subdomain.md https://www.hackerone.com/blog/Guide-Subdomain-Takeovers ã®ç¿»è¨³ 以åã«ãµããã¡ã¤ã³ã®ä¹ã£åããè¡ã£ããã¨ããªããã¾ãã¯æ°ããããããã¨æã£ã¦ãã人ã®ããã åºæ¬çãªèª¬æã«å½¹ç«ã¤ã·ããªãªä¾ãèæ¡ãã¾ããã ãã®ã·ããªãªã§ã¯ãexample.comãã¿ã¼ã²ããã§ãããexample.comãéå¶ãããã¼ã ã«ãã°ãã¦ã³ãã£ããã°ã©ã ãããã¨ä»®å®ãã¾ãã example.comã«å±ãã¦ãããã¹ã¦ã®ãµããã¡ã¤ã³ï¼å¾ã§æ¤è¨ããããã»ã¹ï¼ãåæãã¦ããéã«ã ããã«ã¼ã¯subdomain.example.comã¨ããGitHubãã¼ã¸ãæã示ããµããã¡ã¤ã³ãè¦ã¤ãã¾ãã ãµããã¡ã¤ã³ã®DNSã¬ã³ã¼ãã確èªãããã¨ã§ãããå¤æã§ãã¾ãã ãã®ä¾ã§ã¯ãsubdomain.example.comã«ã¯ãGitHubã®ã«ã¹ã¿ã ãã¼
æ¨ä»ãæ¥éã«å¤ãããããµã¤ãã¼æ»æã«å¯¾å¿ããããã«ã¯ãäºè¦ã»äºæ¸¬ã«ããæªç¶ã®ã»ãã¥ãªãã£å¯¾çãæ±ãããã¦ãã¦ãã¾ããã¨ã¯ããããµã¤ãã¼æ»æãå èªã¿ããã®ã¯æ¥µãã¦å°é£ã§ãããæåãªã»ãã¥ãªãã£ãã³ããã»ãã¥ãªãã£çµç¹ã§ããããµã¤ãã¼ç¯ç½ªè ã®å¾æã«åã£ã¦ããã®ãå®æ ã§ããããããOSINT(open source intelligence)ãæ´»ç¨ãããã¨ã§ããµã¤ãã¼æ»æã®ãäºå ãã¯è£è¶³ãããã¨ãåºæ¥ãããããã¾ãããOSINTã¨ã¯ãã¤ã³ã¿ã¼ãããä¸ã«å ¬éãããè å¨æ å ±(è å¨ã¤ã³ããªã¸ã§ã³ã¹)ãåéããææ³ãæãã¾ããOSINTã¯ãåºæ¬çã«ã¯ã¤ã³ã¿ã¼ãããä¸ã«ç¡åã§å ¬éããã¦ãããä¸ã¤ã®æ å ±ããé¢é£æ§ã®ããæ§ã ãªè å¨æ å ±ãåéãããã¨ãå¯è½ã§ãããã®ä»çµã¿ãæ´»ç¨ãããã¨ã§ãããä¸ã¤ã®è å¨æ å ±ããé¢é£æ å ±ãåéããããã¾ä½ãèµ·ãããã¨ãã¦ããã®ããã¨ããè å¨ã®äºå ãè£è¶³ãããã¨ã«æå¾ ãã§ããããã
ãç¥ãã
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}