data:image/s3,"s3://crabby-images/7e228/7e2287ba60e21dee87416ea9983ec241b5307ec2" alt="vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance"
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Fast, Elegant subdomain scanner using nodejs
If you want to use it as cli tool, you must install it globally first:
sudo npm install -g subquest
Usage: subquest [options] <domain to scan>
Examples:
subquest google.com
subquest facebook.com -s 8.8.8.8 -r 20 -d top_50
subquest twitter.com -s 8.8.8.8 -d all
Options:
-h, --help output usage information
-V, --version output the version number
-b, --bingSearch use Bing search to list all possible subdomains
-s, --server [ip] specify your custom DNS resolver
-r, --rateLimit [limit] set the Rate Limit [Default value is 10]
-d, --dictionary [type] set the dictionary for bruteforcing [top_100]
If you want to use it as a node module you can install and add it to your project dependencies:
npm install subquest
Than you can require it in your script and use various methods:
var subquest = require('subquest');
subquest
.getSubDomains({
host: 'google.com', // required
rateLimit:'4', // four requests at time
dnsServer:'4.2.2.2', // custom DNS server
dictionary: 'top_200' // dictionary file to use
})
.on('end', function(res){
console.log(res); // array of subdomains.
})
This scans google.com for the list of all subdomains using the top_200 dictionary.
Add your list of subdomain names to the ./dictionary/all.txt
file and send a pull request.
FAQs
Fast, Elegant subdomain scanner using nodejs
The npm package subquest receives a total of 41 weekly downloads. As such, subquest popularity was classified as not popular.
We found that subquest demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.