Jump to content

Locked second-order: Scans web applications for second-order subdomain takeover


Recommended Posts

This is the hidden content, please

Second Order

Scans web applications for second-order subdomain takeover by crawling the app, and collecting URLs (and other data) that match certain rules, or respond in a certain way.

Usage Ideas

This is a list of tips and ideas (not necessarily related to second-order subdomain takeover) on what to use Second Order for.

    Check for second-order subdomain takeover: takeover.json. (Duh!)
    Collect inline and imported JS code: javascript.json.
    Find where a target hosts static files cdn.json. (S3 buckets, anyone?)
    Collect <input> names to build a tailored parameter bruteforcing wordlist: parameters.json.
    Feel free to contribute more ideas!

This is the hidden content, please

Link to comment
Share on other sites

This topic is now closed to further replies.
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.