-
-
Notifications
You must be signed in to change notification settings - Fork 93
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
DNSimple #16
Comments
I'm getting "*.example.com matches a reserved subdomain" |
@dadsgone0 Please see the updated "False Positives" section of this issue. :) |
So their domain will not resolve because their payment method is bad, but it cannot be taken over? How is it a false positive then if it can't be taken over? Am i just having a total brain-fart? |
@dadsgone0 It's a false positive because the way to identify vulnerable domains is if they return a |
Okay, I understand now. Thank you.
…On Sat, Nov 11, 2023, 12:39 PM Indiana JSON ***@***.***> wrote:
@dadsgone0 <https://github.com/dadsgone0> It's a false positive because
the way to identify vulnerable domains is if they return a SERVFAIL
error. In this case, even though the domain returned the proper error code
(indicating it was vulnerable) the domain is actually not vulnerable
because it's already in someone's account, (i.e. we thought it was
vulnerable but it was a "false positive").
—
Reply to this email directly, view it on GitHub
<#16 (comment)>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/AUDPSQ6MOONEDO6VSTD4QWTYD7A63AVCNFSM46LEUJZKU5DIOJSWCZC7NNSXTN2JONZXKZKDN5WW2ZLOOQ5TCOBQGY4DQNZZGEZA>
.
You are receiving this because you were mentioned.Message ID:
***@***.***>
|
Service
DNSimpleStatus
VulnerableNameserver
Explanation
You can sign up for a free account on DNSimple. After creating your account go to
Domains
and clickAdd Domains
. If you are able to create a zone for the vulnerable domain then takeover is possible. REMEMBER, the zone will not function until you start a 30-day trial with DNSimple, which requires a credit card on file.False Positives
DNSimple can produce false positives because a domain can be in an account where the account owner's payment method has expired, thus the domain will not resolve (i.e. shows a DNS SERVFAIL error), but cannot be added to your account.
The text was updated successfully, but these errors were encountered: