Projects STRLCPY Cipherops Commits fbf097dd
🤬
Revision indexing in progress... (symbol navigation in revisions will be accurate after indexed)
  • .gitbook/assets/14025
    Diff is too large to be displayed.
  • .gitbook/assets/14050
    Diff is too large to be displayed.
  • .gitbook/assets/14100
    Diff is too large to be displayed.
  • .gitbook/assets/14125
    Diff is too large to be displayed.
  • .gitbook/assets/14150
    Diff is too large to be displayed.
  • .gitbook/assets/image (5).png
  • .gitbook/assets/image (6).png
  • ■ ■ ■ ■ ■
    SUMMARY.md
    skipped 18 lines
    19 19   
    20 20  ***
    21 21   
    22  -* [OSINT tools collection](osint-tools-collection.md)
     22 +* [Subdomain Takeover Resources](subdomain-takeover-resources.md)
    23 23  * [Damn Vulnerabilities List Lab](damn-vulnerabilities-list-lab.md)
    24 24  * [PORT SCANNING](port-scanning.md)
    25 25  * [Offensive virtual machine's](offensive-virtual-machines.md)
    skipped 1 lines
    27 27  * [30 cybersecurity search engines](30-cybersecurity-search-engines.md)
    28 28  * [cybersecurity YouTube channels](cybersecurity-youtube-channels.md)
    29 29  * [Try-Hack-me Roadmap](try-hack-me-roadmap.md)
     30 +* [OSINT](osint.md)
    30 31   
  • ■ ■ ■ ■ ■ ■
    essential-linux-commands.md
    skipped 208 lines
    209 209  * `yes > /dev/null &: Use this command to push a system to its limit.`
    210 210  * `:(){ :|:& };::: A fork bomb – handle with care. Do not run this command on a production system.`
    211 211   
     212 +{% embed url="https://www.commandlinefu.com/commands/browse" %}
     213 + 
    212 214  Remember, you can always use the `man` command (e.g., `man ls`) to get more information about each command.
    213 215   
  • ■ ■ ■ ■ ■ ■
    osint.md
    1  -# osint
     1 +# OSINT
     2 + 
     3 +```markdown
     4 +Osint Lists and collections.
     5 +## Maps, Geolocation, and Transport
     6 +- [Apps.skylens.io](https://apps.skylens.io): Posts with geotags from five social networks at once on one map (Twitter, YouTube, Instagram, Flickr, Vkontakte)
     7 +- [photo-map.ru](https://photo-map.ru): Search geotagged photos from VK.com
     8 +- Snapchat map
     9 +- [YouTube Geofind](https://www.youtube.com/geofind): View YouTube geotagged videos on a map
     10 +- Flickr Photo Map
     11 +- Flickr Common Map: Displays only Flickr photos distributed under a Creative Commons license (250 of the latest for each location)
     12 +- [I know where your cat lives](https://iknowwhereyourcatlives.com): Geotagged photos from Instagram with the #cat hashtag
     13 +- [Trendsmap.com](https://www.trendsmap.com): Explore most popular Twitter trends, hashtags, and users on the world map
     14 +- [Pastvu.com](https://pastvu.com): View historical photos taken at a particular location on a map
     15 +- BirdHunt: A tool to get a list of recent tweets made in a specific geolocation/radius
     16 +- [WikiShootMe](https://tools.wmflabs.org/wikishootme): Worldwide map of geotagged Wikipedia Creative Commons Images
     17 +- [The Painted Planet](http://www.paintedplanet.org): Click on a point on the map to get a list of landscapes by famous artists depicting the area
     18 +- [COPERNIX](https://copernix.io): Worldwide map of geolocated Wikipedia articles
     19 +- [WikiNearby](https://www.wikinearby.org): Enter geographic coordinates and language to get a list of Wikipedia articles about nearby streets, towns, stations, and other notable places
     20 +- [Huntel.io](https://www.huntel.io): Get a list of links to Facebook/Instagram locations linked to geographic coordinates
     21 + 
     22 +## Nature
     23 +- [Map View NGMDB](https://ngmdb.usgs.gov/mapview): Map for exploring geologic maps and articles from the NGMDB (National Geologic Map Database)
     24 +- [WAQI](https://waqi.info): World's Air Pollution: Real-time Air Quality Index map
     25 +- [GlobalFishingMap](https://globalfishingmap.com): Click on a point on the map and get data on the current fishing effort at that location
