
Ferramenta de força bruta de subdomínios que enumera subdomínios existentes e detecta subdomínios mal configurados hospedados na nuvem, vulneráveis a takeover em AWS, GitHub, Heroku, Shopify, Tumblr e Squarespace.
Esta aplicação fará brute force para subdomínios existentes e fornecerá as seguintes informações:
Pode haver alguns falsos positivos dependendo das configurações do host. (Tentei eliminá-los o máximo possível) Também funciona recursivamente no final para obter os subdomínios abaixo dos que já encontrou e despeja todos os dados num ficheiro output.txt como precaução (um novo é criado no início de cada processo)
##Mais informações http://labs.detectify.com/post/109964122636/hostile-subdomain-takeover-using
##Exemplo de saída
Enter a domain you'd like to brute force and look for hostile subdomain takeover(example: yahoo.com)
example.com
200 0.example.com ---> 198.185.159.177
- Subdomain pointing to a non-existing SquareSpace account showing: No Such Account
- Seems like 0.example.com is an alias for exampledomain111.squarespace.com
404 a.example.com ---> 50.116.58.222
- Subdomain pointing to a non-existing WPEngine subdomain indicatingThe site you were looking for couldn't be found.
- Seems like a.example.com is an alias for exampledomain111.wpengine.com
----> Check for further information on where this is pointing to.
404 b.example.com ---> 54.231.18.81
- Subdomain pointing to an unclaimed AmazonAWS bucket showing: NoSuchBucket
- Seems like b.example.com is an alias for exampledomain111.images.s3.amazonaws.com
----> Check for further information on where this is pointing to.
404 c.example.com ---> 23.227.38.70
- Subdomain pointing to a non-existing Shopify subdomain indicatingSorry, this shop is currently unavailable.
- Seems like c.example.com is an alias for theresnosuchdomain.myshopify.com
----> Check for further information on where this is pointing to.
301 cpanel.example.com ---> 1.1.1.1
404 e.example.com ---> 23.235.47.133
- Subdomain pointing to a non-existing Github subdomain indicatingThere isn't a GitHub Pages site here
- Seems like e.example.com is an alias for noneexistingexampledomain.github.com
----> Check for further information on where this is pointing to.
404 f.example.com ---> 199.27.79.133
- Subdomain pointing to a non-existing Github subdomain indicatingThere isn't a GitHub Pages site here
- Seems like f.example.com is an alias for noneexistingexampledomain.github.io
----> Check for further information on where this is pointing to.
200 ftp.example.com ---> 1.1.1.1
200 g.example.com ---> 104.238.181.195
- Seems like g.example.com is an alias for somedomain.anotherexample.com
este modo usa múltiplas threads, por isso produz resultados mais rapidamente. atualmente a saída não está sincronizada.
para executar este modo use --fast como argumento.
ruby sub_brute.rb --fast
Boa sorte!