haccer / subjack

Subdomain Takeover tool written in Go
Apache License 2.0
1.91k stars 337 forks source link

Heroku fingerprint gives false positives #32

Open BBerastegui opened 5 years ago

BBerastegui commented 5 years ago

As seen here: https://github.com/EdOverflow/can-i-take-over-xyz/issues/38

The Heroku detection needs extra checks apart from the one provided in the fingerprints file.

Now it's giving false positives in cases where the domain is .herokuapp.com.

Rhynorater commented 5 years ago

I also experienced this with herokudns.com. Sometimes it would find it and sometimes it would not. It could also not find domains that were domain -> Cloudfront/Cloudflare -> heroku. Even with the -a parameter.