Subdomain Takeover worth 200$

Ali Razzaq
Sep 14, 2018 · 2 min read

Hi! My name is Ali and i am security researcher from Pakistan.

In this article i will explain how i takeover a subdomain which is mapped on netlify. Netlify is platform for web developers to upload their web projects and showcase to world.Netlify allow web developers to add custom domain or subdomain to their projects.

So i was searching for sites on google using some my recent google dorks.I land to a page am not disclosing site due to some reasons,Don’t mind :D) and i saw their scope for testing. I just open and try to get some subdomains.

I saw a subdoamin which was like this and while opening it is just showing “Not Found”

I just check the CNAME record of this subdomain because CNAME will tell you on which 3rd party site the subdomain is mapped.So i got this CNAME.

I register on and upload the web project first.Then it ask me to add custom subdomain.

So I just add the subdomain and click on verify.

So on few clicks the subdomain was mine :D I fully takeover the site. I uploaded a screenshot on twitter :D

After 15 minutes of reporting i got reply from their CTO and he rewarded me 200$ for this takeover.

I hope you enjoyed this takeover and this will help you to understand how you can claim subdomain if this was not claimed before.

Thanks for reading.Keep Sharing and Happy Hunting!

Welcome to a place where words matter. On Medium, smart voices and original ideas take center stage - with no ads in sight. Watch
Follow all the topics you care about, and we’ll deliver the best stories for you to your homepage and inbox. Explore
Get unlimited access to the best stories on Medium — and support writers while you’re at it. Just $5/month. Upgrade

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store