A tool which analyses past TLS certificates for a website and checks which other domains are closely tied to it.
Switch branches/tags
Nothing to show
Clone or download
Latest commit 480ae4d Nov 30, 2018
Permalink
Type Name Latest commit message Commit time
Failed to load latest commit information.
README.md changed to use CT logs Aug 18, 2018
main.js Modify results format Nov 30, 2018

README.md

Cloudflare SAN Scan

A tool which analyses past TLS certificates for a website and checks which other domains are closely tied to it.

How to run

node main.js domain

What does it do?

The tool shows you other domains which are likely to be linked to the domain you are checking. It will only work for websites which use Cloudflare.

How does it work?

Cloudflare provides a free TLS certificate for every domain. These certificates have up to 50 different domains assigned to them using Subject Alternative Name (SAN). If you add multiple domains to the same Cloudflare account, they will be grouped together and assigned to the same certificate. This means that if two domains are on the same account, they will always have the same certificate. Cloudflare SAN Scan looks through past TLS certificates and determines which other domains are likely to be on the same Cloudflare account.