NSBrute
A Python utility that identifies and exploits domains vulnerable to AWS name server takeover attacks by detecting misconfigured DNS settings.

NSBrute
A Python utility that identifies and exploits domains vulnerable to AWS name server takeover attacks by detecting misconfigured DNS settings.
NSBrute Description
NSBrute is a Python utility designed to identify and exploit domains vulnerable to AWS NS (Name Server) takeover attacks. The tool automates the process of discovering misconfigured DNS settings where domain name servers point to AWS resources that are no longer active or properly configured. This creates an opportunity for attackers to register the abandoned AWS resources and gain control over the domain's DNS resolution. NSBrute operates by scanning target domains and checking for vulnerable NS configurations that could allow unauthorized takeover of DNS control. The utility focuses specifically on AWS-hosted name servers that may have been decommissioned or improperly configured, leaving domains susceptible to subdomain takeover attacks. The tool is implemented in Python and provides functionality for security researchers and penetration testers to assess domain configurations for potential NS takeover vulnerabilities in AWS environments.
FEATURED
Password manager with end-to-end encryption and identity protection features
VPN service providing encrypted internet connections and privacy protection
Fractional CISO services for B2B companies to accelerate sales and compliance
Stay Updated with Mandos Brief
Get the latest cybersecurity updates in your inbox
TRENDING CATEGORIES
POPULAR
Security platform that provides protection, monitoring and governance for enterprise generative AI applications and LLMs against various threats including prompt injection and data poisoning.
A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.