{"id":13550473,"url":"https://github.com/indianajson/can-i-take-over-dns","last_synced_at":"2025-04-03T00:34:01.611Z","repository":{"id":38061138,"uuid":"372623146","full_name":"indianajson/can-i-take-over-dns","owner":"indianajson","description":"\"Can I take over DNS?\" — a list of DNS providers and how to claim vulnerable domains.","archived":false,"fork":false,"pushed_at":"2025-03-02T15:13:15.000Z","size":2278,"stargazers_count":1017,"open_issues_count":29,"forks_count":95,"subscribers_count":32,"default_branch":"main","last_synced_at":"2025-03-02T15:26:13.572Z","etag":null,"topics":["bugbounty","bugbountytips","dangling-dns","dns","dns-hijacking","domain-takeover","hacking","hacking-tool","infosec","nameservers","subdomain-takeover","takeover-subdomain"],"latest_commit_sha":null,"homepage":"","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/indianajson.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":".github/FUNDING.yml","license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null},"funding":{"github":"indianajson"}},"created_at":"2021-05-31T20:36:13.000Z","updated_at":"2025-03-02T15:13:18.000Z","dependencies_parsed_at":"2023-11-11T18:29:11.037Z","dependency_job_id":"ffcf0f3a-0c40-46e6-9a33-3259fe46d0df","html_url":"https://github.com/indianajson/can-i-take-over-dns","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/indianajson%2Fcan-i-take-over-dns","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/indianajson%2Fcan-i-take-over-dns/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/indianajson%2Fcan-i-take-over-dns/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/indianajson%2Fcan-i-take-over-dns/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/indianajson","download_url":"https://codeload.github.com/indianajson/can-i-take-over-dns/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":246916733,"owners_count":20854511,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["bugbounty","bugbountytips","dangling-dns","dns","dns-hijacking","domain-takeover","hacking","hacking-tool","infosec","nameservers","subdomain-takeover","takeover-subdomain"],"created_at":"2024-08-01T12:01:33.583Z","updated_at":"2025-04-03T00:34:01.597Z","avatar_url":"https://github.com/indianajson.png","language":null,"funding_links":["https://github.com/sponsors/indianajson"],"categories":["Others"],"sub_categories":[],"readme":"\u003ch1 align=\"center\"\u003eCan I Take Over DNS?\u003cbr\u003e\u003csup\u003e\u003csub\u003eA list of DNS providers and whether their zones are vulnerable to DNS takeover!\u003cbr\u003e\u003csup\u003e Maintained by\u003c/sup\u003e \u003ca target=\"_blank\" href=\"https://twitter.com/intent/user?screen_name=indianajson\"\u003e\u003cimg src=\"https://img.shields.io/twitter/follow/indianajson?style=social\u0026label=%40indianajson\"/\u003e\u003c/a\u003e\u0026nbsp;\u003c/sub\u003e\u003c/sup\u003e \u003c/h1\u003e\n\nInspired by the popular [Can I Take Over XYZ?](https://github.com/EdOverflow/can-i-take-over-xyz) project by [@EdOverflow](https://github.com/EdOverflow) this project is uniquely oriented towards [DNS takeovers](#what-is-a-dns-takeover). DNS takeovers pose a high threat to companies, warrant high bounties, and are easy to find. We are trying to make this list comprehensive, so please [contribute](#contributions)!\n\n## Reporting to Bug Bounty Programs\n\nHere's a [public $500 bounty report](https://hackerone.com/reports/1226891) for a DNS takeover that I wrote with a thorough explanation to help you understand the issue and give you a template for how to write your own report. \n\nRemember, **\u003cins\u003ealways create a valid proof of concept\u003c/ins\u003e** (like the text record I added to the DNS zone in this report) before you report an issue to a bug bounty program, this will save time and get you paid faster. This list is updated infrequently (due to the fact things don't change that fast), so it is possible something listed below as `Vulnerable` is now `Not Vulnerable`. To that end, be sure to always perform a proof of concept takeover before reporting.  \n \n## DNS Providers\n\nThese companies provide DNS nameserver services to the general public. In this list you will find out whether domains pointing to these nameservers are vulnerable to DNS takeover and where you can learn more about them. \n\nProvider                                        | Status         | Fingerprint                                                             | Takeover Instructions                                                    \n--------------------------------------------- | -------------- | -----------------------------------------------------------------------  | -------------------------------------------------------------------------------------------------------------------------------------------\n[000Domains](https://000domains.com/) | **Not Vulnerable** | ns1.000domains.com\u003cbr\u003ens2.000domains.com\u003cbr\u003efwns1.000domains.com\u003cbr\u003efwns2.000domains.com | [Issue #19](https://github.com/indianajson/can-i-take-over-dns/issues/19)\n[AWS Route 53](https://aws.amazon.com/) | **Not Vulnerable** | ns-\\*\\*\\*\\*.awsdns-\\*\\*.org\u003cbr\u003ens-\\*\\*\\*\\*.awsdns-\\*\\*.co.uk\u003cbr\u003ens-\\*\\*\\*.awsdns-\\*\\*.com\u003cbr\u003ens-\\*\\*\\*.awsdns-\\*\\*.net | [Issue #1](https://github.com/indianajson/can-i-take-over-dns/issues/1)\n[Azure (Microsoft)](https://azure.microsoft.com/) | **Edge Case** | ns1-\\*\\*.azure-dns.com\u003cbr\u003ens2-\\*\\*.azure-dns.net\u003cbr\u003ens3-\\*\\*.azure-dns.org\u003cbr\u003ens4-\\*\\*.azure-dns.info | [Issue #5](https://github.com/indianajson/can-i-take-over-dns/issues/5)\n[BigCommerce](https://bigcommerce.com/) | **Not Vulnerable** | ns1.bigcommerce.com\u003cbr\u003ens2.bigcommerce.com\u003cbr\u003ens3.bigcommerce.com | [Issue #35](https://github.com/indianajson/can-i-take-over-dns/issues/35)\n[Bizland](https://bizland.com/) | **Not Vulnerable** | ns1.bizland.com\u003cbr\u003ens2.bizland.com\u003cbr\u003eclickme.click2site.com\u003cbr\u003eclickme2.click2site.com | [Issue #3](https://github.com/indianajson/can-i-take-over-dns/issues/3)\n[ClouDNS](https://cloudns.net/) | **Not Vulnerable** | \\*.cloudns.net | \n[Cloudflare](https://cloudflare.com/) | **Not Vulnerable** | \\*.ns.cloudflare.com | [Issue #10](https://github.com/indianajson/can-i-take-over-dns/issues/10)\n[Digital Ocean](https://digitalocean.com/) | **Vulnerable** | ns1.digitalocean.com\u003cbr\u003ens2.digitalocean.com\u003cbr\u003ens3.digitalocean.com | [Issue #22](https://github.com/indianajson/can-i-take-over-dns/issues/22)\n[DNSMadeEasy](https://dnsmadeeasy.com/) | **Vulnerable** | ns\\*\\*.dnsmadeeasy.com | [Issue #6](https://github.com/indianajson/can-i-take-over-dns/issues/6)\n[DNSimple](https://dnsimple.com/) | **Vulnerable** | ns1.dnsimple.com\u003cbr\u003ens2.dnsimple.com\u003cbr\u003ens3.dnsimple.com\u003cbr\u003ens4.dnsimple.com | [Issue #16](https://github.com/indianajson/can-i-take-over-dns/issues/16)\n[Domain.com](https://domain.com/)| **Vulnerable \u003csub\u003e\u003csup\u003e(w/ purchase)\u003c/sub\u003e\u003c/sup\u003e** | ns1.domain.com\u003cbr\u003ens2.domain.com | [Issue #17](https://github.com/indianajson/can-i-take-over-dns/issues/17)\n[DomainPeople](https://domainpeople.com/)| **Not Vulnerable** | ns1.domainpeople.com\u003cbr\u003ens2.domainpeople.com | [Issue #14](https://github.com/indianajson/can-i-take-over-dns/issues/14)\n[Dotster](https://dotster.com/)| **Not Vulnerable** | ns1.dotster.com\u003cbr\u003ens2.dotster.com\u003cbr\u003ens1.nameresolve.com\u003cbr\u003ens2.nameresolve.com | [Issue #18](https://github.com/indianajson/can-i-take-over-dns/issues/18)\n[Dreamhost](https://dreamhost.com/)| **Edge Case** | ns1.dreamhost.com\u003cbr\u003ens2.dreamhost.com\u003cbr\u003ens3.dreamhost.com | [Issue #40](https://github.com/indianajson/can-i-take-over-dns/issues/40)\n[EasyDNS](https://easydns.com/) | **Not Vulnerable** | dns1.easydns.com\u003cbr\u003edns2.easydns.net\u003cbr\u003edns3.easydns.org\u003cbr\u003edns4.easydns.info| [Issue #9](https://github.com/indianajson/can-i-take-over-dns/issues/9)\n[Gandi.net](https://gandi.net/) | **Not