blacklanternsecurity / baddns

Check subdomains for subdomain takeovers and other DNS tomfoolery
GNU General Public License v3.0
96 stars 5 forks source link

[SignatureBot] Add or update signature nucleitemplates_kinsta-takeover.yml #333

Closed liquidsec closed 9 months ago

liquidsec commented 1 year ago

Add or update signature: nucleitemplates_kinsta-takeover.yml

This PR adds or updates the follow signature:

identifiers:
  cnames: []
  ips: []
  nameservers: []
  not_cnames: []
matcher_rule:
  matchers:
  - dsl:
    - Host != ip
    type: dsl
  - condition: and
    part: body
    type: word
    words:
    - No Site For Domain
  matchers-condition: and
mode: http
service_name: kinsta takeover detection
source: nucleitemplates
liquidsec commented 1 year ago

Test results:

Signature Pass: true :heavy_check_mark:

liquidsec commented 1 year ago

too generic without cname, needs research

liquidsec commented 9 months ago

Reportedly this is no longer possible. Also, the string is too common and no cname seems to be available.