Dangling DNS record for bastion.certb.cdp.bethesda.net
Full Disclosuremailing list archivesFrom: shed riot <shed.riot () gmail com>Da 2026-8-6 19:40:4 Author: seclists.org(查看原文) 阅读量:6 收藏

fulldisclosure logo

Full Disclosure mailing list archives


From: shed riot <shed.riot () gmail com>
Date: Fri, 24 Jul 2026 10:43:16 +0100

# Summary

The hostname resolved to an address within a dynamic cloud IP pool.
The address had been released and was no longer controlled by the
organisation operating the hostname.

This condition is referred to as an "afterlife" issue.

Unlike a conventional CNAME-based subdomain takeover, the DNS record
pointed directly to a reusable cloud IP address. An attacker obtaining
that address could receive traffic intended for the Microsoft-owned
hostname and serve content from it.

I reported the issue to the Microsoft Security Response Center as:
VULN-198489

MSRC closed the report as a non-MSRC case, because the IP address was
not in Azure. Doh.


# Vulnerability

Persistent dangling DNS record to a reusable cloud IP address.
CWE-16: Configuration


# Impact

Impact includes:

* obtaining trusted TLS certificates for the affected hostname;
* serving attacker-controlled content from a trusted hostname;
* receiving traffic intended for the previous service;
* exposure of cookies, bearer tokens or session identifiers;
* exposure of request bodies, API keys or webhook payloads;
* abuse of CORS, OAuth or other domain-based allowlists;
* abuse of same-site cookie and browser trust relationships; and
* phishing or malware hosted under the organisation's domain.


## Proof of Concept (PoC)

1. open a browser and navigate to
   `https://bastion.certb.cdp.bethesda.net`
2. an `afterlife` holding page will be served from the affected
   hostname
3. observe that the browser reports a valid trusted TLS certificate
   for the affected hostname
4. navigate to `https://crt.sh/?q=bastion.certb.cdp.bethesda.net`
   and observe that a new Let's Encrypt certificate has been issued
   (may require a few refreshes as over-subscribed)
5. navigate to `https://bethesda.net/` and login (create an account
   if required)
6. navigate to `https://bastion.certb.cdp.bethesda.net/request.txt`
   and observe that the full request is displayed, along with the
   domain scoped cookies that were received


# Vendor response and timeline

30 June 2026

I submitted the report as VULN-198489.

The portal did not assign an MSRC case number. The recorded status was
"Complete - NA".

MSRC's rejected the issue as outside MSRC's scope, because the IP was
not in Azure.


# References

* MSRC submission VULN-198489
* CWE-16: Configuration
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/


Current thread:

  • Dangling DNS record for bastion.certb.cdp.bethesda.net shed riot (Aug 06)

文章来源: https://seclists.org/fulldisclosure/2026/Aug/35
如有侵权请联系:admin#unsafe.sh