Abandoned subdomains pose security risk for businesses

Many companies set up subdomains for use with external services, but then forget to disable them when they stop using those services, creating a loophole for attackers to exploit.

Because many service providers don’t properly validate the ownership of subdomains pointed at their servers, attackers can set up new accounts and abuse subdomains forgotten by companies by claiming them as their own.

Removing or updating DNS entries for subdomains that are no longer actively used sounds like something that should be common procedure, but according to researchers from Detectify, a Stockholm-based provider of website security scanning services, this type of oversight is actually quite widespread among companies.

To read this article in full or to leave a comment, please click here

Read more: Abandoned subdomains pose security risk for businesses

Story added 23. October 2014, content source with full text you can find at link above.