FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
Before yesterdayYour RSS feeds

dnsReaper now supports subdomain attacks using project discovery and SecurityTrails

Hey all,

I help maintain dnsReaper which is a subdomain takeover tool. It's free, available on GitHub and docker and looks for domains vulnerable to domain takeovers.

Today we've added 2 new integrations!

Project discovery have a massive database of subdomains called CHAOS and you can now query and test domains in dnsReaper.

We've also added SecurityTrails, which also has a huge public subdomain list.

This means that you can just point dnsReaper at a bug bounty domain and let it run. There will be false positives for sure, but we have 61 signatures so hopefully there will be some nice easy findings too.

Our blog post on the new features is here:

https://punksecurity.co.uk/blog/dnsreaper_pd/

Our GitHub is over here:

https://github.com/punk-security/dnsReaper

It's a free tool that we built just to highlight this issue and educate. Please give it a star and share it, we'd appreciate it.

submitted by /u/punksecurity_simon
[link] [comments]

a quick post about rbac-police

TL DR;. it's awesome. Some pods can take over the entire kubernetes cluster. Don't trust helm charts. It's super easy to audit yourself. It's not my tool.

https://punksecurity.co.uk/blog/rbac-police/

submitted by /u/punksecurity_simon
[link] [comments]
❌