Giter VIP home page Giter VIP logo

Comments (36)

ByQwert avatar ByQwert commented on August 11, 2024 7

Weblow requires a TXT verification.
image

from can-i-take-over-xyz.

x1mdev avatar x1mdev commented on August 11, 2024 6

I was able to claim a dangling Webflow subdomain just now; CNAME pointed from sub.victim.com to proxy-ssl.webflow.com. I've added the subdomain to my existing paid Webflow account, set it to Default and published content. Navigating to sub.victim.com confirms that my content is placed on the subdomain. It does not work if you set up a new project with Starter functionality; it will tell you that the domain is already in use.

Apparently, this is a pay2win Subdomain Takeover :p

from can-i-take-over-xyz.

testusername911 avatar testusername911 commented on August 11, 2024 3

You can claim a subdomain but needs TXT verification which means you cannot publish a site so it is useless (takeover not possible).. unless someone finds a "bypass" in the future.
Screenshot 2024-01-17 at 4 39 40 PM

from can-i-take-over-xyz.

0xc0ffeee avatar 0xc0ffeee commented on August 11, 2024 2

This is not vulnerable. I just tried it on an endpoint that was hosted on Webflow and had 404 on both HTTP and HTTPS.
webflow

from can-i-take-over-xyz.

PjMpire avatar PjMpire commented on August 11, 2024 2

-Create webflow account and upgrade to basic paid option
-Create blank site
-Go to project settings > hosting
-Scroll down to custom domains section and add vulnerable domain

-Signature of takeover is webflow 404 same as OP.

Screenshot_3

Takeover is not possible when owner parked the custom domain but not published the site. This scenario would still produce a webflow 404 therefore can be marked as edge case.

Regards

from can-i-take-over-xyz.

PjMpire avatar PjMpire commented on August 11, 2024 2

@0xc0ffeee If the custom domain is registered but the site is not published you will see webflow 404 page but be unable to register the domain. In this scenario you will get a false positive hence my advice to update this to edge case.

webflow 1

from can-i-take-over-xyz.

szd avatar szd commented on August 11, 2024 2

Hi everyone,

Just manage to takeover several subdomains on the same target (H1 private prgm) and I have a theory explaining some false positive.

I observed a webflow 404 on several subdomains of my target:

  • aaa.victim.com
  • bbb.victim.com
  • ccc.victim.com

Webflow let me add these subdomains on my dummy website but unfortunately, when I visit them, still got webflow 404.

I thought it was false positive.

Several days later, I remember that Webflow allow to mark one of your custom domain "default":

60b6a9678bebf79daaf42a75_Set-a-default-domain_1

So if the subdomains I discovered are linked to another "default" one, I will only be able to takeover all if I found the "default" subdomain.

I'm on this target since of few month so I manage to quickly found a past webflow subdomain zzz.victim.com (Now unreachable but still in victim.com webflow account). So I added this subdomain on my own webflow account and the magic happened.

So try to see if your target has several subdomains (even old one, no more online) linked to Webflow.

from can-i-take-over-xyz.

0xc0ffeee avatar 0xc0ffeee commented on August 11, 2024 1

404_-_Page_not_found

from can-i-take-over-xyz.

saurabhss06 avatar saurabhss06 commented on August 11, 2024 1

Yes, Webflow is vulnerable. I did takeover one subdomain using it and published a write-up on this vulnerability

from can-i-take-over-xyz.

bunny0417 avatar bunny0417 commented on August 11, 2024 1

I recently reported a takeover on a program at intigriti using Webflow , but you have to buy a premium inorder to achieve this.

from can-i-take-over-xyz.

rodr-r avatar rodr-r commented on August 11, 2024 1

Hi guys is this still edge case or it is not vulnerable anymore can anyone confirm

from can-i-take-over-xyz.

MuhammadUsman-coder avatar MuhammadUsman-coder commented on August 11, 2024 1

I just tried doing takeover and i can confirm it is not vulnerable anymore .

All the options it gives to add custom domain asks for txt verification , Thus NOT VULNERABLE

from can-i-take-over-xyz.

Avileox avatar Avileox commented on August 11, 2024

Thank you for the update, can you please show the initial screenshot of "404" page

from can-i-take-over-xyz.

Avileox avatar Avileox commented on August 11, 2024

I can confirm that it is not vulnerable anymore,
Thanks for keeping us updated.

from can-i-take-over-xyz.

PjMpire avatar PjMpire commented on August 11, 2024

Webflow sites are still vulnerable to takeover so you may want to change this

Just had a report triaged to confirm.

regards

from can-i-take-over-xyz.

Avileox avatar Avileox commented on August 11, 2024

Can you please share steps to takeover subdomain through webflow.

from can-i-take-over-xyz.

Avileox avatar Avileox commented on August 11, 2024

Thank you for the update.

from can-i-take-over-xyz.

0xc0ffeee avatar 0xc0ffeee commented on August 11, 2024

Interesting. I had a "404 Not Found" response on a webflow website but I was still not able to complete the takeover.

I would receive the following error: "That domain is already connected to a Webflow site."

Mind sharing more information without disclosing the target? @PjMpire

from can-i-take-over-xyz.

mrsin15 avatar mrsin15 commented on August 11, 2024

Hey everyone, is Webflow subdomain takeover still possible? Thanks.
@PjMpire @Avileox

from can-i-take-over-xyz.

Captain0X avatar Captain0X commented on August 11, 2024

https://university.webflow.com/lesson/connect-a-custom-domain everybody,can see this vdio~

from can-i-take-over-xyz.

pdelteil avatar pdelteil commented on August 11, 2024

@szd,

Thanks for your detailed explanation.

from can-i-take-over-xyz.

arthur4ires avatar arthur4ires commented on August 11, 2024

I just confirmed here, I managed to claim domains in a pentest.

from can-i-take-over-xyz.

abd-4fg avatar abd-4fg commented on August 11, 2024

Webflow subdomains is vulnerable to takeover only if the particular subdomain is not connected with any other webflow account.

Recently i was able to claim 4 subdomains pointing to webflow service among which three subdomain gave the following error :
Before_(404_status)
If you come across the above look alike subdomain page , then its vulnerable.

Also note that some webflow hosted vulnerable subdomains may result in Error : SSL_PROTOCOL_ERROR , when you visit them , i was able to claim this one too in my webflow account.

Keep in mind: Webflow subdomains is vulnerable to takeover only if the particular subdomain is not connected with any other webflow account.
Hosting domain is in paid plan of webflow $15/month.

from can-i-take-over-xyz.

Captain0X avatar Captain0X commented on August 11, 2024

from can-i-take-over-xyz.

0xmaruf avatar 0xmaruf commented on August 11, 2024

I was able to claim a dangling Webflow subdomain just now; CNAME pointed from sub.victim.com to proxy-ssl.webflow.com. I've added the subdomain to my existing paid Webflow account, set it to Default and published content. Navigating to sub.victim.com confirms that my content is placed on the subdomain. It does not work if you set up a new project with Starter functionality; it will tell you that the domain is already in use.

Apparently, this is a pay2win Subdomain Takeover :p

hi dude if target.dom.com is showing valid content and its cname is giving 404 can it be taken over???

from can-i-take-over-xyz.

codedbrain avatar codedbrain commented on August 11, 2024

I just took over a sub-domain with webflow. It works but requires a premium plan ! It's a paid sub-domain takeover ;)

from can-i-take-over-xyz.

muhammadahmad62 avatar muhammadahmad62 commented on August 11, 2024

same here still vulnerable if you have a premium account

from can-i-take-over-xyz.

rudram4 avatar rudram4 commented on August 11, 2024

hey guys @PjMpire @saurabhss06 @bunny0417
i have a website, the same error is coming but not on any subdomain, but on the domain itself,

lets say this page on the domain
https://abc.com/careers/junior-software-engineers
https://usabilityhub.com/assets/app_libraries-5eab97030d19c3cfa7406ed6d0067a.js

the same error comes and i have cross checked it is of the webflow only,
so any idea if further exploitation is possible in any way
image

from can-i-take-over-xyz.

saurabhss06 avatar saurabhss06 commented on August 11, 2024

I don't think its vulnerable or takeorable, Its a custom page.

from can-i-take-over-xyz.

zy9ard3 avatar zy9ard3 commented on August 11, 2024

Any updates on this takeover ???

Is this still possible ???

I'm experiencing enforced requirement for mandatory TXT verification !!

from can-i-take-over-xyz.

VictimV59 avatar VictimV59 commented on August 11, 2024

hey guys @PjMpire @saurabhss06 @bunny0417 do you have any idea, Is it possible to takeover this anymore? If anyone can confirm, it'll be very helpful to the community.

Thanks in advance.

from can-i-take-over-xyz.

xElkomy avatar xElkomy commented on August 11, 2024

Any updates on this takeover ???

Is this still possible ???

I'm experiencing enforced requirement for mandatory TXT verification !!

Does it still vulnerable?

from can-i-take-over-xyz.

drocapy avatar drocapy commented on August 11, 2024

hey guys ,
Does it still vulnerable?
404

from can-i-take-over-xyz.

Kools-cmd avatar Kools-cmd commented on August 11, 2024

Hi any update on this
Did you find any bypass for this ?

from can-i-take-over-xyz.

nakib85 avatar nakib85 commented on August 11, 2024

Hi guys is this still edge case or it is not vulnerable anymore can anyone confirm

???

from can-i-take-over-xyz.

nvk0x avatar nvk0x commented on August 11, 2024

Hi,

It's not vulnerable, I just tried, it will ask for txt verification

from can-i-take-over-xyz.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.