Obtaining a subdomain is an attack in which an attacker has complete control over the subdomain. This happens when the provider deletes the web content on the domain but forgets to delete the DNS record.
This error could allow an attacker to gain control of a subdomain, which could allow an attacker to perform any type of attack using that subdomain, including phishing and mapping.
To find out which subdomain is easier to control, you need some tools to find that particular subdomain. That way, you can prevent such attacks. Here are some tools to help you identify subdomains that are easy to adopt.
This will help you find that subdomain. These tools are free to use and display results in less than a minute.
Here are some tools to takover subdomains -
1) subzy
Link - https://github.com/LukaSikic/subzy
2) SubOver
SubOver is likewise a Go language based tool. It can undoubtedly identify and report vulnerable subdomain that can easily takeover.
Link - https://github.com/Ice3man543/SubOver
3) takeover
takeover is a Python based tool which recognize a subdomain which is not difficult to takeover.
Link - https://github.com/m4ll0k/takeover
4) subdomain-takeover
This tool also a python based which helps you to find which subdomain is ready to takeover.
Link - https://github.com/antichown/subdomain-takeover
5) subdover
Subdover is a MultiThreaded Subdomain Takeover Vulnerability Scanner Written In Python3, Which has more than 70+ Fingerprints of potentially vulnerable services. Uses CNAME record for verification of findings.
Link - https://github.com/PushpenderIndia/subdover
If you have any query, please comment below.
Also read -
How to do phishing attacks in termux using SocialFish
How to create metasploit payload easily in linux & termux
0 comments:
Post a Comment
If you have any problem regrading this post, leave a comment !