subdomain takeover (stealing websites)

Поделиться
HTML-код
  • Опубликовано: 29 сен 2024

Комментарии • 307

  • @NetworkChuck
    @NetworkChuck  Год назад +29

    Is your code secure? Use this FREE tool (CodeSec) to find out: bit.ly/3tcPUQx
    TOOLS USED IN THIS VIDEO
    ---------------------------------------------------
    - AMASS: github.com/OWASP/Amass (find subdomains)
    -TakeOver: github.com/m4ll0k/takeover (subdomain takeover vulnerability scanner)
    -Dig (apt install dig)
    🔥🔥Join Hackwell Academy!: ntck.co/NCAcademy
    0:00 ⏩ Intro
    0:18 ⏩ How subdomain takeover works
    1:59 ⏩ Why Subdomain takeovers are dangerous
    2:33 ⏩ Make sure your code is secure using codesec!
    4:06 ⏩ find our targets subdomains using Amass
    5:06 ⏩ The username is not available
    5:57 ⏩ IT actually worked!!
    6:17 ⏩ Once you’re in github…
    6:58 ⏩ The same thing can happen with Azure
    7:45 ⏩ so how do you protect your website

    • @karim3741
      @karim3741 Год назад

      Hey chuck (apt install dig) will not work 😊 its (apt install dnsutils)

    • @owengames7567
      @owengames7567 Год назад

      hey your comment section is botted lol

    • @rdahlinger4509
      @rdahlinger4509 Год назад

      Do you have any recommendations for someone who bought a new computer and the staples set it up in a bad way with admins and a fake windows defender that I can’t seem to figure out how to fix. I have Apache licenses and open sources and all of this stuff I have no idea how to fix. Thoughts?

  • @n1027
    @n1027 Год назад +10

    Thanks for your video. I learns a lot and useful to my job.

  • @brightjoseph9947
    @brightjoseph9947 Год назад +2

    Another video by chuck
    Thank Goodness

  • @willyjancke2622
    @willyjancke2622 Год назад

    Now I know the difference between real voice chuck and content creator chuck. BTW luv the videos !

  •  6 месяцев назад

    You are better than any AI !

  • @InfamousKoala
    @InfamousKoala Год назад +1

    I love your content so much chuck

  • @brolbucht5558
    @brolbucht5558 Год назад +2

    What about a subdomain takeover with Fastly?

  •  Год назад

    This week is hell and a bloodbath can happen but why we don't discuss the fact that Amazon also released their ANM27T in it? Always two sides of a coin

  • @AltoAngelo
    @AltoAngelo Год назад +1

    Wow! So Cool! 😂👍👍👍

  • @andresdevvv
    @andresdevvv Год назад

    NEW VIDEO!!! YAY

  • @0sub686
    @0sub686 Год назад

    As a hacker, I can assure that it was the easiest explanation of Subdomain Takeover.

  • @M3laku
    @M3laku Год назад +7

    Remember kids ...
    it's always DNS, always.

  • @tristunalekzander5608
    @tristunalekzander5608 Год назад +23

    I don't get it, if the website is deployed from github, why would you ever delete your github account? You would have probably switched to another repo or just uploaded the files directly to your server before you delete your account while your website is still dependent on it. I also don't understand why this is only a vulnerability with subdomains.

    • @lampagiul
      @lampagiul Год назад +8

      because you cannot create CNAME records for root domains

    • @LuminousWhispers11
      @LuminousWhispers11 Год назад +3

      You just have to delete the resource and not alter the dns records. Remember this was a demonstration.

    • @777Yashobeamofchrist
      @777Yashobeamofchrist Год назад

      Guys, question. If you have control of the main domain and delete the entry for the subdomain that was took over, that would be the end off correct? Or is there a way to take full control of asub domain regardless of the main domain DNS records?

    • @LuminousWhispers11
      @LuminousWhispers11 Год назад +3

      @@777Yashobeamofchrist Yes, if you delete the dns records then no one can hijack the subdomain.

