Add more takeover-prone providers to the CNAME fingerprint list
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- Under an hour
- Newbie friendliness
- 90/100
Research direction
Start by examining the takeoverProviders list in internal/dns/takeover.go and the existing test cases in internal/dns/takeover_test.go to understand the format. Pick vulnerable services from the can-i-take-over-xyz list, add {suffix, name} entries to the list, and add corresponding test cases including negative matches. Run go test ./internal/dns/ to verify. Done when new providers are in the list with passing tests and the PR references the source entries.
Written by the indexing model from the issue text.
Description
What
subenum flags a result whose CNAME points at a service where dangling records have allowed subdomain takeovers. The list is takeoverProviders in internal/dns/takeover.go (31 suffixes today: S3, Azure, GitHub Pages, Heroku, Fastly, Shopify, Netlify, ...).
Why
Every provider added turns a silent result into a hint a user can act on, and it shows up in -sarif output and code scanning.
How
- Pick one or more services from the community list can-i-take-over-xyz whose status is "Vulnerable" and whose CNAME suffix is not in the list yet.
- Add
{suffix, name}entries (suffix with a leading dot, name lowercase with hyphens). - Add cases to
TestTakeoverProviderininternal/dns/takeover_test.go, including a look-alike that must not match (for exampleherokuapp.com.evil.example.com). - Run
go test ./internal/dns/.
Done when
New providers are in the list with tests, and the PR links the can-i-take-over-xyz entry for each one.
- Dominant language
- Go
- Stars
- 1
- Forks
- 1
- Avg merge
- 5d 2h
- Merged PRs (30d)
- 3
Getting set up
Starts the project's dev container in your browser, under your own GitHub account.
- Ships a Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from TMHSDigital/subenum
-
area: cli enhancement good first issue
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
TMHSDigital/subenum#136 ·
Maintainers usually reply within 1 day
-
community documentation good first issue
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
TMHSDigital/subenum#135 ·
Maintainers usually reply within 1 day
-
community marketing priority: low
Difficulty 5/5 Over a week Newbie friendliness 35/100
TMHSDigital/subenum#132 · 1 comment ·
Maintainers usually reply within 1 day
-
feature priority: low
Difficulty 5/5 Over a week Newbie friendliness 35/100
TMHSDigital/subenum#131 ·
Maintainers usually reply within 1 day
-
documentation marketing priority: medium
Difficulty 5/5 Over a week Newbie friendliness 25/100
TMHSDigital/subenum#127 ·
Maintainers usually reply within 1 day
All issues in TMHSDigital/subenum
Similar issues
-
agent-research-recommend agent-review-finding chore
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
jordansmall/spindrift#4821 · 1 comment ·
Maintainers usually reply within 1 day
-
area:web
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
praetorianer777/GoTome#178 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
oracle/go-oracledb#105 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
Maintainers usually reply within 1 day