PentestPad / subzy

Subdomain takeover vulnerability checker

Home Page:https://www.pentestpad.com

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Not Vulnerable Domain showing as Vulnerable

themarkib opened this issue · comments

Hi team,

When i am running subzy i am getting output as Vulnerable to takeover though it have Not Vulnerable status in fingerprint.json
I am getting Vulnerable takeover of Unbounce and Acquia only.All other things are fine.

takeme1

fingerprint.json

{
    "Engine": "Unbounce",
    "Status": "Not vulnerable",
    "Fingerprint": "The requested URL was not found on this server",
    "Discussion": "https://github.com/EdOverflow/can-i-take-over-xyz/issues/11",
    "Documentation": "Not available",
    "False_Positive": [
      "That’s all we know."
    ]
}

Hi @themarkib, we are working on optimizing fingerprints to reduce false positives, but for a temporary fix - you can always manualy remove Unbounce and Acquia from fingerprint.json