logo

Database

Aws Transfer Lock Disabled

Description

Detects AWS Route53 registered domains that have domain transfer lock disabled. Domain transfer lock is a critical security control that prevents unauthorized transfers of domains to other registrars. Domains without transfer lock enabled are vulnerable to domain hijacking attempts.

Weakness:

165 - Insecure service configuration - AWS

Category: Functionality Abuse

Detection Strategy

    Scans all domains registered through AWS Route53 in the account

    Checks if the domain's StatusList includes the 'clientTransferProhibited' flag

    Reports a vulnerability if the transfer lock protection flag is not present for any domain

    Each vulnerable domain is reported individually with its domain name and status information

Severity v4.0

1.3

Low

Method ID

CSPM-ENR65

Technique

CSPM

Target

AWS

Technology

ROUTE53

CWE ID(s)

CWE-306