Skip to content

Check for domain takeover of NPM dependencies from a map file

License

Notifications You must be signed in to change notification settings

ExcelliumSA/MapOver

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

5 Commits
 
 
 
 
 
 

Repository files navigation

MapOver

The aim of that tool is to find a possible domain takeover via a map file.

The map file allows getting all the dependencies used by the application, after that it could be possible to get the list of all the maintainers of these packages. Once all emails were retrieved, it could be possible to check if the domain name use is still used or if it could be bought ... and perform a domain takeover of the NPM account.

That tool is the application of what is explained on that blog post.

It was just created and used as a PoC for a customer project. The takeover and the exploitation were not done as it was out of scope. Therefore, it could be possible that some bug of issues are present on that script and the corresponding methodology.

Disclaimer

Do not use the result of that script for illegal purpose.

About

Check for domain takeover of NPM dependencies from a map file

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages