Skip to content

Ward opens soon: join the waitlist and we'll email you the day we open.

What Ward checks

Area: Exposed infrastructure

Subdomains

Subdomains that appear in public certificate logs (Cert Spotter, with crt.sh as a backup), possible takeovers and sensitive names. We don't guess names from a dictionary.

What it can report

Open each one to see what it means and how to fix it.

Possible subdomain takeover

What it means

blog.example.com is a name inside your domain that points to ejemplo-blog.herokuapp.com, a Heroku resource, and that destination no longer exists. The pointer is still in your DNS (the internet's address book), but there's nothing behind it.

What could happen

Anyone can create a new resource on Heroku with that same name and your subdomain would show their content, under your name. It is a known way to hijack forgotten subdomains and should be fixed soon.

How an attacker would use it

Someone notices that blog.example.com points to nothing and claims the destination on Heroku. Now a page of theirs appears at your own address, with your name in the web address. They send customers a link to it as a “login” or “invoice” page, and customers trust it because the address is yours.

How to fix it

  1. Decide whether blog.example.com is still in use.Ask your team. It's often a leftover from a finished project, a trial or a former provider.
  2. If it isn't, delete its record (a “CNAME”) in your DNS settings. This is the real fix.
  3. If it is, recreate the destination on Heroku so the pointer leads somewhere you control.
  4. Review your other DNS records that point to outside services and delete those you no longer use.
  5. Make it a habit to delete the DNS record whenever you cancel a service.

How to check it's fixed

Ward looks at the subdomain's record again. Mark the finding as “Pending verification” and Ward will check it again. DNS changes can take a few hours to spread, so if it still shows up, try again later.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Subdomain points to a private address

What it means

Your public DNS (the internet's open address book) lists intranet.example.com with an address that belongs to your internal network. Internal addresses are meant for inside your office or servers, so they shouldn't be published.

What could happen

It doesn't open a door: those addresses can't be reached from the internet. But it tells anyone how your internal network is laid out and what internal names exist. It's a low-severity leak of information.

How an attacker would use it

Someone browsing the public records of your domain sees internal addresses and names, such as where a file server or a camera system sits. If they later get into one computer or the Wi-Fi, they already know where to look next.

How to fix it

  1. Check whether intranet.example.com is still needed.Ask your IT person. It may be left over from a test or an old setup.
  2. If it's not needed, delete its record in your public DNS settings.
  3. If it is needed inside your network, keep it in an internal DNS, not the public one.
  4. Review the rest of your DNS records for other internal addresses.

How to check it's fixed

Ward looks at the subdomain's record again. Mark the finding as “Pending verification” and Ward will check it again. DNS changes can take a few hours to spread, so if it still shows up, try again later.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Subdomain with an internal-looking name

What it means

pruebas.example.com is a public address of your domain whose name suggests an internal use, such as testing, administration, backups or remote access. It responds from the internet, so anyone who knows the name can try it.

What could happen

Systems like these are often less protected than your main website, with weaker passwords, older software or real data copied into them. That's why they attract attackers. If it must be public, it needs the same care as your main site.

How an attacker would use it

Someone looking for a side door doesn't try your well-kept main site but a forgotten test copy of it. It has an easy password, old software and real customer data left in it, and they get into the company through it.

How to fix it

  1. Decide whether pruebas.example.com needs to be reachable from the internet.
  2. If it doesn't, take it offline or restrict access to your company's network, a VPN or a short list of approved addresses.
  3. If it does, protect it with strong passwords and two-step verification, and keep its software updated.
  4. Remove real customer data from test copies and delete old copies and backups left online.
  5. Make sure the software behind it is the current version.

How to check it's fixed

Ward checks again whether the address responds. Mark the finding as “Pending verification” and Ward will check it again. DNS changes can take a few hours to spread, so if it still shows up, try again later.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.