Termux ID: Subdomain Discovery Tool -->

Listing subdomains about the main domain using the technique called Hacking with search engines.

Usage
usage: n4xd0rk.py [-h] [-d DOMAIN] [-i IP] -o OPTION -n SEARCH [-e EXPORT]
[-l LANGUAGE]

This script searchs the subdomains about a domain using the results indexed of Bing search.

optional arguments:
-h, --help show this help message and exit
-d DOMAIN, --domain DOMAIN
The domain which wants to search.
-i IP, --ip IP The IP which to kown the domains to contain.
-o OPTION, --option OPTION
Select an option:
1. Searching the subdomains about a domain using the results indexed.
2. Searching the domains belong to an IP.
-n SEARCH, --search SEARCH
Indicate the number of the search which you want to do.
-e EXPORT, --export EXPORT
Export the results to a json file (Y/N)
Format available:
1.json
2.xlsx
-l LANGUAGE, --language LANGUAGE
Indicate the language of the search
(es)-Spanish(default)
(en)-English


N4xD0rk - Listing Subdomains About A Main Domain


subjack is a Hostile Subdomain Takeover tool written in Go designed to scan a list of subdomains concurrently and identify ones that are able to be hijacked. With Go's speed and efficiency, this tool really stands out when it comes to mass-testing. Always double check the results manually to rule out false positives.

Installing
You need have Go installed. Full details of installation and set up can be found here.
go build subjack.go

How To Use:
./subjack -w domains.txt -t 100 -timeout 30 -o results.txt -https
  • -w domains.txt is your list of subdomains. I recommend using cname.sh (included in repository) to sift through your subdomain list for ones that have CNAME records attached and use that list to optimize and speed up testing.
  • -t is the number of threads (Default: 10 threads).
  • -timeout is the seconds to wait before timeout connection (Default: 10 seconds).
  • -o results.txt where to save results to (Optional).
  • -https enforces https requests which may return a different set of results and increase accuracy (Optional).
Currently checks for:
  • Amazon S3 Bucket
  • Amazon Cloudfront
  • Cargo
  • Fastly
  • FeedPress
  • Ghost
  • Github
  • Helpjuice
  • Help Scout
  • Heroku
  • Pantheon.io
  • Shopify
  • Surge
  • Tumblr
  • UserVoice
  • WordPress
  • WP Engine

Practical Use
subjack included scanio.sh which is kind of a PoC script to mass-locate vulnerable subdomains using results from Rapid7's Project Sonar. This script parses and greps through the dump for desired CNAME records and makes a large list of subdomains to check with subjack if they're vulnerable to Hostile Subdomain Takeover. Of course this isn't the only method to get a large amount of data to test.


subjack - Hostile Subdomain Takeover tool written in Go