Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fingerprint addition needed #2

Closed
GDATTACKER-RESEARCHER opened this issue Sep 3, 2020 · 5 comments
Closed

fingerprint addition needed #2

GDATTACKER-RESEARCHER opened this issue Sep 3, 2020 · 5 comments

Comments

@GDATTACKER-RESEARCHER
Copy link
Contributor

GDATTACKER-RESEARCHER commented Sep 3, 2020

@PushpenderIndia
Copy link
Owner

Thanks for requesting to add these fingerprints!

Can you confirm, whether these fingerprints and there CNAME values are correct or not !

Item Order In Fingerprint Lists is :

  • engine
  • status
  • cname_list
  • fingerprint
f57 = [
        "ReadTheDocs.org",
        "Vulnerable",
        ["readthedocs.io"],
        "is unknown to Read the Docs"
    ] 

f58 = [
        "LeadPages.com",
        "Vulnerable",
        ["custom-proxy.leadpages.net", "leadpages.net"],
        "Double check that you have the right web address and give it another go!</p>"
    ] 

f59 = [
        "Worksites.net",
        "Vulnerable",
        ["NOT_AVAILABLE"],
        "Hello! Sorry, but the website you&rsquo;re looking for doesn&rsquo;t exist."
        ## A Record IP ==> 69.164.223.206
    ] 

f60 = [
        "AgileCRM",
        "Vulnerable",
        ["cname.agilecrm.com", "agilecrm.com"],
        "Sorry, this page is no longer available."
    ] 

f61 = [
        "ElasticBeanstalk_AWS_service",
        "Vulnerable",
        ["elasticbeanstalk.com"],
        "" #No Fingerprint Available
    ] 

f62 = [
        "Uberflip",
        "Vulnerable",
        ["read.uberflip.com", "uberflip.com"],
        "Non-hub domain, The URL you've accessed does not provide a hub. Please check the URL and try again."
    ] 

@GDATTACKER-RESEARCHER
Copy link
Contributor Author

  1. bro can you provide a update command for the script directly.
  2. i am not sure about vulnerable cname entry required for vulnerable leadpages entries.
  3. can you update the serials of service fingerprint in fingerprints.py.
  4. bro many services are still not added you can find those in can i takeover xyz issues list.

@PushpenderIndia
Copy link
Owner

PushpenderIndia commented Sep 4, 2020 via email

@PushpenderIndia
Copy link
Owner

Bigcartel's Fingerprints are already added

  • Added more CNAME records for microsoft azure

I'm unable to find CNAME of Kinsta & Anima & also Kinsta's fingerprints are not available.
Please try to find it and post it here.

And I think Kinsta's Subdomain Takeover is a Edge Case.

Please Verify whether, these info are correct or not, Upper Lower case could also leads to false positive.

Kinsta
Edge Case
[""]
""
# Here is the response from kinsta for orphan CNAME.
# 404 Not Found
# Content-Length=[33604]
# Server = kinsta-nginx

Anima
Vulnerable
[""]
"Missing Website"
"If this is your website and you've just created it, try refreshing in a minute"
# A record : 35.164.217.247

Frontify
Vulnerable
["frontify.com"]
"404 - Page not found. Oops... look like you got lost."

Landingi
Vulnerable
["cname.landingi.com"]
A Record : 174.129.25.170
"<h1>It looks like you’re lost...</h1>"
"<p>The page you are looking for is not found.</p>"

Helprace
Vulnerable
["helprace.com"]
"Alias not configured!"
"Admin of this Helprace account needs to set up domain alias"

Canny.io
Vulnerable
["cname.canny.io"]
"Company Not Found"
"There is no such company. Did you enter the right URL?"

Airee.ru 
Vulnerable
["cdn.airee.com", "airee.com"]
"Ошибка 402. Сервис Айри.рф не оплачен"
"Сайт xyz.xyz.ru. , на который вы заходите, не оплатил сервис Айри.рф. Доступ к сайту временно невозможен."

Ngrok
Vulnerable
["ngrok.io"]
"ngrok.io not found"

LaunchRock
Vulnerable
["launchrock.com"]
"It looks like you may have taken a wrong turn somewhere. Don't worry...it happens to all of us."
A Record :
54.243.190.28
54.243.190.39
54.243.190.47
54.243.190.54

I will also, soon going to add Header & A record Check,

& Auto Update feature is on the way : )

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants