can-i-take-over-xyz
can-i-take-over-xyz copied to clipboard
Domain takeover via wix.com
Service name
https://www.wix.com/
Proof
#Fingerprint Looks Like This Domain Isn't Connected To A Website Yet!
#Steps
- Register to wix
- Create a new site
- Publish > Connect your own customized domain (Need premium account)
- Add the vulnerable domain
- Publish
#NOTE for subdomains "You cannot connect a subdomain in your Wix account if the main domain is in a different Wix account. You must create the subdomain in the same Wix account as the main domain." https://support.wix.com/en/article/connecting-a-subdomain-to-a-site-in-your-wix-account
Cheers Kenziy
This is an edge case. It would only work if the account was deleted.
I still have a premium account if someone wants to test the take over.
More info: https://hackerone.com/reports/1256389
Wix.com - not Vulnerable #245
Can I please have your account for a test?
I can confirm this takeover still works. It's an edge case since there are conditions that allow the subdomain to be register in another account.
I did the take over on a particular subdomain and only worked, all the others (same program) didn't work.
Hi,
It's possible even if the root domain is in another account. When you publish your site and have a premium account, go to connect a domain.
Then choose I'm looking for a subdomain :
When you enter your subdomain, you will have some step to complete like connect to your root domain account and add DNS/CNAME but they are already done by the target team.

So just go at the end and click verify.

Even after that, you will maybe see nothing but just go to https://manage.wix.com/account/domains and you will see that verification passed but it's again under check. I think the wix support team double check manually to validate ? You will have your response after 48 hours.

I think if we can impersonate the target, or maybe due to wix support mistakes, you can takeover the subdomain even if the main domain is in a different account.
Does anyone has a premium account I can check with please?
It doesn't work, If another account have the domain
How can I know if another account has the domain without having premium account 😅💔
How can I know if another account has the domain without having premium account 😅💔
you have to buy 🤷♂️ You can request refund after trying. The monthly package is not so expensive i think :)
please provide wix-takeover bug report format .
This is an edge case. It would only work if the account was deleted.
I still have a premium account if someone wants to test the take over.
HI there could please help I need to test that would also help the community.
I tried this rn and got domain connected to different account. Despite having a moneyback opportunity, I copied some endpoints that can show is domain available or not. I do my tests against root domain, so for subdomain it may vary. You can use it even without premium plan
I show JSON body for domain google.net
as example
POST /_serverless/premium-domains-serverless/domain-search/domain-data HTTP/1.1
Host: manage.wix.com
Cookie: <COOKIES>
{"parsedDomain":{"input":"google.net","main":"google.net","tld":"net","sld":"google","subdomain":null,"isValidTld":true,"formattedInput":"google.net"}}
JSON body variables pretty obviously, so you can try for subdomain, just insert your parts of the domain
Is it still vulnerable? If can someone help me exploit a sub? reach out via Twitter sl4x0
Can anyone help me for testing takeover with premium account? my twitter: @waeldevx