{"repo":"haccer/subjack","free":true,"listed":false,"github":"https://github.com/haccer/subjack","clone":"git clone https://github.com/haccer/subjack.git","description":"DNS Takeover tool written in Go","language":"Go","stars":2108,"topics":["go","golang","hostile","subdomain","takeover","subdomain-takeover","bug-bounty","pentesting","infosec","bugbounty"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"subjack DNS Takeover Scanner Subjack is a DNS takeover scanner written in Go designed to scan a list of domains concurrently and identify ones that are able to be hijacked. With Go's speed and efficiency, this tool really stands out when it comes to mass-testing. Always double check the results manually to rule out false positives. Subjack detects: - CNAME takeovers — dangling CNAMEs pointing to unclaimed third-party services - NS delegation takeovers — expired nameserver domains and dangling cloud DNS zones (Route 53, Google Cloud DNS, Azure DNS, DigitalOcean, Vultr, Linode) - Stale A records — A records pointing to dead IPs on cloud providers (AWS, GCP, Azure, DigitalOcean, Linode, Vultr, Oracle) - Zone transfers (AXFR) — misconfigured nameservers leaking entire zone files, with NS hostname bruteforcing - SPF include takeovers — expired domains in SPF include: directives enabling email spoofing - MX record takeovers — expired mail server domains enabling email interception - CNAME chain takeovers — multi-level CNAME chains where intermediate targets are claimable - SRV record takeovers — SRV records pointing to expired/registrable domains - NXDOMAIN registration — domains that don't exist and are available to be registered Installing Requires Go Usage Flag Description Default ------ ------------- --------- -d Single domain to check -w Path to wordlist of subdomains -t Number of concurrent threads 10 -timeout Seconds to wait before connection timeout 10 -o Output results to ","default_branch":null,"files":null,"tree":[],"storefront":"/r/haccer","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/haccer/subjack/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}