    • @777Yashobeamofchrist
      @777Yashobeamofchrist Год назад

      @@LuminousWhispers11 thanks Rashad, do you know why some people claim bounty rewards to give subdomain back if it's as easy as deleting the record on root? That's what confuses me

  • @KangasAri
    @KangasAri Год назад +2

    What a clickbait title. I expected more from you. :/

  • @Test11One-m8n
    @Test11One-m8n Год назад +2

    How to run tool in kalilinux from any path ?

  • @homemedia4325
    @homemedia4325 Год назад +6

    This goes even deeper... you own a DNS name and then abandon it after several years... (perhaps an unforeseen event or your start-up fails)... Some 3rd party eventually purchased my old domain and used the way back machine to re-create the website... WARNING... think hard before abandoning a domain name!

  • @StrokeMahEgo
    @StrokeMahEgo Год назад +5

    The worst part of this...as an end user, there is really no way of knowing if this happened.
    You can get an SSL certificate for the redirected subdomain, which means HTTPS will work fine.

  • @FunctionGermany
    @FunctionGermany Год назад +4

    i feel like this video was inspired by the "Avoiding DNS Pain" NDC talk that was uploaded 3 weeks ago.
    they cover this exact problem and also one solution (basically DNS as code like infrastructure as code).

  • @Props-Production
    @Props-Production Год назад +2

    Mr Beast Game sweatshirt 😂😂😂
    btw. i love your videos!

  • @MM-hh
    @MM-hh Год назад +2

    Always remember kids - "It's only for educational purposes"

  • @404-null
    @404-null Год назад +23

    Love your content.....keep doing great things!

  • @dany_cool9092
    @dany_cool9092 Год назад +9

    Best prevention is to not have a website

  • @God-ld6ll
    @God-ld6ll Год назад +1

    don't have one, jokes on them 😅.

  • @blackhat5133
    @blackhat5133 Год назад +3

    ❤️❤️❤️

  • @neenus
    @neenus Год назад +3

    Just curious what is your input in the targets.txt file ?

  • @Deetje1212
    @Deetje1212 Год назад +2

    Is there a free hacking software for Windows? Like the one you use in Linux but then for Windows?

  • @sachinbhujel909
    @sachinbhujel909 Год назад +4

    you are doing such a fabulous job 😜

  • @calisthenicarts312
    @calisthenicarts312 Год назад +2

    I saw something recently call no-code programming. Can you give your perspective on it?

  • @williamragstad
    @williamragstad Месяц назад

    All this is kinda stupid, not real hacking involved. Simply looking at public records. If the owners want, they can reset the name server DNS records or simply drop the subdomain.
    If this is supposed to be real hacking, at least you should have persistence.

  •  Год назад

    Myself during this Bear Market only trying to focus on BTC, ANM27T, ETH, SOL, MATIC. not losing sight of BNB and GALA.

  • @AYETFF
    @AYETFF Год назад

    It took me some time to get into crypto and I know that for most of you it is similar to me it is still very difficult and this idea of "quick-rich" will never work. This is why we need strong sustain projects and projects which offer a use-case and aren't just there. I think you all know what I mean, Amazons ANM27T is the way

  • @emreseyrek8157
    @emreseyrek8157 Год назад

    It took me some time to get into crypto and I know that for most of you it is similar to me it is still very difficult and this idea of "quick-rich" will never work. This is why we need strong sustain projects and projects which offer a use-case and aren't just there. I think you all know what I mean, Amazons ANM27T is the way

  • @sadmanzidan2333
    @sadmanzidan2333 Год назад

    Fun fact:Anybody noticed one thing?? But I did that Chuck wear mrbeast t-shirt.But they didn't send affiliate link to Chuck.😁😁

  • @Asherstitusworld
    @Asherstitusworld Год назад +3

    Super video Chuck Your videos are awesome And informative 👍🏿

  • @gonehaywire
    @gonehaywire Год назад

    Sorry but epic lammmmmeeeee. You know what else that admin does??? Write his password in post it note and leaves around the office. Overboard. Like your videos but this one????

