haccer / subjack

Subdomain Takeover tool written in Go
Apache License 2.0
1.91k stars 337 forks source link

Cloudfront now requires additional checks #33

Closed Rhynorater closed 5 years ago

Rhynorater commented 5 years ago

When trying to find a Cloudfront takeover, it is now required that you resolve the domain, find any CNAMEs that it might be pointing to, then resolve those CNAMEs. If those point to Cloudfront and you've got the Cloudfront error, then you've got a takeover. Otherwise, it is invalid. See Can-I-Takeover-XYZ Cloudfront.

haccer commented 5 years ago

From what I understand, CloudFront takeovers are no longer possible so I will be closing this and removing it as a fingerprint.