August 9, 2026
I Took Over Someone’s Subdomain and Put a Cat On It
Was poking around a wildcard scope, let’s call the target *.l4zz3rj0d.com for this one. Ran subzy against a pile of subdomains to check for…

By L4ZZ3RJ0D
2 min read
Was poking around a wildcard scope, let's call the target *.l4zz3rj0d.com for this one. Ran subzy against a pile of subdomains to check for dangling CNAME takeovers.
Tool came back with eight hosts flagged vulnerable.
Eight. I briefly imagined retiring off this one report.
I did not retire.
Automated scanners are fast, and they're liars. Confidently wrong, but said with total conviction, so you believe them for a solid ten minutes before reality catches up. Six of the eight "vulnerable" hosts were just plain Akamai edge nodes returning a bog-standard 404. No dangling CNAME, no "domain not claimed" page, nothing. A generic empty 404 that some pattern-matcher decided looked close enough to a real signature.
Six false positives, gone, in about ten minutes of dig and curl.
That left two real candidates. One was an Akamai edgekey record, harder to verify, not worth the time that day. The last one, though, that one was actually interesting.
CNAME pointing straight into a third-party cloud CMS platform's shared infrastructure. TLS handshake completed fine, valid cert and everything, except the cert's SAN list didn't actually include the hostname I was requesting. Classic tell.
Bypassed the cert check, looked at the response body, and there it was, a "Web Site Not Found" page with an invitation to add this domain to your account through the platform's own console.
Translation: nobody owns this subdomain anymore.
Whoever set it up moved on, decommissioned the app, migrated environments, whatever happened, and forgot to clean up the DNS record still pointing at it. Anyone with a free account on that platform could've claimed it and served whatever they wanted under a domain that still says l4zz3rj0d.com in the address bar.
Now the part nobody warns you about, proving it isn't just "look, the CNAME dangles, trust me." Programs want an actual claim, a live URL you control, actually serving content, under the target subdomain. So I signed up for the platform's free trial specifically to claim the domain, fought through a signup flow clearly built for enterprise sales leads instead of a five-minute researcher PoC, office phone number, company field, the whole song and dance.
Nothing about bug bounty work is ever as fast as the writeup makes it look.
Once claimed, I put up a page. Because if you're going to briefly own a piece of someone else's domain, you might as well have a little fun with it before tearing it back down.
Screenshot captured, timestamp logged, domain alias removed within minutes. In and out.
Wrote the report properly, DNS chain, cert mismatch, response body, the live claim, all of it. Submitted, sat back, felt pretty good about it.
Marked duplicate. Someone else found the exact same dangling record two days before I did.
Fair enough, honestly. Wildcard scopes get hammered by a lot of researchers running the same handful of tools, and dangling CNAMEs don't hide well once you know where to look.
No bounty, no first-blood credit. Just a very polite "thanks, already reported," and the quiet satisfaction of having actually verified my own findings instead of just trusting a scanner blindly.
What actually mattered here:
Trusting the scanner at face value would've gotten me a report padded with six false positives, a much worse look than showing up two days late to a real one.
A dangling CNAME to a CMS platform, an orphaned edge record, and a live-but-misconfigured API endpoint are three completely different investigations wearing the exact same "VULNERABLE" label. Treat them the same, and false positives end up in your report.
Claiming a domain properly, cleanly and minimally, is more effort than it looks. Half the battle was fighting the platform's own enterprise signup flow, not the actual vulnerability.
Happy hunting. See you in the next scope, hopefully one where I actually beat the clock this time.