Subover is a Hostile Subdomain Takeover tool designed in Python. From start, it has been aimed with speed and efficiency in mind. Till date, SubOver detects 36 services which is much more than any other tool out there. The tool is multithreaded and hence delivers good speed. It can easily detect and report potential subdomain takeovers that exist. The list of potentially hijackable services is very comprehensive and it is what makes this tool so powerful.
Installing
You need to have Python 2.7 installed on your machine. The following additional requirements are required -
- dnspython
- colorama
git clone https://github.com/Ice3man543/SubOver.git .
cd SubOver
# consider installing virtualenv
pip install -r requirements.txt
python subover.py -h
Usage
python subover.py -l subdomains.txt -o output_takeovers.txt
-l subdomains.txt
is the list of target subdomains. These can be discovered using various tool such as sublist3r or others.-o output_takeovers.txt
is the name of the output file. (Optional & Currently not very well formatted)-t
20 is the default number of threads that SubOver will use. (Optional)-V
is the switch for showing verbose output. (Optional, Default=False)
Currently Checked Services
- Github
- Heroku
- Unbounce
- Tumblr
- Shopify
- Instapage
- Desk
- Tictail
- Campaignmonitor
- Cargocollective
- Statuspage
- Amazonaws
- Cloudfront
- Bitbucket
- Squarespace
- Smartling
- Acquia
- Fastly
- Pantheon
- Zendesk
- Uservoice
- WPEngine
- Ghost
- Freshdesk
- Pingdom
- Tilda
- Wordpress
- Teamwork
- Helpjuice
- Helpscout
- Cargo
- Feedpress
- Freshdesk
- Surge
- Surveygizmo
- Mashery
FAQ
Q: What should my wordlist look like?
A: Your wordlist should include a list of subdomains you're checking and should look something like:
backend.example.com
something.someone.com
apo-setup.fxc.something.com
Your tool sucks!
Yes, you're probably correct. Feel free to:
- Not use it.
- Show me how to do it better.
Contact
Twitter: @Ice3man543
Credits
- Subdomain Takeover Scanner by 0x94
- subjack : Hostile Subdomain Takeover Tool Written In GO
- Anshumanbh : tko-subs
More articles
- Hacker Tools Apk Download
- Pentest Tools Online
- Growth Hacker Tools
- Game Hacking
- Hack Tools Download
- Hacking Tools 2019
- Hacking Tools For Pc
- Hacking App
- Usb Pentest Tools
- Hack Tools For Games
- Hacking Tools For Beginners
- Hacking Tools For Pc
- Hacker Tools List
- Hacking Tools Kit
- Hack Tools Online
- Hack Tools Pc
- Hacking Tools Name
- Hacker Tools Apk
- Hack App
- Hacker Tools Linux
- Hacking Tools For Windows
- Physical Pentest Tools
- Hack Tools
- Pentest Tools Linux
- Hacker Tools Free
- Hacking Tools For Kali Linux
- Hacker Tools Windows
- Hacker Techniques Tools And Incident Handling
- Ethical Hacker Tools
- Hacking Tools Online
- Nsa Hack Tools
- Best Hacking Tools 2020
- Top Pentest Tools
- Hacking App
- Pentest Tools Windows
- Hacker Tools Free
- Blackhat Hacker Tools
- Bluetooth Hacking Tools Kali
- How To Make Hacking Tools
- Pentest Automation Tools
- Pentest Tools Open Source
- Android Hack Tools Github
- Hacker Tools 2020
- Android Hack Tools Github
- New Hacker Tools
- Pentest Automation Tools
- Hacker Tools Github
- Best Pentesting Tools 2018
- Hacking Tools Pc
- Hacker Hardware Tools
- Hacker Tools For Ios
- Pentest Tools Apk
- Hacking Tools
- Tools Used For Hacking
- Hack Tools Download
- Termux Hacking Tools 2019
- Hacker Tools Free Download
- Hack Apps
- Pentest Tools For Windows
- Hacker Tools Windows
- Hack Tools Pc
- Bluetooth Hacking Tools Kali
- Tools 4 Hack
No comments:
Post a Comment