Skip Navigation

Help me understand this Azure / DNS attack

www.keytos.io Microsoft Azure Vulnerability Still Affecting Thousands of New Subdomains Each Month

Subdomain takeover is a vulnerability that has plagued cloud users for years. Keytos Researches uncover an easy way to find thousands of new vulnerable domains each month.

I feel like I'm missing a step. You take down your website, but leave the DNS entry and the attacker does what? Builds a site that has the IP address your CNAME is pointing to? Can anyone make a website in azure and pick the IP address they want? Thanks

0