This media is not supported in your browser
VIEW IN TELEGRAM
🚨noWAFpls🚨
👉Burp Plugin to Bypass WAFs through the insertion of Junk Data
🔗 https://github.com/assetnote/nowafpls
👉Burp Plugin to Bypass WAFs through the insertion of Junk Data
🔗 https://github.com/assetnote/nowafpls
👍3🔥1🤯1
🚨CVE-2024-23692: Unauthenticated RCE Flaw in Rejetto HTTP File Server
👉It allows remote attackers to execute arbitrary code on affected servers without authentication, potentially leading to data breaches, ransomware attacks, and complete system compromise.
💥PoC: https://github.com/rapid7/metasploit-framework/pull/19240
💥Dorks:
Hunter: /product.name="HTTP File Server" and web.body="Rejetto"
FOFA: product="HFS"
SHODAN: product:"HttpFileServer httpd"
#Rejetto #HFS #bugbounty #bugbountytips #cybersecurity #pentesting
👉It allows remote attackers to execute arbitrary code on affected servers without authentication, potentially leading to data breaches, ransomware attacks, and complete system compromise.
💥PoC: https://github.com/rapid7/metasploit-framework/pull/19240
💥Dorks:
Hunter: /product.name="HTTP File Server" and web.body="Rejetto"
FOFA: product="HFS"
SHODAN: product:"HttpFileServer httpd"
#Rejetto #HFS #bugbounty #bugbountytips #cybersecurity #pentesting
🔥2
This media is not supported in your browser
VIEW IN TELEGRAM
Found this on twitter. The POC is very informative. What you think?
🔥11👍2🤯2
Surprisingly Havij - SQL injection tool helped me to achieve a error based sqli on ferrari 😳
🐳4
Simple but effective method to narrow down your scope, sometimes it helps to think simple.
waybackurls --dates domain(.)com | grep '?id='
Payload : if(now()=sysdate(),SLEEP(8),0)
By:@ynsmroztas
#bugbountytips #bugbounty
waybackurls --dates domain(.)com | grep '?id='
Payload : if(now()=sysdate(),SLEEP(8),0)
By:@ynsmroztas
#bugbountytips #bugbounty
🔥6👍1
Brut Security
🚨CVE-2024-23692: Unauthenticated RCE Flaw in Rejetto HTTP File Server 👉It allows remote attackers to execute arbitrary code on affected servers without authentication, potentially leading to data breaches, ransomware attacks, and complete system compromise.…
Media is too big
VIEW IN TELEGRAM
Rejetto HTTP File Server - Template injection
🔥5
🚨CVE-2024-29849~29852: Veeam’s Backup Nightmare, Full System Access Exposed
⚠Veeam Backup Enterprise Manager has been issued 4 critical vulnerabilities, allowing unauthorized access, account takeover, and data exposure.
💥PoC: https://github.com/sinsinology/CVE-2024-29849
💥Dorks:
Hunter:/product.name="Veeam Backup Enterprise Manager"
FOFA:app="Veeam-Backup-Enterprise-Manager"
SHODAN:http.noscript:"Veeam Backup Enterprise Manager"
#Veeam #backup #infosec #infosecurity #Infosys #Vulnerability #bugbounty #bugbountytips
⚠Veeam Backup Enterprise Manager has been issued 4 critical vulnerabilities, allowing unauthorized access, account takeover, and data exposure.
💥PoC: https://github.com/sinsinology/CVE-2024-29849
💥Dorks:
Hunter:/product.name="Veeam Backup Enterprise Manager"
FOFA:app="Veeam-Backup-Enterprise-Manager"
SHODAN:http.noscript:"Veeam Backup Enterprise Manager"
#Veeam #backup #infosec #infosecurity #Infosys #Vulnerability #bugbounty #bugbountytips
🤯3
🌐🕵️♂️Ominis: OSINT: Web Hunter 🌐🕵️♂️
👉It gathers online information by querying Google with a user-inputted query. The tool then extracts relevant details like noscripts, URLs, and mentions of the query from the search results.
Targetable and Actionable Results 🎯
1. Identifying Potential Threats 🚨
2. Monitoring Competitors 🕵️♂️
3. Gathering Human Intelligence 👥
4. Detecting Brand Mentions 📣
5. Investigating Individuals 🔍
6. Uncovering Financial Insights 💰
7. Mapping Digital Footprints 🗺️
8. Tracking Online Campaigns 📊
9. Monitoring Regulatory Compliance 📝
10. Forecasting Emerging Risks 📈
11. Google Search Filtering 🖇
🔗Download: https://github.com/AnonCatalyst/Ominis-OSINT
👉It gathers online information by querying Google with a user-inputted query. The tool then extracts relevant details like noscripts, URLs, and mentions of the query from the search results.
Targetable and Actionable Results 🎯
1. Identifying Potential Threats 🚨
2. Monitoring Competitors 🕵️♂️
3. Gathering Human Intelligence 👥
4. Detecting Brand Mentions 📣
5. Investigating Individuals 🔍
6. Uncovering Financial Insights 💰
7. Mapping Digital Footprints 🗺️
8. Tracking Online Campaigns 📊
9. Monitoring Regulatory Compliance 📝
10. Forecasting Emerging Risks 📈
11. Google Search Filtering 🖇
🔗Download: https://github.com/AnonCatalyst/Ominis-OSINT
👍6
For Tryhackme and Hackthebox Vip+ Vouchers DM me.
Available For India Only. Dm @wtf_yodhha
Available For India Only. Dm @wtf_yodhha
This media is not supported in your browser
VIEW IN TELEGRAM
Keyfinder 📱 is a tool that let you find keys while surfing the web!
📎 https://github.com/momenbasel/keyFinder
#bugbountytips #bugbounty
#bugbountytips #bugbounty
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥2❤1
Please open Telegram to view this post
VIEW IN TELEGRAM
👍5
Please open Telegram to view this post
VIEW IN TELEGRAM
👍1