EdOverflow / can-i-take-over-xyz

"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.
Creative Commons Attribution 4.0 International
4.87k stars 716 forks source link

Can i takeover subdomain with cname that refers cdn.cloudflare.com #193

Open yousefmoh15 opened 3 years ago

yousefmoh15 commented 3 years ago

I have found a subdomain like sub.example.com which alias to sub.example.com.cdn.cloudflare.com when I request that subdomain it gives me ( 404 not found) so can i take over it or not ?

isira-adithya commented 3 years ago

I have the same question? Anyone knowss how to do this?

indianajson commented 3 years ago

Subdomains pointing to sub.example.com.cdn.cloudflare.com utilize a CNAME Zone on Cloudflare which requires a Business or Enterprise account and requires TXT record verification at the authoritative DNS per this article titled Understanding a CNAME Setup. Thus, takeovers are impossible.

isira-adithya commented 3 years ago

Oh thanks a lot for the clarification. 👌

nhl0010 commented 2 years ago

thanks

abusabiha commented 1 year ago

In Some Place, we see "404 Not Found. nginx".

when we dig this, we saw some ip address. but not found is it from where.

Can anybody tell me how can we find it and is it vulnerable or not?

sunnyshrma commented 11 months ago

I don't think so we can takeover subdomain that point towards the IP. Means cname like 18.6.23.54 not possible to takeover