     26 +- [Natural Hazards Viewer](https://www.ncei.noaa.gov/data/global-natural-hazards-and-risks/hazard-viewer): Natural Hazards Viewer (worldwide)
     27 +- [Lightingmaps](https://www.lightningmaps.org): Lightning strikes in real time and historical data on thunderstorms
     28 +- [Light Pollution World Map](https://www.lightpollutionmap.info): Showing the degree of light pollution in different countries over time
     29 +- [Global Wetlands Map](https://www.globalwetlandsmap.org): Interactive map of wetlands worldwide
     30 +- [Fire MAP NASA](https://firms.modaps.eosdis.nasa.gov/map): Online map of fire hotspots around the world
     31 +- [Ocearch Shark Tracker](https://www.ocearch.org/tracker): Click on a shark on the world map and find out its name, size, and travel log
     32 +- [Surging Seas: Risk Zone Map](https://riskfinder.climatecentral.org): Map of points with a risk of significant sea level rise in the event of melting glaciers
     33 +- [USA Fishermap](https://www.usafishermap.org): Detailed map of freshwater bodies in the USA, including depth at different points
     34 +- [Mind
     35 + 
     36 +at.org](https://www.mindat.org): Mineral maps for different countries
     37 +- [Ventusky.com](https://www.ventusky.com): Collection of weather maps (wind, rain, temperature, air pressure, humidity, waves, etc.)
     38 +- [Wunderground](https://www.wunderground.com): Weather history data
     39 +- [Rain Alarm](https://www.rain-alarm.com): Shows where it is raining on the map and provides notifications of approaching rain
     40 +- [Cyclocane](https://www.cyclocane.com): Click on a hurricane on the map and get detailed information about it
     41 +- [MeteoBlue](https://www.meteoblue.com): Weather stats data
     42 +- [Zoom.earth](https://zoom.earth): Worldwide map of rains, storms, fires, heats, winds, and other natural phenomena
     43 +- [NGDC Bathymetry map](https://www.ngdc.noaa.gov/mgg/bathymetry): Worldwide detailed interactive bathymetry map
     44 +- [Soar.earth](https://soar.earth): Collection of satellite, drone, and ecological maps
     45 +- [Geodesics on the Earth](https://geodesics.online): Finding the shortest path between two points on Earth
     46 +- [Google Earth](https://www.google.com/earth): 3D representation of Earth based on satellite imagery
     47 +- [Everymountainintheworld](https://www.everymountainintheworld.com): Map showing mountains worldwide with altitude information
     48 +- [Rivermap](https://www.rivermap.net): Online map with detailed information on Europe's rivers
     49 +- [Global Biodiversity Information Facility](https://www.gbif.org): Enter the name of an animal, bird, or plant to see a map of where it has been spotted
     50 +- [Natural Hazards Map](https://maps.avijoin.com): Assess the risk of flooding, earthquakes, and hail in a specific location
     51 +- [River Runner Global](https://www.river-runner.org): Trace the path of rainwater from a specific location to the world's oceans
     52 +- [Macrostrat's Geologic Map System](https://macrostrat.org): Integrates over 290 bedrock geologic maps into a single, multiscale database
     53 +- [Global Flood Database](https://www.floods.global): Detailed statistics on floods worldwide over the last 15 years
    2 54   
     55 +## Aviation
     56 +- [Skyvector](https://skyvector.com): Tool for planning private flights and accessing data about the current situation in the sky
     57 +- [Flight Connections](https://www.flightconnections.com): Click on an airport on the map to see direct flight connections
     58 +- [World Aviation Accident Database 1962-2007](https://www.airsafe.com/events/db/index.htm)
     59 +- [World Aviation Accident Database 2008-2021](https://aviation-safety.net/database)
     60 +- [Rzjets.net](https://rzjets.net): User-updated online database of civilian jet and turbojet aircraft
     61 +- [Globe.adsbexchange.com](https://globe.adsbexchange.com): Track flights on a map
     62 +- [Transtats.bts.gov](https://transtats.bts.gov): Flight schedules and data on actual departure/arrival times of flights in the U.S.
     63 +- [Legrooms for Google Flights](https://chrome.google.com/webstore/detail/legrooms-for-google-fligh/bdlfaoffkcmjbmiicbajiflnhhnmfjgo): An extension that displays the size of the legroom between seats next to flight information
     64 +- [Flight Status Info](https://www.flightstats.com): Provides a list of airports by city name, flight schedules, and detailed information about flights
     65 + 
     66 +I hope this helps!
     67 +```
    3 68   
  • ■ ■ ■ ■
    overview/recon-tips/resources/best-recon-technique-for-active-subdomain-enumeration.md
    skipped 40 lines
    41 41  command: cat subdomains.txt | dnsx -a -resp-only | nrich -
    42 42  ```
    43 43   
    44  -<figure><img src="../../../.gitbook/assets/image (5).png" alt="Using shodan Search Engine to detect site that have same favicon hashed"><figcaption><p>use a nrich tool to check out the subdomains </p></figcaption></figure>
     44 +<figure><img src="../../../.gitbook/assets/image (6).png" alt="Using shodan Search Engine to detect site that have same favicon hashed"><figcaption><p>use a nrich tool to check out the subdomains </p></figcaption></figure>
    45 45   
    46 46  <mark style="color:green;">Technique 4:</mark> Choosing the Right Target When dealing with applications that have numerous subdomains, selecting the right subdomain to start hunting can be challenging. Utilize the interesting subs gf pattern list to identify interesting subdomains worth investigating. Execute the following command:
    47 47   
    skipped 44 lines
  • ■ ■ ■ ■ ■ ■
    subdomain-takeover-resources.md
     1 +# Subdomain Takeover Resources
     2 + 
     3 +```markdown
     4 +Here is a list of subdomain takeover resources along with their descriptions:
     5 + 
     6 +1. [Subdomain Takeover of help.bitstripsforschools.com](https://hackerone.com/reports/269109): This report details a subdomain takeover vulnerability found on help.bitstripsforschools.com.
     7 + 
     8 +2. [Subdomain Takeover via Unclaimed WordPress site](https://hackerone.com/reports/274336): This report describes a subdomain takeover vulnerability that occurred through an unclaimed WordPress site.
     9 + 
     10 +3. [Subdomain Takeover Through Expired Cloudfront Distribution | live.lamborghini.com](https://blog.securitybreached.org/2017/10/10/subdomain-takeover-lamborghini-hacked/): This blog post explains a subdomain takeover vulnerability that took place through an expired Cloudfront distribution on live.lamborghini.com.
     11 + 
     12 +4. [Hostile Subdomain Takeover tool written in Go](https://github.com/haccer/subjack): This is a tool called Subjack written in Go that helps identify and exploit subdomain takeover vulnerabilities.
     13 + 
     14 +5. [UBER Wildcard Subdomain Takeover](https://blog.securitybreached.org/2017/11/20/uber-wildcard-subdomain-takeover/): This blog post discusses a wildcard subdomain takeover vulnerability discovered in UBER.
     15 + 
     16 +6. [Subdomain Takeover](https://hackerone.com/reports/289051): This report describes a subdomain takeover vulnerability found on an undisclosed website.
     17 + 
     18 +7. [AWS S3 bucket - Subdomain takeover](http://www.tutorgeeks.net/2017/12/aws-s3-bucket-subdomain-takeover.html): This blog post explains a subdomain takeover vulnerability related to an AWS S3 bucket.
     19 + 
     20 +8. [MIT Subdomain Takeover](https://medium.com/@bluedangerforyou/mit-subdomain-takeover-65b1fe0f1347): This Medium article discusses a subdomain takeover vulnerability discovered at MIT.
     21 + 
     22 +9. [Second-order subdomain takeover scanner](https://github.com/mhmdiaa/second-order): This is a tool called Second-order that scans for second-order subdomain takeover vulnerabilities.
     23 + 
     24 +10. [Subdomain takeover at news-static.semrush.com](https://hackerone.com/reports/294201): This report details a subdomain takeover vulnerability found on news-static.semrush.com.
     25 + 
     26 +11. [SubdomainDB](https://github.com/smiegles/subdomainDB/): SubdomainDB is a self-hosted API that allows users to maintain their own subdomain database.