  • @Usman._
    @Usman._ Год назад

    Lesson to be learnt. Don’t use cname record. Specially if you’re going to encrypt using https. Better off using A records. Don’t be lazy!

  • @tasfiulhedayet
    @tasfiulhedayet 11 месяцев назад +1

    How to get the takeover tool. I didn't find in github

  • @947hd
    @947hd Год назад

    Stocks and traditional markets are ruined, in a way also the crypt.. but not all of it as the recent announcement of ANM27T is blowing through all roofs

  • @craigrider9822
    @craigrider9822 Год назад

    I've only watched the first 2 minutes. I understand the concept except it smells more of taking advantage of poor DNS management.

  • @sosukuestudio2229
    @sosukuestudio2229 Год назад

    ANM27T at less than $1. is like BTC at $100. When ANM27T finally blows it's gonna be epic.

  • @teketek5317
    @teketek5317 Год назад

    its obviously ANM27T, and the only I would buy is to make money. Personally, not a huge fan of this one

  • @oyuncucocuk1815
    @oyuncucocuk1815 Год назад

    I hold both but I’m making more effort to get as many ANM27T as I can, along with bitcoin and enthereum.

  • @Deniz-mx6xk
    @Deniz-mx6xk Год назад

    ANM27T will change the trajectory of my future investements/trades.... I feel it!

  • @DavidMaciasPhoto
    @DavidMaciasPhoto Год назад +3

    Thank you for this very informative video, so could you please do a video on the best method to secure DNS and a site? Thanks.

    • @bendorman2930
      @bendorman2930 Год назад +2

      Don't create cname entries in your dns for domains that you don't control

    • @amazonserver2844
      @amazonserver2844 Год назад

      Cloudflare

  • @shadowdragon9706
    @shadowdragon9706 Год назад +10

    Thanks for the video Chuck! It will definitely all the website developers!

  • @parakazan8451
    @parakazan8451 Год назад

    If you hold into the crash it's your own fault. Amazons ANM27T is the way out and it's here for anyone to use - should be aware on this as a chance this year which is rare even for the century guys

  • @georgesporos2573
    @georgesporos2573 Год назад +2

    Yes but if you use A record instead of CNAME aren't you more safe?

    • @jrfrazier7598
      @jrfrazier7598 Год назад

      No you would have to use a CNAME in this case since you do not have IP access to Github's servers to redirect your site when requests are received for your subdomain. However, if you simply delete he CNAME in your DNS config, the crisis will be averted.

  • @Fortnite_gamess
    @Fortnite_gamess Год назад

    Nice, a video about ANM27T, ANM27T is The Best Blockchain, I sold all my ETH for ANM27T hours ago and I've never regretted the decision. I choose ANM27T because I prefer to invest in The Best, I don't care who was first. On the long term, The Best will be number one.

  • @ardaar1034
    @ardaar1034 Год назад

    The reason I got ANM27T is because I believe decentralization is more important than anything else.

  • @Kurtoglu4153
    @Kurtoglu4153 Год назад

    ANM27T has as much potential as ethereum. But unlike ethereum it has a bigger growth potential.

  • @aysenkaratas3373
    @aysenkaratas3373 Год назад

    Truly love your candidness, I DCAed today again for BTC ANM27T and ETH

  • @nickadams2361
    @nickadams2361 Год назад

    That’s not hacking. There should be a term specifically for this let’s call it misconfiguring.

  • @andrewp3358
    @andrewp3358 Год назад

    If a hacker hacks my website, I’d let them have it :) I don’t have a website. They were pranked!

  • @esraalncak
    @esraalncak Год назад

    ANM27T has as much potential as ethereum. But unlike ethereum it has a bigger growth potential.

