Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

2.2 KiB

API Reference: Broken Link Hijacking

Concept

Broken Link Hijacking (BLH) occurs when a website links to external resources that no longer exist. An attacker can register the expired resource (domain, GitHub repo, npm package) to serve malicious content via the trusted site.

Hijackable Platforms

Platform Hijack Vector
GitHub Register abandoned username/repo
npm Publish unclaimed package name
PyPI Register unclaimed package
Twitter/X Claim abandoned handle
BitBucket Register abandoned team/repo
Custom domain Register expired domain

HEAD Request

import requests
resp = requests.head(url, timeout=10, allow_redirects=True, verify=False)
# 404 = broken link, potential hijack

Connection Error = Domain Takeover

try:
    requests.head(url, timeout=5)
except requests.ConnectionError:
    print("Domain may be unregistered - takeover possible")

Regex Patterns

import re
# href links
re.finditer(r'href=["\']([^"\']+)', html)
# src links
re.finditer(r'src=["\']([^"\']+)', html)

Domain Availability Check

WHOIS Lookup

whois expired-domain.com
# "No match for" = available for registration

DNS Check

dig expired-domain.com +short
# Empty = no DNS records (likely available)

GitHub API — Check Username Availability

Check user exists

GET https://api.github.com/users/username
  • 200 = exists
  • 404 = available for registration

Check repo exists

GET https://api.github.com/repos/owner/repo

npm Registry — Check Package

GET https://registry.npmjs.org/package-name
  • 200 = exists
  • 404 = available for registration

Subdomain Takeover Indicators

CNAME to Unclaimed Service

dig CNAME old-service.example.com
# old-service.example.com. CNAME  unregistered.herokuapp.com.

Common Vulnerable Services

Service Indicator
GitHub Pages 404 "There isn't a GitHub Pages site here"
Heroku "No such app"
AWS S3 "NoSuchBucket"
Azure "404 Web Site not found"
Shopify "Sorry, this shop is currently unavailable"