Subdomain Takeover Severity Depends on Security Context, Not Exploit Method
Security researchers warn that triaging subdomain takeover vulnerabilities solely by exploit mechanism — such as a dangling CNAME — leads to critical bugs being misclassified as low-severity. A 2017 HackerOne report by Arne Swinnen demonstrated this gap: claiming the abandoned saostatic.uber.com CDN subdomain via CloudFront allowed full session hijacking across all Uber services due to a wildcard-scoped cookie. The same CloudFront fingerprint can yield a Critical rating on an auth subdomain but an Informational on a blog subdomain, with the difference lying in what trust and cookie scope that subdomain carried. A USENIX Security 2021 study reinforced the scale of the problem, finding that 81% of sites with vulnerable subdomains had cookie confidentiality issues exploitable by related-domain attackers. Experts advocate evaluating each high-confidence scanner finding against security context factors — including cookie scope, OAuth whitelist inclusion, and CSP trust — before assigning a severity rating.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in