Skip to content

[45%] Subdomain takeover risk on unprobed hostmaster.* / cto.onecode.de via dangling CNAME #5

Description

@github-actions

Title

Subdomain takeover risk on unprobed hostmaster.* / cto.onecode.de via dangling CNAME

Target

hostmaster.onecode.de, hostmaster.www.onecode.de, hostmaster.hostmaster.onecode.de, hostmaster.hostmaster.www.onecode.de, cto.onecode.de

Class

MISCONFIG

Confidence

45/100

Reasoning

5 hosts unprobed in passive recon; hostmaster.* often point to DNS/mail providers (e.g., Cloudflare, Google Workspace); cto.onecode.de could point to personal/dev infra. Wildcard-dominated zone per dedicated-deep.md increases takeover surface.

Evidence needed

CNAME targets for each unprobed host; verify if target service allows claim (e.g., GitHub Pages, Heroku, Railway, AWS S3)

Verify steps

dig +short CNAME hostmaster.onecode.de; dig +short CNAME cto.onecode.de; check each CNAME target for claimability

Impact

Full subdomain control → phishing, credential harvest, brand damage — CRITICAL

Testability

PASSIVE

model: nemotron3 · auto-synced from leads/lead-*.md

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions