Skip to content

Latest commit

 

History

History
14 lines (11 loc) · 787 Bytes

cloud-aws-cloudfront.md

File metadata and controls

14 lines (11 loc) · 787 Bytes

INFO

Cloudfront is a CDN and it checks the HOST header in CNAMES, so:

  • The domain "test.disloops.com" is a CNAME record that points to "disloops.com".
  • The "disloops.com" domain is set up to use a CloudFront distribution.
  • Because "test.disloops.com" was not added to the "Alternate Domain Names (CNAMEs)" field for the distribution, requests to "test.disloops.com" will fail.
  • Another user can create a CloudFront distribution and add "test.disloops.com" to the "Alternate Domain Names (CNAMEs)" field to hijack the domain.

TOOLS

git clone --recursive https://github.com/MindPointGroup/cloudfrunt pip install -r requirements.txt python cloudfrunt.py -o cloudfrunt.com.s3-website-us-east-1.amazonaws.com -i S3-cloudfrunt -l list.txt