Did I Properly Identify Potential Subdomain Takeovers?

thakillingjoke

Lurker
Member
Joined
Threads
1
Posts
3
First post here — Azure DNS verification / research dataset

Hey everyone, first post in the group.

I'm still learning and building out my methodology for DNS and cloud-security research, and this is probably the furthest I've gotten with a dataset that I feel is worth putting in front of other researchers for review.


Scope

The scope of this research was limited to publicly observable DNS records associated with samsclub.com subdomains identified during my research.

The verification focused on Azure / Azure Traffic Manager-related CNAME records and the DNS state of their referenced targets.

I did not attempt to claim, provision, modify, access, or otherwise take control of any identified cloud resource.


Verification date

September 17, 2026

The individual observations in the dataset contain their own UTC verification timestamps. The recorded verification was performed against the publicly resolvable DNS state at that time.


What I found

I performed independent DNS verification and recorded the observations in the attached dataset.

The dataset contains:


  • Hostname
  • DNS provider
  • CNAME target
  • Target DNS status
  • Authoritative nameserver
  • Authoritative response
  • Verification status
  • Classification
  • UTC verification timestamp
  • Research notes
The important distinction I'm trying to learn correctly is:

A dangling CNAME / NXDOMAIN response is not automatically proof of a successful subdomain takeover.

I'm documenting what I can actually verify rather than claiming exploitation or resource claimability where I haven't demonstrated it.


Dataset

sams_azure_verified.csv

Download:


You must reply to see the hidden content. Consider upgrading your account to increase your reply limit.


Format: CSV / ASCII text
Size: ~14 KB

SHA-256:


0e52b8e0d8b79394b2f399ff526fd72b13c8a17ea8b2a45dab35e821ada649ab

The hash is included so anyone downloading the artifact can independently verify that the file matches the research copy.

What I'm looking for from the community

I'm posting this primarily because I'd really appreciate experienced eyes on my methodology and interpretation.

What I'm interested in is understanding whether I've correctly distinguished:


  1. What the DNS evidence actually demonstrates
  2. What it does not demonstrate
  3. Where my verification methodology could be improved
  4. What additional evidence would normally be required before calling something genuinely exploitable
  5. What the appropriate next steps would be for safely researching this type of condition in a controlled, authorized environment
I'm particularly curious about what could theoretically come from taking the research further, but I have not attempted to claim, provision, modify, or access any of the referenced cloud resources.

If I've misunderstood something, I'd genuinely rather have someone point it out than walk away with an incorrect understanding.

I'm especially interested in feedback from people who have worked with Azure, Traffic Manager, dangling CNAMEs, DNS verification, or subdomain takeover research.


Thanks for taking a look. I'm here to learn.
 
  • T
    Created
  • Last reply
  • 0
    Replies
  • 145
    Views
  • 1
    Participants
  • Participants list