Blog | G5 Cyber Security

Researchers Hijack Over 2,000 Subdomains From Legitimate Sites in CloudFront Experiment

Security experts have hijacked over 2,000 subdomains from legitimate websites while researching possible security flaws in Amazon’s CloudFront CDN service. Experts found that CloudFront’s CDN routing mechanism that linked a site’s domain to a specific server contained a flaw that allowed attackers to point misconfigured subdomain to their own endpoint instead. Some of the most high-profile subDOMains belonged to companies such as the Red Cross, Bloomberg, Reuters, Dow Jones, Harvard, Harvard and University of Maryland.

Source: https://www.bleepingcomputer.com/news/security/researchers-hijack-over-2-000-subdomains-from-legitimate-sites-in-cloudfront-experiment/

Exit mobile version