Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Add more takeover-prone providers to the CNAME fingerprint list

Open Beginner friendly
#134 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
Under an hour
Newbie friendliness
90/100
Issue type
Feature
Clarity
Clearly specified
Activity status
Active
Tech stack
go
Domain
security

Research direction

Start by examining the takeoverProviders list in internal/dns/takeover.go and the existing test cases in internal/dns/takeover_test.go to understand the format. Pick vulnerable services from the can-i-take-over-xyz list, add {suffix, name} entries to the list, and add corresponding test cases including negative matches. Run go test ./internal/dns/ to verify. Done when new providers are in the list with passing tests and the PR references the source entries.

Written by the indexing model from the issue text.

Description

area: dns enhancement good first issue

What

subenum flags a result whose CNAME points at a service where dangling records have allowed subdomain takeovers. The list is takeoverProviders in internal/dns/takeover.go (31 suffixes today: S3, Azure, GitHub Pages, Heroku, Fastly, Shopify, Netlify, ...).

Why

Every provider added turns a silent result into a hint a user can act on, and it shows up in -sarif output and code scanning.

How

  1. Pick one or more services from the community list can-i-take-over-xyz whose status is "Vulnerable" and whose CNAME suffix is not in the list yet.
  2. Add {suffix, name} entries (suffix with a leading dot, name lowercase with hyphens).
  3. Add cases to TestTakeoverProvider in internal/dns/takeover_test.go, including a look-alike that must not match (for example herokuapp.com.evil.example.com).
  4. Run go test ./internal/dns/.

Done when

New providers are in the list with tests, and the PR links the can-i-take-over-xyz entry for each one.

Dominant language
Go
Stars
1
Forks
1
Avg merge
5d 2h
Merged PRs (30d)
3

Getting set up

Open in Codespaces

Starts the project's dev container in your browser, under your own GitHub account.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from TMHSDigital/subenum

All issues in TMHSDigital/subenum

Similar issues

More Go issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.