     27 + 
     28 +12. [SubOver - The Most Powerful Subdomain Takeover Tool Available](https://github.com/Ice3man543/SubOver/): SubOver is a powerful subdomain takeover tool designed to detect and exploit vulnerabilities.
     29 + 
     30 +13. [How I could make more than 1,700 Subdomain Takeovers on Amazon S3 in a few minutes](https://medium.com/@thebuckhacker/how-i-could-make-more-then-1-700-subdomains-takeovers-on-amazon-s3-in-few-minutes-8f6b27bffe0d): This Medium article describes a technique to perform numerous subdomain takeovers on Amazon S3.
     31 + 
     32 +14. [Subdomain takeover on developer.openapi.starbucks.com](https://hackerone.com/reports/275714): This report outlines a subdomain takeover vulnerability discovered on developer.openapi.starbucks.com.
     33 + 
     34 +15. [Hacker pro tip: when you takeover a subdomain on Heroku but the website still displays the "No such app" page, try to use an app in a different region](https://twitter.com/gwendallecoguic/status/966708730
     35 + 
     36 +```
     37 + 
     38 +```markdown
     39 +- [$4500 Bounty — How I got lucky](https://medium.com/bugbountywriteup/4500-bounty-how-i-got-lucky-99d8bc933f75)
     40 +- [Subdomain takeover with Shopify, Heroku and something more](https://medium.com/@valeriyshevchenko/subdomain-takeover-with-shopify-heroku-and-something-more-6e9504da34a1)
     41 +- [Subdomain takeover on svcgatewayus.starbucks.com](https://hackerone.com/reports/325336)
     42 +- [Subdomain takeover on svcgatewaydevus.starbucks.com and svcgatewayloadus.starbucks.com](https://hackerone.com/reports/383564)
     43 +- [svcardproxydevus.starbucks.com Subdomain take over](https://hackerone.com/reports/380158)
     44 +- [Subdomain takeover on wfmnarptpc.starbucks.com](https://hackerone.com/reports/388622)
     45 +- [Subdomain Takeover: Yet another Starbucks case](https://0xpatrik.com/subdomain-takeover-starbucks-ii/)
     46 +- [Guide To Subdomain Takeovers](https://medium.com/@Hacker0x01/a-guide-to-subdomain-takeovers-ddebe0684a58)
     47 +- [Subdomain takeover at segway.shipt.com](https://hackerone.com/reports/389783)
     48 +- [Subdomain Takeover: Going beyond CNAME](https://0xpatrik.com/subdomain-takeover-ns/)
     49 +- [How to do 55.000+ Subdomain Takeover in a Blink of an Eye](https://medium.com/@thebuckhacker/how-to-do-55-000-subdomain-takeover-in-a-blink-of-an-eye-a94954c3fc75)
     50 +- [Subdomain Takeover worth 200$](https://medium.com/@alirazzaq/subdomain-takeover-worth-200-ed73f0a58ffe)
     51 +- [Subdomain Takeover via Unsecured S3 Bucket Connected to the Website](https://blog.securitybreached.org/2018/09/24/subdomain-takeover-via-unsecured-s3-bucket/)
     52 +- [Takeover script extracts CNAME record of all subdomains at once. TakeOver saves researcher time and increase the chance of finding subdomain takeover vulnerability.](https://github.com/samhaxr/TakeOver-v1)
     53 +- [Subdomain Takeover — New Level](https://medium.com/bugbountywriteup/subdomain-takeover-new-level-43f88b55e0b2)
     54 +- [Subdomain Takeover: Second Order Bugs](https://0xpatrik.com/second-order-bugs/)
     55 +- [Subdomain takeover [Awarded $200]](https://medium.com/@friendly_/subdomain-takeover-awarded-200-8296f4abe1b0)
     56 +- [Subdomain takeover on dev-admin.periscope.tv](https://hackerone.com/reports/531890)
     57 +- [subdomain take over at recommendation.algolia.com](https://hackerone.com/reports/673273)
     58 +- [Subdomain takeover of d02-1-ag.productioncontroller.starbucks.com](https://hackerone.com/reports/661751)
     59 +- [Subdomain takeover of datacafe-cert.starbucks.com](https://hackerone.com/reports/665398)
     60 +```
     61 + 
Please wait...
Page is in error, reload to recover