Discussion
Loading...

#Tag

  • About
  • Code of conduct
  • Privacy
  • About Bonfire
cR0w 馃 boosted
B'ad Samurai 馃悙
@badsamurai@infosec.exchange  路  activity timestamp 10 hours ago

Similar to Drift, where I used DNS TXT records to gauge my potential 3rd party blast radius, I have scanned 1300 tech domains for the common Gainsight DNS CNAME records gsemail or gsnemail.

230 domains have one or both of these entries.

It doesn't mean they were breached, use Gainsight, or weren't affected (different domain). But I like to have an idea of who I might be talking to soon.

https://github.com/BadSamuraiDev/gainsight-cname-list

#gainsight #salesforce #dns

GitHub

GitHub - BadSamuraiDev/gainsight-cname-list: List of domains with the gsemail and gsnemail cname records

List of domains with the gsemail and gsnemail cname records - BadSamuraiDev/gainsight-cname-list
Screenshot from Gainsight DNS configuration

3. Expand email header details. You have an active sender authentication policy if the value in the Mailed-by
header element displays either of the following sub-domains:
o gsemail.<yourdomain>.com
o gsnemail.<yourdomain>.com
Screenshot from Gainsight DNS configuration 3. Expand email header details. You have an active sender authentication policy if the value in the Mailed-by header element displays either of the following sub-domains: o gsemail.<yourdomain>.com o gsnemail.<yourdomain>.com
Screenshot from Gainsight DNS configuration 3. Expand email header details. You have an active sender authentication policy if the value in the Mailed-by header element displays either of the following sub-domains: o gsemail.<yourdomain>.com o gsnemail.<yourdomain>.com
  • Copy link
  • Flag this post
  • Block
B'ad Samurai 馃悙
@badsamurai@infosec.exchange  路  activity timestamp 10 hours ago

Similar to Drift, where I used DNS TXT records to gauge my potential 3rd party blast radius, I have scanned 1300 tech domains for the common Gainsight DNS CNAME records gsemail or gsnemail.

230 domains have one or both of these entries.

It doesn't mean they were breached, use Gainsight, or weren't affected (different domain). But I like to have an idea of who I might be talking to soon.

https://github.com/BadSamuraiDev/gainsight-cname-list

#gainsight #salesforce #dns

GitHub

GitHub - BadSamuraiDev/gainsight-cname-list: List of domains with the gsemail and gsnemail cname records

List of domains with the gsemail and gsnemail cname records - BadSamuraiDev/gainsight-cname-list
Screenshot from Gainsight DNS configuration

3. Expand email header details. You have an active sender authentication policy if the value in the Mailed-by
header element displays either of the following sub-domains:
o gsemail.<yourdomain>.com
o gsnemail.<yourdomain>.com
Screenshot from Gainsight DNS configuration 3. Expand email header details. You have an active sender authentication policy if the value in the Mailed-by header element displays either of the following sub-domains: o gsemail.<yourdomain>.com o gsnemail.<yourdomain>.com
Screenshot from Gainsight DNS configuration 3. Expand email header details. You have an active sender authentication policy if the value in the Mailed-by header element displays either of the following sub-domains: o gsemail.<yourdomain>.com o gsnemail.<yourdomain>.com
  • Copy link
  • Flag this post
  • Block
Log in

bonfire of thepocolips

come over, warm up. coffee?

bonfire of thepocolips: About 路 Code of conduct 路 Privacy 路
bonfire social 路 1.0.0 no JS en
Automatic federation enabled
  • Explore
  • About
  • Code of Conduct
Home
Login