Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Review and update subdomain takeover content #1145

Open
1 task done
coj337 opened this issue Jun 16, 2024 · 0 comments
Open
1 task done

Review and update subdomain takeover content #1145

coj337 opened this issue Jun 16, 2024 · 0 comments
Assignees
Labels
enhancement A new or improved feature for the WSTG or repo revise Needs quality review, updates, or revision

Comments

@coj337
Copy link

coj337 commented Jun 16, 2024

What would you like added?
The subdomain takeover guide is a bit dated and focuses on manually reviewing for takeovers. Testers validate manually but test automatically due to the wide variety of fingerprints and the error-prone nature of manual validation for takeovers.

I think the guide should be updated to focus on the typical workflow and the current state of tooling.

The typical workflow is along the lines of:

  1. Subdomain enumeration
  2. Detection via (open-source) tools
  3. Validation (since it's a false-positive prone process)

There are also quite a few tools, many unmaintained and most miss a lot of instances. Here's an engineering post analyzing existing tools while developing a new one.

This would require a relatively major rewrite of the page but I'm happy to help. Opinions welcome!

Would you like to be assigned to this issue?

  • Assign me, please!
@coj337 coj337 added help wanted new New content to write labels Jun 16, 2024
@kingthorin kingthorin added enhancement A new or improved feature for the WSTG or repo revise Needs quality review, updates, or revision and removed help wanted new New content to write labels Jun 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement A new or improved feature for the WSTG or repo revise Needs quality review, updates, or revision
Projects
None yet
Development

No branches or pull requests

2 participants