Vulnerable** | a.dns.gandi.net\u003cbr\u003eb.dns.gandi.net\u003cbr\u003ec.dns.gandi.net | \n[Google Cloud](https://cloud.google.com/) | **Edge Case** | ns-cloud-\\*\\*.googledomains.com | [Issue #2](https://github.com/indianajson/can-i-take-over-dns/issues/2)\n[Hostinger (old NS)](https://hostinger.com/) | **Not Vulnerable** | ns1.hostinger.com\u003cbr\u003ens2.hostinger.com | \n[Hover](https://hover.com/) | **Not Vulnerable** | ns1.hover.com\u003cbr\u003ens2.hover.com | [Issue #21](https://github.com/indianajson/can-i-take-over-dns/issues/21)\n[Hurricane Electric](https://dns.he.net/) | **Vulnerable** | ns5.he.net\u003cbr\u003ens4.he.net\u003cbr\u003ens3.he.net\u003cbr\u003ens2.he.net\u003cbr\u003ens1.he.net | [Issue #25](https://github.com/indianajson/can-i-take-over-dns/issues/25)\n[Linode](https://linode.com/) | **Vulnerable** | ns1.linode.com\u003cbr\u003ens2.linode.com | [Issue #26](https://github.com/indianajson/can-i-take-over-dns/issues/26)\n[MediaTemple (mt)](https://mediatemple.net/) | **Not Vulnerable** | ns1.mediatemple.net\u003cbr\u003ens2.mediatemple.net | [Issue #23](https://github.com/indianajson/can-i-take-over-dns/issues/23)\n[MyDomain](https://mydomain.com/) | **Not Vulnerable** | ns1.mydomain.com\u003cbr\u003ens2.mydomain.com | [Issue #4](https://github.com/indianajson/can-i-take-over-dns/issues/4)\n[Name.com](https://name.com/) | **Vulnerable \u003csub\u003e\u003csup\u003e(w/ purchase)\u003c/sub\u003e\u003c/sup\u003e** | ns1***.name.com\u003cbr\u003ens2***.name.com\u003cbr\u003ens3***.name.com\u003cbr\u003ens4***.name.com | [Issue #8](https://github.com/libertalialtd/can-i-take-over-dns/issues/8)\n[namecheap](https://namecheap.com/) | **Not Vulnerable\u003c/sup\u003e** | \\*.namecheaphosting.com\u003cbr\u003e\\*.registrar-servers.com | \n[Network Solutions](https://networksolutions.com/) | **Not Vulnerable** | ns\\*\\*.worldnic.com | [Issue #15](https://github.com/indianajson/can-i-take-over-dns/issues/15)\n[NS1](https://nsone.net/) | **Registration Closed \u003cbr\u003e\u003csub\u003eI can help, comment on the linked issue.\u003c/sub\u003e** | dns1.p\\*\\*.nsone.net\u003cbr\u003edns2.p\\*\\*.nsone.net\u003cbr\u003edns3.p\\*\\*.nsone.net\u003cbr\u003edns4.p\\*\\*.nsone.net | [Issue #7](https://github.com/indianajson/can-i-take-over-dns/issues/7)\n[TierraNet](https://tierra.net/) | **Vulnerable** | ns1.domaindiscover.com\u003cbr\u003ens2.domaindiscover.com | [Issue #24](https://github.com/indianajson/can-i-take-over-dns/issues/24)\n[Reg.ru](https://reg.ru/) | **Vulnerable \u003csub\u003e\u003csup\u003e\u003cbr\u003e(sanctions may stop payments)\u003c/sub\u003e\u003c/sup\u003e** | ns1.reg.ru\u003cbr\u003ens2.reg.ru | [Issue #28](https://github.com/indianajson/can-i-take-over-dns/issues/28)\n[UltraDNS](https://www.home.neustar/dns-services/ultra-dns) | **Not Vulnerable** | pdns***.ultradns.com\u003cbr\u003eudns***.ultradns.com\u003cbr\u003esdns***.ultradns.com | [Issue #29](https://github.com/indianajson/can-i-take-over-dns/issues/29)\n[Yahoo Small Business](https://yahoosmallbusiness.com/) | **Vulnerable \u003csub\u003e\u003csup\u003e(w/ purchase)\u003c/sub\u003e\u003c/sup\u003e** | yns1.yahoo.com\u003cbr\u003eyns2.yahoo.com | [Issue #20](https://github.com/indianajson/can-i-take-over-dns/issues/20)\n\n\n## Private DNS\n\nThese are private nameservers operated by various companies. The general public cannot create zones on these nameservers and thus takeovers are not possible. Knowning nameservers that are private and not vulnerable can be helpful to eliminate false positives from your testing. \n\nOwner                                        | Status         | Fingerprint                                                             |                                                     \n--------------------------------------------- | -------------- | -----------------------------------------------------------------------  |\n[Activision](https://activision.com/) | **Not Vulnerable** | ns\\*.activision.com | \n[Adobe](https://adobe.com/) | **Not