{"repo":"mhmdiaa/second-order","free":true,"listed":false,"github":"https://github.com/mhmdiaa/second-order","clone":"git clone https://github.com/mhmdiaa/second-order.git","description":"Second-order subdomain takeover scanner","language":"Go","stars":408,"topics":["security","security-tools","wordlist","wordlist-generator","penetration-testing","pentesting","infosec","recon","reconnaissance","mapping"],"license":"MIT","category":"security-tools","readme_excerpt":"Second Order Scans web applications for second-order subdomain takeover by crawling the app, and collecting URLs (and other data) that match certain rules, or respond in a certain way. Installation From binary Download a prebuilt binary from the releases page and unzip it. From source Go version 1.17 is recommended. Docker Command line options Configuration File Example configuration files are in config - LogQueries : A map of tag-attribute queries that will be searched for in crawled pages. For example, \"a\": \"href\" means log every href attribute of every a tag. - LogNon200Queries : A map of tag-attribute queries that will be searched for in crawled pages, and logged only if they contain a valid URL that doesn't return a 200 status code. - LogInline : A list of tags whose inline content (between the opening and closing tags) will be logged, like title and script Output All results are saved in JSON files that specify what and where data was found - The results of LogQueries are saved in attributes.json - The results of LogNon200Queries are saved in non-200-url-attributes.json - The results of LogInline are saved in inline.json Usage Ideas This is a list of tips and ideas (not necessarily related to second-order subdomain takeover) on what to use Second Order for. - Check for second-order subdomain takeover: takeover.json. (Duh!) - Collect inline and imported JS code: javascript.json. - Find where a target hosts static files cdn.json. (S3 buckets, anyone?) - Collect names to b","default_branch":null,"files":null,"tree":[],"storefront":"/r/mhmdiaa","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/mhmdiaa/second-order/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}