Skip to main content
HOME|SIGNATURES DIRECTORY
PUBLIC VULNERABILITY DIRECTORY

42 Cloud Takeover Fingerprints

Live database of cloud provider dangling CNAME response patterns monitored continuously by SubdomainWatch. Search by error string, provider, or infrastructure category.

Showing 16 of 16 verified fingerprints
CRITICAL

AWS S3

Trigger: 404 Not Found
CANONICAL CNAME TARGET
*.s3.amazonaws.com / *.s3-website-*.amazonaws.com
EXACT BODY MATCH TOKEN
"NoSuchBucket"

Vulnerability Mechanism: An orphan CNAME points to an Amazon S3 bucket that was deleted or never created. An attacker can create the S3 bucket with the exact matching name in any AWS account and host arbitrary payloads or phishing pages on your domain.

Remediation Action: Delete the dangling CNAME DNS record in your DNS provider immediately, or re-create the target S3 bucket under your own AWS account with appropriate public-access block controls.

CRITICAL

GitHub Pages

Trigger: 404 Not Found
CANONICAL CNAME TARGET
*.github.io
EXACT BODY MATCH TOKEN
"There isn't a GitHub Pages site here"

Vulnerability Mechanism: A custom domain points via CNAME to a user.github.io host, but no GitHub repository currently claims this custom domain in its CNAME file. An attacker can create a public repo with a CNAME file claiming your domain.

Remediation Action: Remove the CNAME DNS record pointing to *.github.io, or configure a verified GitHub repository in your organization with this custom domain and enforce HTTPS.

CRITICAL

Heroku App

Trigger: 404 / 502
CANONICAL CNAME TARGET
*.herokudns.com / *.herokuapp.com
EXACT BODY MATCH TOKEN
"No such app"

Vulnerability Mechanism: A DNS record points to a decommissioned Heroku dyno. An adversary can register a new Heroku application, attach your custom domain via the Heroku CLI, and immediately serve content under your authoritative domain.

Remediation Action: Delete the dangling CNAME in DNS, or re-attach the domain to an active Heroku application inside your verified team account.

CRITICAL

Microsoft Azure App Service

Trigger: 404 Not Found
CANONICAL CNAME TARGET
*.azurewebsites.net / *.cloudapp.net
EXACT BODY MATCH TOKEN
"404 Web Site not found"

Vulnerability Mechanism: An Azure App Service plan or slot was deleted while the DNS CNAME record remains active. Any Azure customer can create an App Service with the unallocated subdomain prefix and claim ownership.

Remediation Action: Delete the dangling CNAME record from your authoritative DNS zone or re-bind the custom domain to an active Azure App Service plan.

CRITICAL

AWS CloudFront

Trigger: 403 Forbidden / 404
CANONICAL CNAME TARGET
*.cloudfront.net
EXACT BODY MATCH TOKEN
"Bad Request generated by cloudfront"

Vulnerability Mechanism: A CNAME references an unallocated or deleted CloudFront distribution. If an attacker knows the target, they can attempt to bind the custom domain to a newly provisioned CloudFront distribution.

Remediation Action: Remove the dangling CNAME or ensure the CloudFront distribution is active with an attached ACM SSL certificate covering the custom domain.

CRITICAL

AWS Elastic Beanstalk

Trigger: NXDOMAIN / 404
CANONICAL CNAME TARGET
*.elasticbeanstalk.com
EXACT BODY MATCH TOKEN
"Target Unallocated"

Vulnerability Mechanism: An Elastic Beanstalk environment was terminated, releasing the regional subdomain prefix back to the public pool. Attackers can provision a new Beanstalk app with the identical environment name.

Remediation Action: Delete the CNAME record or recreate the Elastic Beanstalk environment in the same AWS region.

HIGH

Fastly CDN

Trigger: 404 / 500
CANONICAL CNAME TARGET
*.fastly.net
EXACT BODY MATCH TOKEN
"Fastly error: unknown domain"

Vulnerability Mechanism: The CNAME points to Fastly edge routers, but no Fastly service is currently configured to handle requests for this host. Anyone with a Fastly account can claim the domain on their service.

Remediation Action: Delete the Fastly CNAME record from DNS or add the domain to your authorized Fastly service.

HIGH

Shopify Storefront

Trigger: 404 Not Found
CANONICAL CNAME TARGET
*.myshopify.com
EXACT BODY MATCH TOKEN
"Sorry, this shop is currently unavailable"

Vulnerability Mechanism: A subdomain mapped to Shopify has been disconnected from an active store. An attacker can connect the domain to an arbitrary Shopify account and display custom storefront content.

Remediation Action: Delete the CNAME pointing to myshopify.com or claim the domain in your verified Shopify admin dashboard.

CRITICAL

Surge.sh

Trigger: 404 Not Found
CANONICAL CNAME TARGET
*.surge.sh
EXACT BODY MATCH TOKEN
"project not found"

Vulnerability Mechanism: Surge.sh static site hosting was decommissioned without cleaning up the CNAME record. Any user running the Surge CLI can deploy a project claiming this exact domain name.

Remediation Action: Remove the Surge CNAME record from DNS or redeploy a verified project using the Surge CLI.

HIGH

Zendesk Help Center

Trigger: 404 Not Found
CANONICAL CNAME TARGET
*.zendesk.com
EXACT BODY MATCH TOKEN
"Help Center Closed"

Vulnerability Mechanism: An organization's help center CNAME points to a Zendesk instance that has been closed or renamed. Attackers can register a new trial Zendesk instance with the same subdomain mapping.

Remediation Action: Delete the host mapping CNAME in DNS or verify host mapping settings in your active Zendesk Admin Center.

HIGH

Readme.io

Trigger: 404 Not Found
CANONICAL CNAME TARGET
*.readme.io
EXACT BODY MATCH TOKEN
"Project doesnt exist yet"

Vulnerability Mechanism: Documentation CNAME points to an unclaimed or deleted Readme project. Anyone can register the matching project subdomain on Readme.io.

Remediation Action: Delete the CNAME pointing to Readme.io or configure the project slug within your Readme.io dashboard.

MEDIUM

Ghost CMS

Trigger: 404 Not Found
CANONICAL CNAME TARGET
*.ghost.io
EXACT BODY MATCH TOKEN
"The thing you were looking for is gone"

Vulnerability Mechanism: CNAME points to an expired Ghost Pro publication. Attackers can claim the slug on Ghost Pro if unallocated.

Remediation Action: Remove the Ghost CNAME record in DNS.

MEDIUM

Atlassian Statuspage

Trigger: 404 Not Found
CANONICAL CNAME TARGET
*.statuspage.io
EXACT BODY MATCH TOKEN
"Status page not found"

Vulnerability Mechanism: A status page was decommissioned but the custom domain CNAME record still resolves to Atlassian Statuspage edge.

Remediation Action: Delete the CNAME record in DNS or re-link your Statuspage organization.

HIGH

Pantheon Hosting

Trigger: 404 Not Found
CANONICAL CNAME TARGET
*.pantheonsite.io
EXACT BODY MATCH TOKEN
"404 Unknown Site"

Vulnerability Mechanism: A WordPress or Drupal environment on Pantheon was deleted while DNS remains pointed. Attackers can claim the site slug.

Remediation Action: Remove the CNAME pointing to Pantheon or re-associate the custom domain.

HIGH

WordPress.com

Trigger: 302 / 404
CANONICAL CNAME TARGET
*.wordpress.com
EXACT BODY MATCH TOKEN
"Do you want to register this domain?"

Vulnerability Mechanism: CNAME points to an unmapped WordPress.com blog. Attackers can map the custom domain to their personal WordPress.com site.

Remediation Action: Delete the CNAME in DNS or add domain mapping in your WordPress.com account.

MEDIUM

Tumblr

Trigger: 404 Not Found
CANONICAL CNAME TARGET
*.tumblr.com
EXACT BODY MATCH TOKEN
"There's nothing here"

Vulnerability Mechanism: CNAME points to Tumblr edge without a registered blog mapping the custom domain.

Remediation Action: Remove the CNAME DNS record.