/takeover
Scan subdomains for takeover candidates (dangling CNAMEs to GitHub Pages, S3, Heroku, Shopify, etc.). Wraps dnsReaper (best signal) and subjack (fast Go fallback). With no scanner installed, runs a built-in fingerprint grep over a curated set of providers. Usage: /takeover
$ npx -y skills add shuvonsec/claude-bug-bounty --agent claude-codeHow it fires
How this command gets triggered: by you, by Claude, or both.
- Fires itselfClaude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/takeover
Context preview
What this command does when you run it.
Scan subdomains for takeover candidates (dangling CNAMEs to GitHub Pages, S3, Heroku, Shopify, etc.). Wraps dnsReaper (best signal) and subjack (fast Go fallback). With no scanner installed, runs a built-in fingerprint grep over a curated set of providers. Usage: /takeover
Command definition
takeover.mddescription: Scan subdomains for takeover candidates (dangling CNAMEs to GitHub Pages, S3, Heroku, Shopify, etc.). Wraps dnsReaper (best signal) and subjack (fast Go fallback). With no scanner installed, runs a built-in fingerprint grep over a curated set of providers. Usage: /takeover <subdomains-file> | /takeover --recon <recon-dir>
/takeover
Find subdomains pointing at services you can claim and serve content from.
Usage
/takeover recon/target.com/subdomains/all.txt
/takeover --recon recon/target.com # equivalent
How it works
`tools/takeover_scanner.sh` tries each strategy in turn:
1. **dnsReaper** (`punk-security/dnsReaper`) — broadest fingerprint set, JSON output. 2. **subjack** (`haccer/subjack`) — fast Go scanner. 3. **Curl + fingerprint grep** fallback — minimal coverage but always runs.
Scoring & submission
Subdomain takeover sits high on most program reward tables — typically **$500–$5,000** depending on what the parent brand uses the subdomain for. Before submitting:
- Confirm the dangling target service is actually claimable today (Heroku and
GitHub Pages are easy; some providers now block re-claims by name).
- Take **only** the screenshot you need to prove control — never serve real
content or interact with users from the claimed subdomain.
- Cross-reference `EdOverflow/can-i-take-over-xyz` for the per-provider claim
instructions and known-good fingerprints.
Output
`findings/takeover/<timestamp>/` with raw scanner JSON / text plus a `fingerprint_grep.txt` summary of suspicious responses.
Read more
description: Scan subdomains for takeover candidates (dangling CNAMEs to GitHub Pages, S3, Heroku, Shopify, etc.). Wraps dnsReaper (best signal) and subjack (fast Go fallback). With no scanner installed, runs a built-in fingerprint grep over a curated set of providers. Usage: /takeover <subdomains-file> | /takeover --recon <recon-dir>
/takeover
Find subdomains pointing at services you can claim and serve content from.
Usage
/takeover recon/target.com/subdomains/all.txt /takeover --recon recon/target.com # equivalent
How it works
`tools/takeover_scanner.sh` tries each strategy in turn:
1. **dnsReaper** (`punk-security/dnsReaper`) — broadest fingerprint set, JSON output. 2. **subjack** (`haccer/subjack`) — fast Go scanner. 3. **Curl + fingerprint grep** fallback — minimal coverage but always runs.
Scoring & submission
Subdomain takeover sits high on most program reward tables — typically **$500–$5,000** depending on what the parent brand uses the subdomain for. Before submitting:
- Confirm the dangling target service is actually claimable today (Heroku and
GitHub Pages are easy; some providers now block re-claims by name).
- Take **only** the screenshot you need to prove control — never serve real
content or interact with users from the claimed subdomain.
- Cross-reference `EdOverflow/can-i-take-over-xyz` for the per-provider claim
instructions and known-good fingerprints.
Output
`findings/takeover/<timestamp>/` with raw scanner JSON / text plus a `fingerprint_grep.txt` summary of suspicious responses.
AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Code.
Repo: shuvonsec/claude-bug-bounty
Other commands on claude-bug-bounty.
- /arsenal
Show which external bug-bounty tools are installed on this machine and print install hints for the missing ones. Curated from high-signal repos. Use to bootstrap a fresh box or audit which optional capabilities are wired in. Usage: /arsenal | /arsenal <tool-name>
Open command - /autopilot
Run autonomous hunt loop on a target — scope check → recon → rank surface → hunt → validate → report with configurable checkpoints. Usage: /autopilot target.com [--paranoid|--normal|--yolo]
Open command - /breach-check
HIBP k-anonymity check on a password wordlist. Enriches each password with its breach count, ranks DESC. Free API (no key), only first 5 chars of SHA-1 sent. Output -> <input>-ranked.txt. Usage /breach-check <wordlist> [--min-count N] [--max-count N] [--with-counts]
Open command - /bypass-403
Probe a 403/401 endpoint with the most-paid bypass tricks (header injection, path encoding, method swap, WAF fingerprint, vendor-specific). Wraps byp4xx when installed; otherwise runs a built-in matrix of 38+ techniques. Usage: /bypass-403 <url> | /bypass-403 -l <urls-file>
Open command - /chain
Build an exploit chain — given bug A, finds B and C to combine for higher severity and payout. Knows common chain patterns: IDOR→ATO, SSRF→cloud metadata, XSS→ATO, open redirect→OAuth theft, S3→bundle→secret→OAuth. Usage: /chain
Open command - /cloud-recon
Sweep cloud assets for a target — public S3/Azure/GCP buckets via S3Scanner and cloud_enum, plus CloudFlare-bypassed origin IPs via CloudFail (or built-in DNS-history fallback). Use --keyword for storage discovery and --cf-bypass to find an origin IP behind CloudFlare. Usage:
Open command

