Resources

Cheatsheet

Playbook: Commands & Tactics

  • Recon
    dig CNAME system.facebook.com
    dig any system.facebook.com
  • Automate
    subzy r --targets sub.txt
    nuclei -l live_suby.txt -t http/takeovers/ 
    cat live_suby.txt | cnames -v

Tools

Notes

Every 404 Error does not mean that the subdomain is vulnerable to subdomain takeover