Web Security Series
Web security lessons for DNS, subdomain takeover, certificate transparency, storage exposure, and OWASP risk.
3 chapters · about 86 min end to end
- Subdomain Takeover — How a Deleted S3 Bucket Let a Stranger Serve a Scam on My DomainA real, redacted incident: a static site was moved off AWS, the old S3 bucket was deleted, but the DNS record pointing at it was left behind. A stranger re-created a bucket with the same name and started serving a gambling scam at the real domain. The full anatomy of a dangling-DNS subdomain takeover — why deleted bucket names are a loaded gun, the AI-agent migration mistake that opened the door, how to put the fire out, and the pre-flight checklist that stops it ever happening.Intermediate · 26 min
- Is My Domain Hacked? The Field Guide — Investigate a Suspected Takeover, Then Audit Every Domain You OwnThe hands-on companion to Chapter 1's takeover story. The exact outside-in method I used to prove my hijacked domain was a misconfiguration, not an account breach — whois/RDAP, dig against an external resolver (and the VPN fake-IP trap that fools you), reading HTTP headers to fingerprint the backend, and the single decision that separates 'misconfigured' from 'compromised.' Then the full map of every dangling-pointer variant — cloud buckets, PaaS, SaaS CNAMEs, recycled IPs, NS delegation, expired domains, email spoofing, registrar hijack — and the 15-minute quarterly audit, with a copy-paste Cloudflare sweep, that finds them on every domain you own before a scanner does.Intermediate · 28 min
- How Logins Get Broken — Credential Stuffing, Session Hijacking, and the Auth Defenses That Actually HoldAuthentication is where most apps quietly leak. This chapter walks the real attack surface of a login system end to end — how passwords get cracked when storage is wrong, how credential stuffing turns someone else's breach into your incident, how sessions get stolen via XSS, CSRF, and fixation, and where OAuth and password-reset flows go sideways. Then it builds the defenses that genuinely hold: correct slow hashing, breached-password checks, rate limiting that targets the account not the IP, hardened session cookies (HttpOnly + Secure + SameSite), token rotation, and a TOTP second factor — all framed against the hand-built Cloudflare Worker auth from the Web series.Intermediate · 32 min