Rampant CNAME misconfiguration leaves thousands of organizations open to subdomain takeover attacks
RedHunt Labs found more than 424,000 subdomains with misconfigured CNAME records during a automated trawl of 220 million hosts. How many of these sites were abandoned, such as if they belonged to defunct organizations, was unclear “because we need to lookup company registries to get that information”, said Mittal. Aided by HTTP response grabbing, the researchers also uncovered evidence that 139 of Alexa’s top 1,000 domains may have fallen prey to subdomain takeovers.