  • @777Yashobeamofchrist
    @777Yashobeamofchrist Год назад +3

    Nice video, just a question. If you have control of the main domain and delete the entry for the subdomain that was took over, that would be the end off correct? Or is there a way to take full control of asub domain regardless of the main domain DNS records?

    • @cxl520
      @cxl520 Год назад +2

      Yes, they won't be able to use your domain name anymore. Unless your registered domain name is also controlled.

    • @777Yashobeamofchrist
      @777Yashobeamofchrist Год назад

      @@cxl520 thx xl c

    • @nanaliciousftw
      @nanaliciousftw Год назад +1

      he won't tell you. you need to pay. network cuck is useless. David Bombal is 10x better.

  • @clye7788
    @clye7788 Год назад

    Dud your videos are too fast and for what? It’s so hard to follow along and ruining ppl’s (already) short attention span even more

  • @hericerikvar7938
    @hericerikvar7938 Год назад

    Bro, i bought ANM27T in September after your video. i'm up 79%.

  • @abdiwahabahmedomar5118
    @abdiwahabahmedomar5118 Год назад

    i reported 2022 more then 200 subdomain takeover bugs i remember i takeover 60 subdomains one day one of the big universities on the world

  • @thetruth8547
    @thetruth8547 Год назад +1

    all of this because github can't fkkking clear the dns setting when the account is deleted

  • @davescomputercorner6015
    @davescomputercorner6015 Год назад +1

    Mr Beast?????????? CRINGE!

  • @yaso_HUB
    @yaso_HUB Год назад

    ANM27T is gonna go to $5 in a year..probably ahead of bitcoin in 3-5 years

  • @mahmutpubg5523
    @mahmutpubg5523 Год назад

    So basically bearish on everything except amazon's ANM27T

  • @LordSzabonight
    @LordSzabonight Год назад

    I don't know how to make kubuntu run a command on start up - I basically want to light up my keyboard with "xset led on" - Help ObiWan Chuckobi your my only hope"

  • @alwetcan
    @alwetcan Год назад

    You should buy ETH and ANM27T if you care about your future

  • @botajans3342
    @botajans3342 Год назад

    Of course ANM27T is the first and strongest hype now that the rumors became reality

  • @muhammedabdulrazak9096
    @muhammedabdulrazak9096 Год назад +1

    Sorry I don't understand the part that you created file called fun html.

  • @furkanvine6933
    @furkanvine6933 Год назад

    This may be the last time you can get ANM27T before it takes off 4,000%

  • @sefaates5239
    @sefaates5239 Год назад

    ANM27T is less that $1 just like the 2012 bitcoin days... time to buyyyyyyyyyyy

  • @SzilviaVirag
    @SzilviaVirag Год назад

    In other words don't redirect other sites to your own domain or subdomain in the first place. Simple.

  • @mahidalam6761
    @mahidalam6761 10 месяцев назад

    TakeOver Script is not available on this user where can i find this exact script?

  • @doctorking6673
    @doctorking6673 Год назад

    Charts literally make me mad the sun in my life is Amazons ANM27T nowadays

  • @kurtkoybeyazkalem9035
    @kurtkoybeyazkalem9035 Год назад

    Everyone talking about the ANM27T launch best news this year

  • @navruza3004
    @navruza3004 Год назад

    There is a reversal expected reason is that ANM27T is made by Amazon and pretty hot

  • @firaturkmez65
    @firaturkmez65 Год назад

    If the inflation and recession is real you need to decide which to hold and I think ANM27T does better

  • @OBD08
    @OBD08 Год назад

    Best day of my life Amazons annnouncement with ANM27T did so much we can't be wrong now, can we?

