CRITICAL SEVERITYCLOUDID: aws-s3
AWS S3 Dangling DNS Takeover Fingerprint
An orphan CNAME points to an Amazon S3 bucket that was deleted or never created. An attacker can create the S3 bucket with the exact matching name in any AWS account and host arbitrary payloads or phishing pages on your domain.
CNAME Fingerprint Rule
*.s3.amazonaws.com / *.s3-website-*.amazonaws.com
404 Not Found
Response Body Token
“NoSuchBucket”
When SubdomainWatch scanner receives HTTP responses matching this token on a dangling CNAME, it raises a critical alert immediately.
Remediation Guide & Mitigation
Action Required: Delete the dangling CNAME DNS record in your DNS provider immediately, or re-create the target S3 bucket under your own AWS account with appropriate public-access block controls.
Immediate Defensive Checklist:
- Audit authoritative DNS zone records for any CNAME records pointing to
*.s3.amazonaws.com / *.s3-website-*.amazonaws.com. - Verify whether the corresponding target resource is still active in your cloud tenant.
- If the service was deprecated, delete the DNS record immediately to prevent hijackers from claiming the endpoint.
- Add automated continuous monitoring to alert before third parties can register matching resource names.
Monitor AWS S3 In Real-Time
SubdomainWatch continuously monitors your DNS zones for orphaned AWS S3 pointers, expired certificates, and dangling records 24/7.
Related Cloud Takeover Signatures
HOSTINGCRITICAL
GitHub Pages
*.github.io
HOSTINGCRITICAL
Heroku App
*.herokudns.com / *.herokuapp.com
CLOUDCRITICAL
Microsoft Azure App Service
*.azurewebsites.net / *.cloudapp.net
CLOUDCRITICAL
AWS CloudFront
*.cloudfront.net
CLOUDCRITICAL
AWS Elastic Beanstalk
*.elasticbeanstalk.com
DNSHIGH
Fastly CDN
*.fastly.net