-
Notifications
You must be signed in to change notification settings - Fork 0
/
subdomain-takeover_detect-all-takeovers.yaml
387 lines (317 loc) · 9.52 KB
/
subdomain-takeover_detect-all-takeovers.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
id: detect-all-takeovers
info:
name: Subdomain Takeover Detection
author: "melbadry9 & pxmme1337"
severity: high
# Update this list with new takeovers matchers
# Do not delete other template files for takeover
# https://github.com/EdOverflow/can-i-take-over-xyz
# You need to claim the subdomain / CNAME of the subdomain to confirm the takeover.
# Do not report subdomain takeover issues only based on detection.
# Total number of services #71
requests:
- method: GET
path:
- "{{BaseURL}}/"
matchers-condition: or
matchers:
- type: word
name: acquia
words:
- If you are an Acquia Cloud customer and expect to see your site at this address
- The site you are looking for could not be found.
- type: word
name: agilecrm
words:
- Sorry, this page is no longer available.
- type: word
name: airee
words:
- Ошибка 402. Сервис Айри.рф не оплачен
- type: word
name: aftership
words:
- Oops.</h2><p class="text-muted text-tight">The page you're looking for doesn't
exist.
- type: word
name: aha
words:
- There is no portal here ... sending you back to Aha!
- type: word
name: anima
words:
- "If this is your website and you've just created it, try refreshing in a minute"
- type: word
name: aws-bucket
words:
- "The specified bucket does not exist"
- type: word
name: bigcartel
words:
- "<h1>Oops! We couldn’t find that page.</h1>"
- type: word
name: bitbucket
words:
- The page you have requested does not exist
- Repository not found
- type: word
name: brightcove
words:
- '<p class="bc-gallery-error-code">Error Code: 404</p>'
- type: word
name: campaignmonitor
words:
- "<strong>Trying to access your account?</strong>"
- or <a href="mailto:[email protected]
- type: word
name: canny
words:
- Company Not Found
- There is no such company. Did you enter the right URL?
- type: word
name: cargo
words:
- If you're moving your domain away from Cargo you must make this configuration
through your registrar's DNS control panel.
- type: word
name: cargocollective
words:
- <div class="notfound">
- 404 Not Found<br>
- type: word
name: fastly
words:
- "Fastly error: unknown domain:"
- type: word
name: feedpress
words:
- The feed has not been found.
- type: word
name: frontify
words:
- 404 - Page Not Found
- Oops… looks like you got lost
condition: and
part: body
- type: word
name: gemfury
words:
- "404: This page could not be found."
- type: word
name: getresponse
words:
- With GetResponse Landing Pages, lead generation has never been easier
- type: word
name: ghost
words:
- The thing you were looking for is no longer here
- The thing you were looking for is no longer here, or never was
- type: word
name: github
words:
- There isn't a GitHub Pages site here.
- For root URLs (like http://example.com/) you must provide an index.html file
- type: word
name: hatenablog
words:
- 404 Blog is not found
- Sorry, we can't find the page you're looking for.
- type: word
name: helpjuice
words:
- We could not find what you're looking for.
- type: word
name: helprace
words:
- Alias not configured!
- Admin of this Helprace account needs to set up domain alias
- "(see Step 2 here: Using your own domain with Helprace)."
- type: word
name: helpscout
words:
- "No settings were found for this company:"
- type: word
name: heroku
words:
- There's nothing here, yet.
- herokucdn.com/error-pages/no-such-app.html
- "<title>No such app</title>"
- type: word
name: hubspot
words:
- Domain not found
- does not exist in our system
- type: word
name: intercom
words:
- This page is reserved for artistic dogs.
- <h1 class="headline">Uh oh. That page doesn’t exist.</h1>
- type: word
name: jazzhr
words:
- This account no longer active
- type: word
name: jetbrains
words:
- is not a registered InCloud YouTrack.
- type: word
name: kinsta
words:
- No Site For Domain
- type: word
name: landingi
words:
- It looks like you're lost
- The page you are looking for is not found
- type: word
name: launchrock
words:
- It looks like you may have taken a wrong turn somewhere. Don't worry...it happens
to all of us.
- type: word
name: mashery
words:
- Unrecognized domain <strong>
- type: word
name: ngrok
words:
- ngrok.io not found
- Tunnel *.ngrok.io not found
- type: word
name: pantheon.io
words:
- "The gods are wise, but do not know of the site which you seek."
- type: word
name: pingdom
words:
- Public Report Not Activated
- This public report page has not been activated by the user
- type: word
name: proposify
words:
- If you need immediate assistance, please contact <a href="mailto:[email protected]
- type: word
name: readme
words:
- Project doesnt exist... yet!
- type: word
name: shopify
words:
- "Sorry, this shop is currently unavailable."
- type: word
name: simplebooklet
words:
- We can't find this <a href="https://simplebooklet.com
- type: word
name: smartjob
words:
- Job Board Is Unavailable
- This job board website is either expired
- This job board website is either expired or its domain name is invalid.
- type: word
name: smartling
words:
- Domain is not configured
- type: word
name: smugmug
words:
- '{"text":"Page Not Found"'
- type: word
name: strikingly
words:
- But if you're looking to build your own website
- you've come to the right place.
- type: word
name: surge
words:
- project not found
- type: word
name: surveygizmo
words:
- data-html-name
- type: word
name: tave
words:
- "<h1>Error 404: Page Not Found</h1>"
- type: word
name: teamwork
words:
- Oops - We didn't find your site.
- type: word
name: thinkific
words:
- You may have mistyped the address or the page may have moved.
- type: word
name: tictail
words:
- Building a brand of your own?
- 'to target URL: <a href="https://tictail.com'
- Start selling on Tictail.
- type: word
name: tilda
words:
- Domain has been assigned
- type: word
name: tumblr
words:
- Whatever you were looking for doesn't currently exist at this address.
- There's nothing here.
- type: word
name: uberflip
words:
- "Non-hub domain, The URL you've accessed does not provide a hub."
- type: regex
name: unbounce
regex:
- "^The requested URL was not found on this server.$"
- type: regex
name: uptimerobot
regex:
- "^page not found$"
- type: word
name: uservoice
words:
- This UserVoice subdomain is currently available!
- type: word
name: vend
words:
- Looks like you've traveled too far into cyberspace.
- type: word
name: webflow
words:
- <p class="description">The page you are looking for doesn't exist or has been
moved.</p>
- type: word
name: wishpond
words:
- https://www.wishpond.com/404?campaign=true
- type: word
name: wordpress
words:
- Do you want to register
- type: regex
name: worksites
regex:
- "(?:Company Not Found|you’re looking for doesn’t exist)"
- type: word
name: wufoo
words:
- Profile not found
- Hmmm....something is not right.
- type: word
name: zendesk
words:
- this help center no longer exists
- type: word
name: readthedocs
words:
- unknown to Read the Docs
- type: word
name: tilda
words:
- <title>Please renew your subscription</title>
- Please go to the site settings and put the domain name in the Domain tab.
- type: word
name: smart-jobboard
words:
- This job board website is either expired or its domain name is invalid.