#工具 OSINT tool to get information from a Github and Gitlab profile and find user's email addresses leaked on commits.
从Github或Gitlab配置文件中获取信息,并查找提交时泄露的用户电子邮件地址。
https://github.com/GONZOsint/gitrecon
从Github或Gitlab配置文件中获取信息,并查找提交时泄露的用户电子邮件地址。
https://github.com/GONZOsint/gitrecon
GitHub
GitHub - GONZOsint/gitrecon: OSINT tool to get information from a Github and Gitlab profile and find user's email addresses leaked…
OSINT tool to get information from a Github and Gitlab profile and find user's email addresses leaked on commits. - GONZOsint/gitrecon
#漏洞 Mybb associate CVE-2021-27890 & CVE-2021-27889 to RCE poc
https://github.com/xiaopan233/Mybb-XSS_SQL_RCE-POC
https://github.com/xiaopan233/Mybb-XSS_SQL_RCE-POC
GitHub
GitHub - xiaopan233/Mybb-XSS_SQL_RCE-POC: Mybb associate CVE-2021-27890 & CVE-2021-27889 to RCE poc
Mybb associate CVE-2021-27890 & CVE-2021-27889 to RCE poc - GitHub - xiaopan233/Mybb-XSS_SQL_RCE-POC: Mybb associate CVE-2021-27890 & CVE-2021-27889 to RCE poc
#漏洞 Two Vulnerabilities Patched in Facebook for WordPress Plugin
https://www.wordfence.com/blog/2021/03/two-vulnerabilities-patched-in-facebook-for-wordpress-plugin/
https://www.wordfence.com/blog/2021/03/two-vulnerabilities-patched-in-facebook-for-wordpress-plugin/
Wordfence
Two Vulnerabilities Patched in Facebook for WordPress Plugin
On December 22, 2020, our Threat Intelligence team responsibly disclosed a vulnerability in Facebook for WordPress, formerly known as Official Facebook Pixel, a WordPress plugin installed on over 500,000 sites. This flaw made it possible for unauthenticated…
#漏洞 CVE-2021-23888-McAfee ePolicy Orchestrator HTML注入
https://ricardojba.github.io/CVE-2021-23888-McAfee-ePolicy-Orchestrator-HTML-Injection/
https://ricardojba.github.io/CVE-2021-23888-McAfee-ePolicy-Orchestrator-HTML-Injection/
blog.vibri.us
CVE-2021-23888 McAfee ePolicy Orchestrator HTML Injection | vibrio's personal infosec blog
Product: McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 Type: OWASP Top Ten 2013 Category A10 - Unvalidated Redirects and Forwards Summary: Unvali...
#bountytip How to bypass CloudFlare bot protection ?
https://jychp.medium.com/how-to-bypass-cloudflare-bot-protection-1f2c6c0c36fb
https://jychp.medium.com/how-to-bypass-cloudflare-bot-protection-1f2c6c0c36fb
Medium
How to bypass CloudFlare bot protection ?
Several months ago I submitted what appeared to be a security flaw to CloudFalre’s bugbounty program. According to them, this is not a…
#漏洞 Afterlogic Aurora & WebMail Pro 文件上传漏洞(CVE-2021-26293)
https://github.com/E3SEC/AfterLogic/blob/main/CVE-2021-26293-rce-via-public-unrestricted-file-upload-vulnerability.md
https://github.com/E3SEC/AfterLogic/blob/main/CVE-2021-26293-rce-via-public-unrestricted-file-upload-vulnerability.md
GitHub
AfterLogic/CVE-2021-26293-rce-via-public-unrestricted-file-upload-vulnerability.md at main · E3SEC/AfterLogic
AfterLogic Products Vulnerabilities. Contribute to E3SEC/AfterLogic development by creating an account on GitHub.
#漏洞 Afterlogic Aurora & WebMail Pro 任意文件读取(CVE-2021-26294)
https://github.com/E3SEC/AfterLogic/blob/main/CVE-2021-26294-exposure-of-sensitive-information-vulnerability.md
https://github.com/E3SEC/AfterLogic/blob/main/CVE-2021-26294-exposure-of-sensitive-information-vulnerability.md
GitHub
AfterLogic/CVE-2021-26294-exposure-of-sensitive-information-vulnerability.md at main · E3SEC/AfterLogic
AfterLogic Products Vulnerabilities. Contribute to E3SEC/AfterLogic development by creating an account on GitHub.
#漏洞 Universal “netmask” npm package, used by 270,000+ projects, vulnerable to octal input data: server-side request forgery, remote file inclusion, local file inclusion, and more (CVE-2021-28918)
https://sick.codes/universal-netmask-npm-package-used-by-270000-projects-vulnerable-to-octal-input-data-server-side-request-forgery-remote-file-inclusion-local-file-inclusion-and-more-cve-2021-28918/
https://sick.codes/universal-netmask-npm-package-used-by-270000-projects-vulnerable-to-octal-input-data-server-side-request-forgery-remote-file-inclusion-local-file-inclusion-and-more-cve-2021-28918/
Sick Codes - Security Research, Hardware & Software Hacking, Consulting, Linux, IoT, Cloud, Embedded, Arch, Tweaks & Tips!
Universal "netmask" npm package, used by 270,000+ projects, vulnerable to octal input data: server-side request forgery, remote…
The following research outlines a vulnerability discovered in netmask npm package that is currently used by 278,722+ other projects. The vulnerability has been present for 9 years. Since this package is so incredibly widespread, I would suggest every nodejs…
#情报 PHP的Git服务器被黑客入侵以向PHP源代码添加后门
https://www.bleepingcomputer.com/news/security/phps-git-server-hacked-to-add-backdoors-to-php-source-code/
https://www.bleepingcomputer.com/news/security/phps-git-server-hacked-to-add-backdoors-to-php-source-code/
BleepingComputer
PHP's Git server hacked to add backdoors to PHP source code
In the latest software supply chain attack, the official PHP Git repository was hacked and tampered with. Yesterday, two malicious commits were pushed to the php-src Git repository maintained by the PHP team on their git.php.net server. The threat actors…