Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Is there a way to check A records? #1

Open
oldesec opened this issue Mar 12, 2019 · 4 comments
Open

Is there a way to check A records? #1

oldesec opened this issue Mar 12, 2019 · 4 comments
Assignees
Labels
enhancement New feature or request

Comments

@oldesec
Copy link

oldesec commented Mar 12, 2019

Hi.

Is there a way to check A records?

or Only CNAME check?

Thanks.

@jakejarvis
Copy link
Owner

Hi there!

For subdomain takeovers specifically, it really only makes sense to check for stale CNAME records. I think I understand what you're saying about subdomains pointing to IP addresses they no longer control/own, but taking those over is usually improbable due to providers assigning IPs somewhat randomly.

Is that what you're asking?

@oldesec
Copy link
Author

oldesec commented Mar 16, 2019

@jakejarvis Thank you for your kind reply.

Sometimes, can take over subdomains if use A records.
I want to detect it.

Here's a case.
Ref : https://blog.initd.sh/others-attacks/mis-configuration/subdomain-takeover-explained/ (Only Tilda page)

@jakejarvis
Copy link
Owner

Ah, thanks for the link. I see what you're saying about services providing the same IPs for users that can't use CNAMEs. I think Tumblr, GitHub Pages, and Bitly do the same. This should be doable, I'll definitely take a look!

@jakejarvis jakejarvis added the enhancement New feature or request label Mar 18, 2019
@jakejarvis jakejarvis self-assigned this Mar 18, 2019
@oldesec
Copy link
Author

oldesec commented Mar 23, 2019

@jakejarvis Good.
exactly. hmm.. Many tools do not support this feature.
I do not know why.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants