Rate limiting on subdomain enumeration
- Bypass: Use passive-only sources (SecurityTrails, Shodan, crt.sh, VirusTotal) to avoid triggering WAF/IDS. DNS resolution doesn't touch the web server.
Defense: Program claims "low severity / no impact"
- Bypass: Demonstrate same-origin cookie theft, OAuth redirect abuse, or CSP bypass to escalate. Find if the subdomain is listed in any
postMessagetargetOriginchecks in JS.
Gate 0 Validation
-
What can the attacker DO right now? Can you register the unclaimed resource (GitHub repo, S3 bucket, Heroku app, UserVoice account) and serve arbitrary content — including phishing pages, credential harvesters, or malicious scripts — under the target's trusted domain name?
-
What does the victim LOSE? Users lose trust and safety: they see a company-branded URL serving attacker content. The company loses brand integrity, potentially leaks session cookies if the subdomain is in
domain=.target.comscope, and may have OAuth/SSO flows hijacked. Depending on CSP configuration, XSS against the main application may be possible. -
Can it be reproduced in 10 minutes from scratch?
dig CNAME subdomain.target.com→ confirms CNAME to providercurl -sk https://subdomain.target.com→ confirms provider error string- Visit provider registration page → confirms namespace is available
- Screenshots of all three steps = reproducible in under 10 minutes
If you cannot show the provider resource is currently unclaimed and claimable, it is not a valid report.
Real Impact Examples
Scenario A — Trusted Brand Phishing via Abandoned SaaS (Snapchat/UserVoice)
An attacker finds feedback.snapchat.com CNAME pointing to a UserVoice subdomain. The UserVoice account was cancelled but the DNS record remained. The attacker registers the matching UserVoice subdomain for free, gaining control of feedback.snapchat.com. Any user navigating to that URL — perhaps from old bookmarks or Google results — sees attacker-controlled content on a Snapchat-branded domain. Since the domain is trusted by browsers, phishing campaigns sent from this subdomain bypass email security filters that check domain reputation.
Scenario B — CDN Origin Takeover Enabling Same-Origin Attacks (Mozilla/Fastly)
addons-preview-cdn.mozilla.net had a CNAME pointing to a Fastly origin hostname that was no longer registered to Mozilla's Fastly account. An attacker could create a Fastly service claiming that origin hostname, causing all requests to addons-preview-cdn.mozilla.net to be routed to attacker-controlled Fastly infrastructure. Since the subdomain shares the mozilla.net domain, it could be leveraged to serve malicious CDN assets that appear to come from Mozilla's infrastructure, potentially bypassing CSP rules that allowlist `*
Truncated for display — read the full file on GitHub.
Related Skills
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG…
ui-ux-pro-max
130.2kUI/UX design intelligence for web, mobile, and desktop. This skill should be used when designing, building, reviewing, or fixing interfaces, including pages, components, design systems, accessibility, interaction, responsive layout, typography, color, charts, and stack-specific UI implementation.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
