Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerabile Shopify stores #127

Closed
arjunnkn opened this issue Dec 19, 2019 · 9 comments
Closed

Vulnerabile Shopify stores #127

arjunnkn opened this issue Dec 19, 2019 · 9 comments

Comments

@arjunnkn
Copy link

arjunnkn commented Dec 19, 2019

Service name

pamleftpamright.com
peterreed.com
pgpromotionalitems.co.uk
piecestopeaces.com
pillowfightfactory.com
pilovilo.com
pitbull-store.co.uk
portraydesigns.com
quantumbassmarket.com
quickmobilefix.com
rayethelabel.com
rdfabrikwerks.com
rebeccaminkoff.com
recoconyc.com
ripdiculous.com
ritualandlore.com
roughneckoutlet.com
sabithestore.us
samayhome.com
sayitwithasock.com.
seasiderug.com
seavees.com
shiokcollaborative.sg
shoewin.com
shop.thegentlemensposse.com
shopsuperdeluxe.com
shopwickliffela.com
simplepaperie.com
simplicitylaser.com
sinnersattire.com
skandiboxes.com
slaworldwide.com
smilingdesignsforkids.com
smithstreetcandles.com
sockittome.com.au
socutesocute.com
songbirdocarina.com
specialeventsparklers.com
spornette898.com
squashabout.com
squat-life.co.uk
squeekyart.com
st-roche.com
storydeals.com
straightfromthebarrel.net
streetgents.com
sugarcityspeedshop.com
suite7seven.com
sun-siesta.com
sundaeriot.com
sweetorange.shop
t2mwireless.com

Proof

All are vulnerable via Shopify service

Documentation

Attached

@melardev
Copy link

melardev commented Dec 19, 2019

I read your message, I am still trying to understand it, can you help me(or us) to understand this?
The worst thing is that I achieved to read 2 domains in that very bad quality picture, and both sites are alive.

UPDATE: I got it!!! In that very bad quality image, there are some domains that are applications built on top of Shopify, some of them(I just found one) do not exist.
But there is nothing interesting there, first, they may be or may not be vulnerable to Subdomain Takeover. Second, the report goes to those companies, not to Shopify.
Third, most of them are domains and not subdomains, so those companies don't exist anymore, so point 2 does not apply because there is no company to report to.

UPDATE2: In that image I saw you requested mediation to HackerOne because you were not happy with how Shopify closed the report, I don't know if it was closed as N/A or Spam, but at least here this post is a Spam, no hate against you, but this post is nothing more than spam.

@arjunnkn
Copy link
Author

arjunnkn commented Dec 19, 2019 via email

@arjunnkn
Copy link
Author

The report was closed as duplicate , and if you are aware of hackerone rules , they must either merge the duplicate report to the original one or acknowledge the duplicate with the original report Id . They did nothing but said that they knew the issue internally

@arjunnkn
Copy link
Author

Sorry I submitted this report month ago and all were tested at that time , coz at that time I had 20k domains fully tested . I thought it would be worth testing

@melardev
Copy link

@arjunnkn
Ok so what you reported was a design issue to Shopify because their service allows subdomain takeover?
Well, we knew that long ago, indeed if you know the hackerone rules, submitting a duplicate issue will not make any difference on your hackerone points ....
BUT ..... listen to this:
Submitting a report that is a duplicate of a known issue MAKES you lose points, so you actually should have lost points there, because this is a very known issue for all of us, however, you still went ahead and reported it to Shopify.
Source : https://docs.hackerone.com/hackers/reputation.html

Hint: the trick is on the table of that hackerone docs page.
Hint 2: You should have lost 5 points

@arjunnkn
Copy link
Author

All were vulnerabile to subdomain takeover that too wildcard one that gives countless subdomains takeover at once per domains

This is misconfiguration at client end but when Shopify is allowing a non parent domain owner to takeover any other parent subdomain it's Shopify issue

@arjunnkn
Copy link
Author

arjunnkn commented Dec 19, 2019

![Screenshot_20191220-000335](https://user-images.githubusercontent.com/14961110/71199609-4b417b00-22bc-11ea-8837-f466b0ac7cb9.png
Screenshot_20191220-001744

Noone reported this issue to Shopify via hackerone platform . Shopify confirmed it to me I can show you

Moreover I didn't loose a single reputation on it . Trick

@arjunnkn
Copy link
Author

@melardev what you got as response from hackerone for your shopify submission ?

@arjunnkn arjunnkn reopened this Jan 23, 2020
@codingo codingo closed this as completed Jan 24, 2020
@codingo
Copy link
Collaborator

codingo commented Jan 24, 2020

This is outside the remit of this repository. Further posting of vulnerable sites will lead to a ban.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants