Code Monkey home page Code Monkey logo

Comments (15)

Mouja0412 avatar Mouja0412 commented on August 24, 2024 2

Hello @codingo
I managed to takeover a subdomain, I had this fingerprint "Only one step left!
To finish setting up your new web address, go to your domain settings, click "Add existing domain", and enter: yourdomainname

Verify if the name of the store is available or not
Add your domain without the www's under Online store > Domains.

https://medium.com/@thebuckhacker/how-to-do-55-000-subdomain-takeover-in-a-blink-of-an-eye-a94954c3fc75

subdomain

from can-i-take-over-xyz.

codingo avatar codingo commented on August 24, 2024 1

This isn't really a new fingerprint, it's an edge case. Tested this now and it requires the store to be created, but never linked to the domain. Even if the shop is in the portal with a status of "not connected" (i.e. added to any account in advance of DNS), it can not be taken over.

Going to call this an edge case since there's some truth to it, but I think it's a fairer assessment to say it's not vulnerable as it's such an unlikely scenario that somebody would point DNS before adding their domain into their account.

from can-i-take-over-xyz.

FalcoXYZ avatar FalcoXYZ commented on August 24, 2024 1

Just took over a subdomain with "Only one step left" fingerprint. Same procedure as Mouja0412

from can-i-take-over-xyz.

xElkomy avatar xElkomy commented on August 24, 2024 1

Shopify is Still Vulnerable ❤️

from can-i-take-over-xyz.

Attacker991 avatar Attacker991 commented on August 24, 2024 1

"Upon visiting the domain, I received the message "Sorry, this store is currently unavailable." However, Shopify indicates that the same domain, flagged as vulnerable to takeover by Nuclei, is currently in use. Can someone clarify this discrepancy and its implications for subdomain takeover?

from can-i-take-over-xyz.

codingo avatar codingo commented on August 24, 2024

Resolved in #52

from can-i-take-over-xyz.

marcelo321 avatar marcelo321 commented on August 24, 2024

hello @codingo,

I have found several subdomains that had the fingerprints:

Sorry, this shop is currently unavailable.

But when visiting the CNAME, it showed a perfectly working shop in shopify.

So shop.example.com was giving me "shop is currently unavailable" but when visiting example.myshopify.com it was a perfectly working shop.

Is this still vulnerable?

from can-i-take-over-xyz.

NagliNagli avatar NagliNagli commented on August 24, 2024

I tookover a domain like the example above as well.

from can-i-take-over-xyz.

h4ckdi avatar h4ckdi commented on August 24, 2024

I just managed to takeover subdomain with fingerprint "Only one step left!

from can-i-take-over-xyz.

wicked-wick avatar wicked-wick commented on August 24, 2024

I did the same as explained above ? will this be accepted?

from can-i-take-over-xyz.

wouterdedroog avatar wouterdedroog commented on August 24, 2024

I recently had a subdomain takeover on Shopify as well as described above

from can-i-take-over-xyz.

ibk96 avatar ibk96 commented on August 24, 2024

Date: 04/09/2022

I takeover one.

from can-i-take-over-xyz.

sl4x0 avatar sl4x0 commented on August 24, 2024

I take over a subdomain called: https://shop.target.de/ and It has all the mentioned fingerprints.
image

from can-i-take-over-xyz.

Attacker991 avatar Attacker991 commented on August 24, 2024

.

from can-i-take-over-xyz.

WadQamar10 avatar WadQamar10 commented on August 24, 2024

Shopify is not vulnerable to Subdomain Takeover anymore right? Because i faced this message in the photo, when i tried to takeover a subdomains

IMG_٢٠٢٤٠٧١٧_١١٥٣١٨

from can-i-take-over-xyz.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.