跳到主要内容

子域名接管

前言

国内的子域名接管漏洞比较少

今天遇到一个pagewiz的网站疑似存在子域名接管,然后去尝试了一下,失败了,所以觉得还是有必要先占个位,等以后遇到成功案例再写

image-20220225210723879

核心

copy自:https://github.com/EdOverflow/can-i-take-over-xyz

EngineStatusFingerprintDiscussionDocumentation
AcquiaNot vulnerableWeb Site Not FoundIssue #103
Agile CRMVulnerableSorry, this page is no longer available.Issue #145
Airee.ruVulnerableIssue #104
AnimaVulnerableIf this is your website and you've just created it, try refreshing in a minuteIssue #126Anima Documentation
AkamaiNot vulnerableIssue #13
AWS/S3VulnerableThe specified bucket does not existIssue #36
AWS/Load Balancer (ELB)Not Vulnerablestatus NXDOMAIN and CNAME pointing to XYZ.elb.amazonaws.comIssue #137
BitbucketVulnerableRepository not found
Campaign MonitorVulnerableTrying to access your account?Support Page
Cargo CollectiveVulnerable404 Not FoundIssue #152Cargo Support Page
CloudfrontNot vulnerableViewerCertificateExceptionIssue #29Domain Security on Amazon CloudFront
DeskNot vulnerablePlease try again or try Desk.com free for 14 days.Issue #9
Digital OceanVulnerableDomain uses DO name serves with no records in DO.
DiscourseVulnerableHackerone
FastlyEdge caseFastly error: unknown domain:Issue #22
FeedpressNot vulnerableThe feed has not been found.Issue #80
FirebaseNot vulnerableIssue #128
Fly.ioVulnerable404 Not FoundIssue #101
FreshdeskNot vulnerableWe couldn't find servicedesk.victim.tld Maybe this is still fresh! You can claim it now at http://www.freshservice.com/signupIssue #214Freshdesk Support Page
GemfuryVulnerable404: This page could not be found.Issue #154Article
GhostVulnerableThe thing you were looking for is no longer here, or never was
GithubVulnerableThere isn't a GitHub Pages site here.Issue #37 Issue #68
GitlabNot vulnerableHackerOne #312118
Google Cloud StorageNot vulnerableNoSuchBucketThe specified bucket does not exist.
HatenaBlogvulnerable404 Blog is not found
Help JuiceVulnerableWe could not find what you're looking for.Help Juice Support Page
Help ScoutVulnerableNo settings were found for this company:HelpScout Docs
HerokuEdge caseNo such appIssue #38
HubSpotNot vulnerableThis page isn’t available
InstapageNot vulnerableIssue #73
IntercomVulnerableUh oh. That page doesn't exist.Issue #69Help center
JetBrainsVulnerableis not a registered InCloud YouTrackYouTrack InCloud Help Page
Key CDNNot vulnerableIssue #112
KinstaVulnerableNo Site For DomainIssue #48kinsta-add-domain
LandingiEdge caseIt looks like you’re lost...Issue #117
LaunchRockVulnerableIt looks like you may have taken a wrong turn somewhere. Don't worry...it happens to all of us.Issue #74
MasheryEdge CaseUnrecognized domainHackerOne #275714, Issue #14
Microsoft AzureVulnerableIssue #35
NetlifyEdge CaseNot Found - Request ID:Issue #40
NgrokVulnerableTunnel *.ngrok.io not foundIssue #92Ngrok Documentation
PantheonVulnerable404 error unknown site!Issue #24Pantheon-Sub-takeover
PingdomVulnerableSorry, couldn't find the status pageIssue #144Support Page
Readme.ioVulnerableProject doesnt exist... yet!Issue #41
SendgridNot vulnerable
ShopifyEdge CaseSorry, this shop is currently unavailable.Issue #32, Issue #46Medium Article
Short.ioVulnerableLink does not existIssue #260
SmartJobBoardVulnerableThis job board website is either expired or its domain name is invalid.Issue #139Support Page
SmartlingEdge CaseDomain is not configuredIssue #67
SquarespaceNot vulnerable
StatuspageNot VulnerableStatus page pushed a DNS verification in order to prevent malicious takeovers what they mentioned in This DocPR #105 and PR #171Statuspage documentation
StrikinglyVulnerablepage not foundIssue #58Strikingly-Sub-takeover
Surge.shVulnerableproject not foundSurge Documentation
TumblrVulnerableWhatever you were looking for doesn't currently exist at this addressIssue #240Tumblr Custom Domains
TildaEdge CasePlease renew your subscriptionIssue #155PR #20
UberflipVulnerableNon-hub domain, The URL you've accessed does not provide a hub.Issue #150Uberflip Documentation
UnbounceNot VulnerableThe requested URL was not found on this server.Issue #11
UptimerobotVulnerablepage not foundIssue #45Uptimerobot-Sub-takeover
UserVoiceVulnerableThis UserVoice subdomain is currently available!
WebflowEdge CaseThe page you are looking for doesn't exist or has been moved.Issue #44forum webflow
WixEdge CaseLooks Like This Domain Isn't Connected To A Website Yet!Issue #231
WordpressVulnerableDo you want to register *.wordpress.com?
WorksitesVulnerableHello! Sorry, but the website you’re looking for doesn’t exist.Issue #142
WP EngineNot vulnerable
ZendeskNot vulnerableHelp Center ClosedIssue #23Zendesk Support

参考