Try It Now

Tag: attack surface

Subdomain takeover explained — a dangling CNAME on your domain still points at a third-party service that released the name, letting someone else serve content from your subdomain | SelfHack AI

Subdomain Takeover: How Dangling DNS Records Hand Attackers Your Domain

Subdomain takeover: how a dangling CNAME lets someone else serve content on your domain, how to find them safely, and how to prevent the next.

Read More
How to check open ports on your own domain safely and legally — listening services, firewall reachability, nmap and ss on assets you own | SelfHack AI

How to Check Open Ports on Your Own Servers (and What to Close)

How to check open ports on infrastructure you own: the commands that work, what each exposed service means, and the decision rule for what to close.

Read More
How to find subdomains of a domain — passive OSINT sources including Certificate Transparency logs, DNS records, passive DNS and web archives feeding a subdomain inventory | SelfHack AI

How to Find Subdomains: A Practical Guide to Mapping Your Own Attack Surface

How to find subdomains of a domain you own: certificate transparency, passive DNS, brute force and resolution — plus what to do with the list you get.

Read More
Free security checks — six things to test on your own domain: subdomains, security headers, DMARC, open ports, subdomain takeover and SSL TLS | SelfHack AI

Free Security Checks: 6 Things to Test on Your Own Domain

Free security checks: six tests you can run on your own domain today — subdomains, headers, DMARC, open ports, dangling DNS and TLS, with real commands.

Read More