/** * Subdomain takeover detection patterns. * * When a DNS CNAME record points to a third-party service (e.g., Heroku, * GitHub Pages, S3) but the resource on that service has been deleted or never * provisioned, an attacker can register the same resource and serve arbitrary * content on the victim's subdomain. * * Each entry contains CNAME target regex patterns and response fingerprints * (body text, HTTP status, headers) that confirm the resource is unclaimed. * * References: * - https://github.com/EdOverflow/can-i-take-over-xyz * - https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/10-Test_for_Subdomain_Takeover */ /** A subdomain takeover detection entry for a specific hosting service. */ export interface TakeoverPattern { /** Name of the hosting / SaaS service */ service: string; /** Regex patterns that match the CNAME target hostname */ cnamePatterns: string[]; /** Response fingerprints that confirm the resource is unclaimed */ fingerprints: { /** Body content patterns (regex) indicating an unclaimed resource */ body?: string[]; /** Expected HTTP status code for unclaimed resources */ status?: number; /** Header patterns (name → regex) on the error response */ headers?: Record; }; /** Risk severity — high means trivially exploitable with no auth */ severity: "high" | "medium" | "low"; /** Reference URL for takeover documentation / proof-of-concept */ documentation?: string; } export declare const TAKEOVER_PATTERNS: TakeoverPattern[]; //# sourceMappingURL=takeover-patterns.d.ts.map