Vulnerable** | adobe-dns-0*.adobe.com | \n[Apple](https://apple.com/) | **Not Vulnerable** | a.ns.apple.com\u003cbr\u003eb.ns.apple.com\u003cbr\u003ec.ns.apple.com\u003cbr\u003ed.ns.apple.com |\n[Automattic](https://automattic.com/) | **Not Vulnerable** | ns*.automattic.com |\n[Capital One](https://capitalone.com/) | **Not Vulnerable** | ns*.capitalone.com | \n[Disney](https://disney.com/) | **Not Vulnerable** | ns*.twdcns.com\u003cbr\u003ens*.twdcns.info\u003cbr\u003ens*.twdcns.co.uk |\n[Google](https://google.com/) | **Not Vulnerable** | ns*.google.com |\n[Lowe's](https://lowes.com/) | **Not Vulnerable** | authns*.lowes.com | \n[T-Mobile](https://tmobileus.com/) | **Not Vulnerable** | ns10.tmobileus.com\u003cbr\u003ens10.tmobileus.net | \n\n\n## What is a DNS takeover?\n\n\u003e DNS takeover vulnerabilities occur when a subdomain (subdomain.example.com) or domain has its authoritative nameserver set to a provider (e.g. AWS Route 53, Akamai, Microsoft Azure, etc.) but the hosted zone has been removed or deleted. Consequently, when making a [request for DNS records](https://www.diggui.com/#type=A\u0026hostname=github.technology\u0026nameserver=public\u0026public=8.8.8.8\u0026specify=\u0026clientsubnet=\u0026tcp=def\u0026transport=def\u0026mapped=def\u0026nssearch=def\u0026trace=def\u0026recurse=def\u0026edns=def\u0026dnssec=def\u0026subnet=def\u0026cookie=def\u0026all=def\u0026cmd=def\u0026question=def\u0026answer=def\u0026authority=def\u0026additional=def\u0026comments=def\u0026stats=def\u0026multiline=def\u0026short=def\u0026colorize=on) the server responds with a `SERVFAIL` error. This allows an attacker to create the missing hosted zone on the service that was being used and thus control all DNS records for that (sub)domain. \u003c!--For example, if subdomain.example.com was pointing to a GitHub page and the user decided to delete their GitHub page, an attacker can now create a GitHub page, add a CNAME file containing subdomain.example.com, and claim subdomain.example.com.--\u003e\n\nYou can read more at: https://0xpatrik.com/subdomain-takeover-ns/\n\nA python implementation of DNS takeovers: https://github.com/pwnesia/dnstake\n\n## Contributions\n\nWe need more DNS providers added to the database with information about their services. \n\nIf you want to help out, please check out the getting started guide [here](https://github.com/indianajson/can-i-take-over-dns/issues/11). \n\n## Press\n\n\u003e\"How does one know whether a DNS provider is exploitable? There is a frequently updated list published on GitHub called “Can I take over DNS,” which has been documenting exploitability by DNS provider over the past several years.\"\u003cbr\u003e[Brian Krebs](https://krebsonsecurity.com/2024/07/dont-let-your-domain-name-become-a-sitting-duck/)\n\n\u003e\"I honestly think this is a great resource for security researchers and bug bounty hunters.\"\u003cbr\u003e\n[@0xpatrik](https://securitytrails.com/blog/blast-radius-dns-takeovers)\n\n\u003e\"A new, but incredibly useful resource.. Essentially, a more modern/accurate can-i-take-over list for the STO you likely don't yet know about\"\u003cbr\u003e\n[Michael Skelton, Director of Security @ BugCrowd](https://mobile.twitter.com/codingo_/status/1406560274518138881)\n\n\u003e \"Still trying to find your first domain/subdomain takeover vulnerability? Go to indianajson/can-i-take-over-dns for a curated DNS takeover list. \"\u003cbr\u003e[Intigriti, Bug Bounty Platform](https://mobile.twitter.com/intigriti/status/1406213934663847937)\n\n\u003e \"There's this excellent resource on GitHub... which has a list of nameservers... that you can perform takeovers on, so I think this is an excellent resource\" \u003cbr\u003e[Shubham Shah, CTO of Assetnote](https://www.youtube.com/live/-vmZOSxdRCE?feature=share\u0026t=324)\n\n\n.\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Findianajson%2Fcan-i-take-over-dns","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Findianajson%2Fcan-i-take-over-dns","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Findianajson%2Fcan-i-take-over-dns/lists"}