Giter Site home page Giter Site logo

touhidshaikh / subdomaintakeoverlab Goto Github PK

View Code? Open in Web Editor NEW

This project forked from initd-sh/subdomaintakeoverlab

0.0 1.0 2.0 7.16 MB

Subdomain Takeover lab is FREE for everyone. This means here is a legal to takeover Subdomain of this website not my Personal Domain. hehe ;) Here you'll find more than 70 subdomain which is waiting for TAKEOVER. For more visit:

Home Page: https://subdomain-takeover.tk/

License: Mozilla Public License 2.0

CSS 32.34% JavaScript 10.96% PHP 56.70%

subdomaintakeoverlab's Introduction

SubdomainTakeoverLab

SubdomainTakeoverLab

Subdomain takeover vulnerabilities occur when a subdomain (subdomain.example.com) is pointing to a service (e.g. Amazone S3, GitHub pages, Heroku, etc.) that has been removed or deleted. This allows an attacker to set up a page on the service that was being used and point their page to that subdomain. For example, if subdomain.example.com was pointing to a GitHub page and the user decided to delete their GitHub page, an attacker can now create a GitHub page, add a CNAME file containing subdomain.example.com, and claim subdomain.example.com.

Who we are ? (InitD Community)

The name of our community would be initD indicating a daemon process that continues running until the system is shut down. So our community will be the direct or indirect ancestor of all kinds of knowledge that will be shared among us. Our community will include sharing of knowledge through hands-on sessions, Capture the Flags(CTF) and lot more. The main aim of our community is to share an InfoSec Knowledge to all and motivate beginners to build something. It may include any open source project such as application, website etc.

Lab Details

Subdomain Takeover lab is FREE for everyone. This means here is a legal to takeover Subdomain of this website not my Personal Domain. hehe ;) Here you'll find more than 70 subdomain which is waiting for TAKEOVER ๐Ÿ˜‰

Links

Subdomain Takeover Article

Practice Lab

How To Play

  • Find Your Target Subdomain.
  • Claim Your Subdomain and Generate Unique Value. This will use as a filename in further step.
  • Once You Takeover the subdomain. Make a txt file with previous generated value as a Filename and file content must be your E-Mail only.
  • Command Example:
echo "[email protected]" > d1282ee66b41e66645be96937b3d6a03.txt
  • Host this file d1282ee66b41e66645be96937b3d6a03.txt on root of subdomain.
  • Let's Verify your Sudomain.
  • Done!!.

List Of Vulnerable Services

  • AWS/S3.
  • Github Page
  • Heroku
  • Tumblr
  • Tilda and etc.

Author

See also the list of contributors who participated in this project.

Bugs Reports

If You Find any Bugs, Errors and Misconfiguration. Please report on InitD Bugs.

License

This project is licensed under the Mozilla Public License 2.0 License - see the LICENSE.md file for details

Thank You Guys!

Shrutirupa, Hina, [Sachin], [Sagar]

subdomaintakeoverlab's People

Contributors

touhidshaikh avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.