P1 Bug Bounties: Subdomain Takeover Bug Hunting

Graham Zemel
The Gray Area
Published in
5 min readJan 4, 2023

--

TL;DR- A guide to subdomain takeover, critical vulnerabilities associated with insecure protections, and its potential for critical bug bounties.

Introduction

A subdomain is a second-level domain that is part of a larger domain. For example, www.grahamzemel.com would be a subdomain of grahamzemel.com. In this case, www would be the subdomain…

--

--