// the find
nahamsec/HostileSubBruteforcer
A Ruby script that brute-forces subdomains from a wordlist, resolves them, and flags any whose CNAME points at a third-party host that looks unclaimed, the usual dangling-DNS subdomain takeover pattern. It is aimed at bug bounty hunters and people auditing their own domains. The last push was January 2021, so treat it as a reference for the technique rather than a current tool.
- Each finding quotes the provider's own error text, such as 'NoSuchBucket' for S3 or 'There isn't a GitHub Pages site here' for GitHub Pages. A reviewer can check the candidate by eye instead of trusting a bare flag.
- It recurses into the subdomains it finds, so a hit on a shallow name can lead to deeper ones that a flat wordlist would miss.
- Each run starts a fresh output.txt, so a crash partway through still leaves the results gathered so far.
- Provider error pages and fingerprint strings have changed since 2021, so expect missed takeovers and some stale matches. Nothing in the repo suggests they have been revalidated.
- Coverage is six services (AWS, GitHub, Heroku, Shopify, Tumblr, Squarespace). The README's own example output shows WPEngine results, which the detection list does not include, so the example overstates what the tool does.
- The --fast threaded mode is marked experimental and its output is not synchronised, as the README admits. Lines from different threads can interleave, so use the default mode for anything you plan to act on.
- A fingerprint match only means the target looks unclaimed. The tool does not confirm that the resource can actually be claimed, and the README itself warns of false positives. Verify by hand before reporting.