Route53 and CloudFront Enumeration
Route53
List Hosted Zones
Private zones are only resolvable within the associated VPC — they expose internal hostnames.
List All DNS Records
CNAME records pointing to AWS services (S3, Elastic Beanstalk, CloudFront) may be dangling takeover candidates. See S3 Bucket Discovery.
Private Zone Records
Private zones reveal internal service names, database hostnames, internal load balancers, and microservice endpoints:
Health Checks
Route53 health checks reveal which endpoints are being monitored and their status:
CloudFront
List Distributions
Get Distribution Config
Full config including origins, behaviours, WAF associations, and geo-restrictions:
Origin domain names may reveal:
S3 bucket names (potential public access if misconfigured)
Internal ALB DNS names (reachable directly if security groups allow it)
EC2 instance public DNS
Origin Access Control / Identity
Check if S3 origins are protected by an OAC or OAI (restricts direct S3 access):
If OriginAccessIdentity is empty and the S3 bucket has no separate restriction, the bucket may be accessible directly.
Cache Policies and Functions
CloudFront Functions run at the edge and may contain business logic, auth checks, or token validation — worth reviewing for bypasses.
Was this helpful?
Your feedback helps improve this page.