devleague / steam-team

Bug Bounty Team Collaboration for Hacker0x01 Steam Program
1 stars 1 forks source link

dota2.com #3

Open CarrotShaver opened 6 years ago

NicklausPark commented 6 years ago

used burp suite to crawl hostname to give a list of all subdomains and other pages linked from dota2.com

http://blog.dota2.com http://cdn.dota2.com <--- seems like they are pulling javascript from here and its unsecure http://dota2.com https://help.steampowered.com https://steamcommunity-a-akamaihd.net http://steamcommunity-a-akamaihd.net http://steamcommunity.com https://steamcommunity.com https://store.steampowered.com http://store.steampowered.com http://translation.steampowered.com http://www.valvesoftware.com

NicklausPark commented 6 years ago

// Hostname IP output from theharvester .beta.dota2.com : empty .dota2.com : empty beta.dota2.com : empty blog.dota2.com : 107.20.138.179 br.dota2.com : 107.20.138.179 cdn.dota2.com : 209.107.207.98 cn.dota2.com : 107.20.138.179 dac.dota2.com : empty de.dota2.com : 107.20.138.179 dev.dota2.com : 104.130.118.64 en.dota2.com : 107.20.138.179 es.dota2.com : 107.20.138.179 fr.dota2.com : 107.20.138.179 kr.dota2.com : 107.20.138.179 members.dota2.com : empty partner.dota2.com : 23.11.245.109 partner.staging.dota2.com : empty ru.dota2.com : 107.20.138.179 www.dota2.com : 192.16.31.139 www.staging.dota2.com : empty