All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

How a wildcard DNS record on GitHub Pages allowed strangers to create scam subdomains on my domain

By

rmeertens

13d ago· 5 min readenInsight

Summary

A developer traveling in Africa discovers that a wildcard DNS record pointing to GitHub Pages allowed strangers to create scam subdomains (like kafka.immersivepoints.com) under his personal domain without his knowledge. The article details how GitHub Pages' subdomain handling combined with wildcard DNS configurations creates a security loophole where anyone can claim subdomains on someone else's domain, leading to potential abuse for phishing and scams.

Key quotes

· 3 pulled
My immersivepoints.com domain is only used for one website hosted as a GitHub page.
There definitely is no Kafka involved here, let alone that I knew the new owner of this subdomain.
How a wildcard DNS record pointing at GitHub Pages let strangers spin up scam subdomains on my own domain — and what should change.
Snippet from the RSS feed
How a wildcard DNS record pointing at GitHub Pages let strangers spin up scam subdomains on my own domain — and what should change.

You might also wanna read