Subdomain takeover due to an unclaimed Amazon S3 bucket
Program: U.S. Dept Of Defense
Bug Type: subdomain takeover
Bounty: Unspecified
Date: 2020-07-08
subdomain-takeover
awsamazon
s3-bucket
Summary
The researcher came across a subdomain owned by the US dept. of defense that was an amazon S3 bucket in US-EAST region that no longer existed. The researcher was able to claim the s3 bucket, successfully taking over the subdomain.