PushpenderIndia / subdover

Subdover is a MultiThreaded Subdomain Takeover Vulnerability Scanner Written In Python3
99 stars 34 forks source link

fingerprint addition needed #2

Closed GDATTACKER-RESEARCHER closed 3 years ago

GDATTACKER-RESEARCHER commented 4 years ago

can you update these fingerprints sir.

https://github.com/EdOverflow/can-i-take-over-xyz/issues/160

https://github.com/EdOverflow/can-i-take-over-xyz/issues/166

https://github.com/EdOverflow/can-i-take-over-xyz/issues/142

https://github.com/EdOverflow/can-i-take-over-xyz/issues/145

https://github.com/EdOverflow/can-i-take-over-xyz/issues/147

https://github.com/EdOverflow/can-i-take-over-xyz/issues/150

PushpenderIndia commented 4 years ago

Thanks for requesting to add these fingerprints!

Can you confirm, whether these fingerprints and there CNAME values are correct or not !

Item Order In Fingerprint Lists is :

f57 = [
        "ReadTheDocs.org",
        "Vulnerable",
        ["readthedocs.io"],
        "is unknown to Read the Docs"
    ] 

f58 = [
        "LeadPages.com",
        "Vulnerable",
        ["custom-proxy.leadpages.net", "leadpages.net"],
        "Double check that you have the right web address and give it another go!</p>"
    ] 

f59 = [
        "Worksites.net",
        "Vulnerable",
        ["NOT_AVAILABLE"],
        "Hello! Sorry, but the website you&rsquo;re looking for doesn&rsquo;t exist."
        ## A Record IP ==> 69.164.223.206
    ] 

f60 = [
        "AgileCRM",
        "Vulnerable",
        ["cname.agilecrm.com", "agilecrm.com"],
        "Sorry, this page is no longer available."
    ] 

f61 = [
        "ElasticBeanstalk_AWS_service",
        "Vulnerable",
        ["elasticbeanstalk.com"],
        "" #No Fingerprint Available
    ] 

f62 = [
        "Uberflip",
        "Vulnerable",
        ["read.uberflip.com", "uberflip.com"],
        "Non-hub domain, The URL you've accessed does not provide a hub. Please check the URL and try again."
    ] 
GDATTACKER-RESEARCHER commented 4 years ago

1) bro can you provide a update command for the script directly. 2) i am not sure about vulnerable cname entry required for vulnerable leadpages entries. 3) can you update the serials of service fingerprint in fingerprints.py. 4) bro many services are still not added you can find those in can i takeover xyz issues list.

PushpenderIndia commented 4 years ago

Yes for sure! I will soon add this update feature, whenever i will be free.

And are you talking about rearranging newly added fingerprints in ascending order ?

If yes then it is also on the way. Little bit busy due to personal work.

And could you please do a favor, by searching those unknown fingerprints, from the issue section.

Just start a new issue or post the new fingerprints in this issue only.

Required Things :

  1. Engine
  2. Status (Vulnerable/Not Vulnerable/Edge Case)
  3. CNAME record value List
  4. Fingerprint

On Fri, 4 Sep, 2020, 8:16 PM The Mysterious Cyber Warriors, < notifications@github.com> wrote:

  1. bro can you provide a update command for the script directly.
  2. i am not sure about vulnerable cname entry required for vulnerable leadpages entries.
  3. can you update the serials of service fingerprint in fingerprints.py.
  4. bro many services are still not added you can find those in can i takeover xyz issues list.

— You are receiving this because you commented. Reply to this email directly, view it on GitHub https://github.com/PushpenderIndia/subdover/issues/2#issuecomment-687192739, or unsubscribe https://github.com/notifications/unsubscribe-auth/ANORYIQUW6WAX2VG4OIFKN3SED4V5ANCNFSM4QUM2HVA .

GDATTACKER-RESEARCHER commented 4 years ago

1) microsoft azure takeover need more cname entries to be added in fingerprint file.

https://github.com/EdOverflow/can-i-take-over-xyz/issues/35

2) kinsta takeover need to be added https://github.com/EdOverflow/can-i-take-over-xyz/issues/48

3)animaapp takeover need to be added https://github.com/EdOverflow/can-i-take-over-xyz/issues/126

4) frontify takeover need to be added https://github.com/EdOverflow/can-i-take-over-xyz/issues/122

5) landingi https://github.com/EdOverflow/can-i-take-over-xyz/issues/117

6) Helprace https://github.com/EdOverflow/can-i-take-over-xyz/issues/115

7) canny https://github.com/EdOverflow/can-i-take-over-xyz/issues/114

8) airee https://github.com/EdOverflow/can-i-take-over-xyz/issues/104

9) ngrok takeover https://github.com/EdOverflow/can-i-take-over-xyz/issues/92

10) launchrock takeover https://github.com/EdOverflow/can-i-take-over-xyz/issues/74

11) Bigcartel https://github.com/EdOverflow/can-i-take-over-xyz/issues/158

PushpenderIndia commented 4 years ago

Bigcartel's Fingerprints are already added

I'm unable to find CNAME of Kinsta & Anima & also Kinsta's fingerprints are not available. Please try to find it and post it here.

And I think Kinsta's Subdomain Takeover is a Edge Case.

Please Verify whether, these info are correct or not, Upper Lower case could also leads to false positive.

Kinsta
Edge Case
[""]
""
# Here is the response from kinsta for orphan CNAME.
# 404 Not Found
# Content-Length=[33604]
# Server = kinsta-nginx

Anima
Vulnerable
[""]
"Missing Website"
"If this is your website and you've just created it, try refreshing in a minute"
# A record : 35.164.217.247

Frontify
Vulnerable
["frontify.com"]
"404 - Page not found. Oops... look like you got lost."

Landingi
Vulnerable
["cname.landingi.com"]
A Record : 174.129.25.170
"<h1>It looks like you’re lost...</h1>"
"<p>The page you are looking for is not found.</p>"

Helprace
Vulnerable
["helprace.com"]
"Alias not configured!"
"Admin of this Helprace account needs to set up domain alias"

Canny.io
Vulnerable
["cname.canny.io"]
"Company Not Found"
"There is no such company. Did you enter the right URL?"

Airee.ru 
Vulnerable
["cdn.airee.com", "airee.com"]
"Ошибка 402. Сервис Айри.рф не оплачен"
"Сайт xyz.xyz.ru. , на который вы заходите, не оплатил сервис Айри.рф. Доступ к сайту временно невозможен."

Ngrok
Vulnerable
["ngrok.io"]
"ngrok.io not found"

LaunchRock
Vulnerable
["launchrock.com"]
"It looks like you may have taken a wrong turn somewhere. Don't worry...it happens to all of us."
A Record :
54.243.190.28
54.243.190.39
54.243.190.47
54.243.190.54

I will also, soon going to add Header & A record Check,

& Auto Update feature is on the way : )