Search This Blog

Saturday, August 22, 2020

SubOver - A Powerful Subdomain Takeover Tool


Subover is a Hostile Subdomain Takeover tool designed in Python. From start, it has been aimed with speed and efficiency in mind. Till date, SubOver detects 36 services which is much more than any other tool out there. The tool is multithreaded and hence delivers good speed. It can easily detect and report potential subdomain takeovers that exist. The list of potentially hijackable services is very comprehensive and it is what makes this tool so powerful.

Installing
You need to have Python 2.7 installed on your machine. The following additional requirements are required -
  • dnspython
  • colorama
git clone https://github.com/Ice3man543/SubOver.git .
cd SubOver
# consider installing virtualenv
pip install -r requirements.txt
python subover.py -h

Usage
python subover.py -l subdomains.txt -o output_takeovers.txt
  • -l subdomains.txt is the list of target subdomains. These can be discovered using various tool such as sublist3r or others.
  • -o output_takeovers.txtis the name of the output file. (Optional & Currently not very well formatted)
  • -t 20 is the default number of threads that SubOver will use. (Optional)
  • -V is the switch for showing verbose output. (Optional, Default=False)

Currently Checked Services
  • Github
  • Heroku
  • Unbounce
  • Tumblr
  • Shopify
  • Instapage
  • Desk
  • Tictail
  • Campaignmonitor
  • Cargocollective
  • Statuspage
  • Amazonaws
  • Cloudfront
  • Bitbucket
  • Squarespace
  • Smartling
  • Acquia
  • Fastly
  • Pantheon
  • Zendesk
  • Uservoice
  • WPEngine
  • Ghost
  • Freshdesk
  • Pingdom
  • Tilda
  • Wordpress
  • Teamwork
  • Helpjuice
  • Helpscout
  • Cargo
  • Feedpress
  • Freshdesk
  • Surge
  • Surveygizmo
  • Mashery
Count : 36

FAQ
Q: What should my wordlist look like?
A: Your wordlist should include a list of subdomains you're checking and should look something like:
backend.example.com
something.someone.com
apo-setup.fxc.something.com

Your tool sucks!
Yes, you're probably correct. Feel free to:
  • Not use it.
  • Show me how to do it better.

Contact
Twitter: @Ice3man543

Credits


More articles


  1. Hacker Tools Apk Download
  2. Pentest Tools Online
  3. Growth Hacker Tools
  4. Game Hacking
  5. Hack Tools Download
  6. Hacking Tools 2019
  7. Hacking Tools For Pc
  8. Hacking App
  9. Usb Pentest Tools
  10. Hack Tools For Games
  11. Hacking Tools For Beginners
  12. Hacking Tools For Pc
  13. Hacker Tools List
  14. Hacking Tools Kit
  15. Hack Tools Online
  16. Hack Tools Pc
  17. Hacking Tools Name
  18. Hacker Tools Apk
  19. Hack App
  20. Hacker Tools Linux
  21. Hacking Tools For Windows
  22. Physical Pentest Tools
  23. Hack Tools
  24. Pentest Tools Linux
  25. Hacker Tools Free
  26. Hacking Tools For Kali Linux
  27. Hacker Tools Windows
  28. Hacker Techniques Tools And Incident Handling
  29. Ethical Hacker Tools
  30. Hacking Tools Online
  31. Nsa Hack Tools
  32. Best Hacking Tools 2020
  33. Top Pentest Tools
  34. Hacking App
  35. Pentest Tools Windows
  36. Hacker Tools Free
  37. Blackhat Hacker Tools
  38. Bluetooth Hacking Tools Kali
  39. How To Make Hacking Tools
  40. Pentest Automation Tools
  41. Pentest Tools Open Source
  42. Android Hack Tools Github
  43. Hacker Tools 2020
  44. Android Hack Tools Github
  45. New Hacker Tools
  46. Pentest Automation Tools
  47. Hacker Tools Github
  48. Best Pentesting Tools 2018
  49. Hacking Tools Pc
  50. Hacker Hardware Tools
  51. Hacker Tools For Ios
  52. Pentest Tools Apk
  53. Hacking Tools
  54. Tools Used For Hacking
  55. Hack Tools Download
  56. Termux Hacking Tools 2019
  57. Hacker Tools Free Download
  58. Hack Apps
  59. Pentest Tools For Windows
  60. Hacker Tools Windows
  61. Hack Tools Pc
  62. Bluetooth Hacking Tools Kali
  63. Tools 4 Hack

No comments:

Post a Comment