Deep WebThreat Intelligence

Attack Surface Discovery: We Found 47 Forgotten Subdomains — 12 Were Vulnerable

May 25, 2025
Outcome

47 unknown subdomains discovered; 12 critical vulnerabilities identified; 3 shadow IT systems decommissioned.

Background

A regional bank's IT team believed they held a comprehensive inventory of their external-facing assets. Like many institutions that have grown through acquisitions, vendor pilots, and years of departmental projects, their real footprint had quietly outpaced their documentation. As part of an annual security assessment, they engaged TraxIntel for an authorized external attack surface audit built entirely from publicly available sources. The goal was straightforward but consequential: reconcile what the bank believed it exposed to the internet against what an outside observer could actually see. For a financial institution, an undocumented asset is not just untidy record-keeping; it is a control gap that governance, audit, and incident-response processes never account for.

Investigation Methodology

  1. Scope and authorization. Before any collection began, we confirmed the engagement was owner-authorized and limited to the bank's own domains, so every step operated within the client's permission and applicable law.
  2. Passive DNS enumeration. We mapped subdomains using passive DNS aggregators, certificate transparency logs, and historical DNS records — all public reference sources that reveal names an organization has published over time without touching the bank's infrastructure.
  3. Corporate and registration review. Domain registration records and related corporate filings helped us attribute assets to the correct legal entities and separate genuine bank property from lookalike or third-party domains.
  4. Passive service observation. For each confirmed asset we reviewed publicly returned service banners, software version strings, and exposed configuration details as presented to any ordinary visitor, rather than probing beyond what the systems already advertised.
  5. Vulnerability referencing. Observed software versions were cross-referenced against published vulnerability databases to flag components with known, documented weaknesses. This is a review-and-flag step: it identifies plausible risk for the client's team to validate internally, not proof of exploitability.

Key Findings

The public-source review surfaced material the bank's inventory did not:

  • 47 subdomains were identified that did not appear in the asset inventory — remnants of old projects, decommissioned test environments, and shadow IT deployments stood up outside the IT process.
  • 12 of these carried components matching known, documented vulnerabilities: outdated WordPress installations, exposed administrative panels, and unpatched web servers publicly advertising affected versions.
  • 3 subdomains pointed to unauthorized SaaS platforms that individual departments had provisioned without IT approval.
  • One subdomain resolved to a forgotten development environment that, by its public responses, appeared to expose a 2022 copy of production customer data — a finding we escalated immediately for the client to confirm and contain.

Evidence and Sources

Every conclusion rested on publicly observable evidence: certificate transparency entries, passive DNS history, registration records, and the service and version information the assets themselves returned. Where a single source was ambiguous, we corroborated across at least two independent public references before treating an asset as confirmed bank property. Vulnerability flags were tied to specific published advisories rather than general impressions, so the client's engineers could trace each item back to a named source and reproduce our reasoning. Screenshots, response headers, and timestamped records of each observation were preserved so the findings would remain auditable after the engagement closed.

Limitations and Review Notes

This review reflects what was publicly discoverable during a defined window; public records lag reality, so newly created or recently removed assets may not be represented, and a later scan could differ. Version-based flags indicate exposure to known issues, not confirmed compromise or a demonstrated breach — establishing actual impact requires the client's authenticated internal validation. Public-source discovery cannot see purely internal systems, nor can it prove intent behind any deployment. Because attribution and severity judgments are probabilistic, a human analyst reviewed each finding to filter false positives, weigh corroboration, and prioritize genuinely bank-owned exposure over noise.

Outcome

All 47 subdomains were cataloged and triaged. The 12 vulnerable systems were patched or decommissioned within 72 hours, and the exposed development database was secured and wiped once the bank verified it. Three shadow IT systems were formally decommissioned. Beyond the immediate fixes, the audit informed a broader decision: the bank folded continuous external discovery into its asset-governance program so that undocumented exposure would be caught on a schedule rather than once a year. Total investigation time: 1 week.