Step 1
[RECON]
Queried NS records — dig NS tvshare.lge.com → NS entries exist in corporate DNS
Step 2
[VERIFY]
Queried NS directly — SERVFAIL / no response → NS does not recognize this domain
Step 3
[CRIT]
NS mismatch confirmed — Route 53 hosted zone no longer exists
Step 4
[EXPLOIT]
Created new Route 53 hosted zone for tvshare.lge.com — succeeded without restriction
Step 5
[CRIT]
NS values matched corporate DNS entry — full DNS control acquired
Step 6
[DEPLOY]
A record pointed to attacker-controlled EC2 — web server deployed
Step 7
[DONE]
TLS certificate issued via Let's Encrypt — HTTPS active on hijacked subdomain