Subover is a Hostile Subdomain Takeover tool designed in Python. From start, it has been aimed with speed and efficiency in mind. Till date, SubOver detects 36 services which is much more than any other tool out there. The tool is multithreaded and hence delivers good speed. It can easily detect and report potential subdomain takeovers that exist. The list of potentially hijackable services is very comprehensive and it is what makes this tool so powerful.
Installing
You need to have Python 2.7 installed on your machine. The following additional requirements are required -
- dnspython
- colorama
git clone https://github.com/Ice3man543/SubOver.git .
cd SubOver
# consider installing virtualenv
pip install -r requirements.txt
python subover.py -h
Usage
python subover.py -l subdomains.txt -o output_takeovers.txt
-l subdomains.txt
is the list of target subdomains. These can be discovered using various tool such as sublist3r or others.-o output_takeovers.txt
is the name of the output file. (Optional & Currently not very well formatted)-t
20 is the default number of threads that SubOver will use. (Optional)-V
is the switch for showing verbose output. (Optional, Default=False)
Currently Checked Services
- Github
- Heroku
- Unbounce
- Tumblr
- Shopify
- Instapage
- Desk
- Tictail
- Campaignmonitor
- Cargocollective
- Statuspage
- Amazonaws
- Cloudfront
- Bitbucket
- Squarespace
- Smartling
- Acquia
- Fastly
- Pantheon
- Zendesk
- Uservoice
- WPEngine
- Ghost
- Freshdesk
- Pingdom
- Tilda
- Wordpress
- Teamwork
- Helpjuice
- Helpscout
- Cargo
- Feedpress
- Freshdesk
- Surge
- Surveygizmo
- Mashery
FAQ
Q: What should my wordlist look like?
A: Your wordlist should include a list of subdomains you're checking and should look something like:
backend.example.com
something.someone.com
apo-setup.fxc.something.com
Your tool sucks!
Yes, you're probably correct. Feel free to:
- Not use it.
- Show me how to do it better.
Contact
Twitter: @Ice3man543
Credits
- Subdomain Takeover Scanner by 0x94
- subjack : Hostile Subdomain Takeover Tool Written In GO
- Anshumanbh : tko-subs
Related posts
- Nsa Hacker Tools
- Hacking Tools Hardware
- Hacking App
- Hacker Tools For Pc
- Pentest Tools Apk
- Hack Website Online Tool
- Hacker Tools Windows
- Github Hacking Tools
- Hack Tools For Windows
- Hacker Tools Apk
- Hack Tool Apk
- Hacker Search Tools
- Tools For Hacker
- Kik Hack Tools
- Github Hacking Tools
- Hack And Tools
- Pentest Tools List
- Hack Tool Apk No Root
- Hacker Hardware Tools
- Hack Tool Apk
- Hacking Tools Name
- Install Pentest Tools Ubuntu
- Beginner Hacker Tools
- Hacking Tools Usb
- Hacking Tools For Games
- Hack Tools Download
- Hacking Tools 2019
- Pentest Tools Framework
- Black Hat Hacker Tools
- Hack Tools Online
- Hack App
- Hacker Tools For Windows
- Hacker Tools For Mac
- Pentest Tools Find Subdomains
- Pentest Tools List
- Pentest Tools Online
- Hacker Tools Github
- Hacking Tools Pc
- Hacking Tools For Mac
- Hacker Tools Github
- Hack Tools For Windows
- Hacker Tools Github
- Top Pentest Tools
- Pentest Tools Github
- Hack Apps
- Hacking Tools 2020
- Black Hat Hacker Tools
- Hacking Tools Usb
- Hacker Tools Hardware
- Hacking Tools Github
- Pentest Tools Linux
- Hacker Tools For Pc
- Hacker Tool Kit
- Hack Tools For Pc
- Pentest Reporting Tools
- Pentest Tools List
- Pentest Tools Online
- Computer Hacker
- Pentest Tools For Ubuntu
- Blackhat Hacker Tools
- Hacker Tools Free Download
- Hacker Tools Hardware
- Pentest Tools For Mac
- Hacker Tools For Mac
- Install Pentest Tools Ubuntu
- How To Install Pentest Tools In Ubuntu
- Pentest Tools Windows
- Hacking Tools Software
- New Hack Tools
- Pentest Tools Nmap
- Ethical Hacker Tools
- Easy Hack Tools
- Hacker Tool Kit
- Pentest Tools Alternative
- Hack Tools For Pc
0 comments:
Post a Comment