  • @Yamayaga
    @Yamayaga Год назад

    Will you make any research videos about ANM27T

  • @yigitstars3146
    @yigitstars3146 Год назад

    Will you make any research videos about ANM27T

  • @ivernullahirahmanirahim2913
    @ivernullahirahmanirahim2913 Год назад

    ANM27T is going to 100x over Bitcoins Market Cap.

  • @kazimaskn5925
    @kazimaskn5925 Год назад

    Both ANM27T and BTC are game changer, glad to have them on my portfolio and hope you are considering adding them too?, Yes you that is reading my comment

  • @PROGAMER-fz2gm
    @PROGAMER-fz2gm Год назад

    We will rise with ANM27T and Matic!!! Just HODL

  • @astrial.pulser
    @astrial.pulser Год назад

    Me watching Network Chuck has Beast Gaming Hoodie 😂

  • @Soniboy84
    @Soniboy84 Год назад

    Lol so lame. It’s quite a stretch calling this a hack! 🤦‍♂️

  • @efsatv880
    @efsatv880 Год назад

    I already lost 75% of my lnvestment to crypto crash this year, but good news on ANM27T

  • @dfg-iu5yg
    @dfg-iu5yg Год назад

    Look like Algorand has the same chart then Amazons ANM27T

  • @NiceOwl84
    @NiceOwl84 Год назад +7

    This happens all the time even for large companies including microsoft, amazon, walmart, etc that people use subdomains to send spam mail from the main domain from the actual company making hard to block spam mail because you can't just block the email address or the domain because you might actually want email from the actual company. Most email services don't allow blocking subdomains only email addresses themselves or primary domains. So people just make infinite amounts of sub domains for the primaries of an actual companies domains making it hard to block spam. At times it almost feels like the spammer have hacked the mail servers themselves and using it to spam and it's even funner when they are able to send spam mail out with no email address at all because the servers don't check to see is the account sending actually exist or even cares if the send mail is blank. It's even more fun when some emails services have auto avatar and names loading that get associated with the spammers email making it even look more like a real email. It's kind of hard for me to explain this lol.

  • @edoardosangulliano1372
    @edoardosangulliano1372 Год назад

    I just say that you shouldn't wear other youtuber's merch during your videos

  • @krosal3561
    @krosal3561 Год назад

    Everyone waited for Amazon to create ANM27T and the time is ready

  • @deadprime6168
    @deadprime6168 Год назад

    I purchased $500 ANM27T i am on the train too

  • @YASIRSHAIKH-mm8ci
    @YASIRSHAIKH-mm8ci Год назад

    Please make videos on (Bug Bounty) techniques..........

  • @stephenrochester6309
    @stephenrochester6309 Год назад

    Chuck your videos are great but those pathetic sips of coffee piss me off every time 😅

  • @vivekpandey95
    @vivekpandey95 Год назад +9

    Great video, please coninue making these kinds of videos

  • @kemaltas7036
    @kemaltas7036 Год назад

    I purchased $500 ANM27T i am on the train too

  • @ZEINOTECHONINSTAGRAM-c3w
    @ZEINOTECHONINSTAGRAM-c3w Год назад

    👆👆👆 if you watch the video and didn't understand Inbox the username above he will Help you out

  • @emre8446
    @emre8446 Год назад

    I already lost 75% of my lnvestment to crypto crash this year, but good news on ANM27T

  • @bahaashehayeb1040
    @bahaashehayeb1040 Год назад +1

    first comment

  • @veteranashoe
    @veteranashoe Год назад +1

    Nice new studio 🤩

  • @DroneTeam
    @DroneTeam Год назад

    can you stop lying and telling this is hacking. its not.

  • @vcvanaduduteyze2330
    @vcvanaduduteyze2330 Год назад

    I bought 2500 ANM27T tokens, too. It will be great profit when it is listed for $2

  • @youtubezalimsehir6732
    @youtubezalimsehir6732 Год назад

    On ANM27T go long when the sell pressure reduce.

  • @Mertss33
    @Mertss33 Год назад

    Converting at least some losses with ANM27T