In March, I found an SSRF in a
googlecloud
service, which gave me access to a few internal Cloud projects.
I recorded myself finding the bug from start to finish. Today, I published a video where I react to these recordings and explain the issue.
https://youtu.be/UyemBjyQ4qA
googlecloud
service, which gave me access to a few internal Cloud projects.
I recorded myself finding the bug from start to finish. Today, I published a video where I react to these recordings and explain the issue.
https://youtu.be/UyemBjyQ4qA
YouTube
Reacting to myself finding an SSRF vulnerability in Google Cloud
The raw report I have sent to the Google VRP team, with all additional comments:
https://feed.bugs.xdavidhu.me/bugs/0008
My previous writeup of the same URL parsing vulnerability:
https://bugs.xdavidhu.me/google/2020/03/08/the-unexpected-google-wide-domain…
https://feed.bugs.xdavidhu.me/bugs/0008
My previous writeup of the same URL parsing vulnerability:
https://bugs.xdavidhu.me/google/2020/03/08/the-unexpected-google-wide-domain…
First check for open port (80 or 443) then pass the output to httpx or httprobe, you might get different results so I will suggest to run in a loop at least 2 or 3 times,and also configure the threads according to your server.
https://github.com/projectdiscovery/httpx
https://github.com/tomnomnom/httprobe
https://github.com/projectdiscovery/httpx
https://github.com/tomnomnom/httprobe
GitHub
GitHub - projectdiscovery/httpx: httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp…
httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library. - projectdiscovery/httpx
found and reported these vulnerabilities with ginkoid.
In this post, I will discuss the root cause of these vulnerabilities, as well as briefly walk through the exploitation process. I’ll also include some thoughts about bug bounty in general at the end.
These are the associated CVEs and payouts:
https://robertchen.cc/blog
In this post, I will discuss the root cause of these vulnerabilities, as well as briefly walk through the exploitation process. I’ll also include some thoughts about bug bounty in general at the end.
These are the associated CVEs and payouts:
https://robertchen.cc/blog
Forwarded from Network Slutter ™ 🥷
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from Network Slutter ™ 🥷
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from Network Slutter ™ 🥷
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from Network Slutter ™ 🥷
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from Network Slutter ™ 🥷
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from CYBERMONKEYOFFICIAL
LATEST TECHNOLOGY AND CYBERNEWS
BY @cybermonkeyofficials
🌐VULNERABILITY IN PNB SERVER EXPOSED CUSTOMER DATA FOR ABOUT SEVEN MONTHS : CYBERX9
🌐GOVT PUTS ON SALE MTNL , BSNL ASSETS AT BASE PRICES OF RS 970 CRORE
🌐MICROSOFT , AWS PREPARE FOR NEW PENTAGON $10 BN CLOUD CONTRACT
🌐NEED TO REVIEW PLI SCHEME FOR ELECTRONIC COMPONENTS , IT HARDWARE TO MAKE IT MORE ATTRACTIVE : MOS IT
🌐IBM BETS BIG ON INDIA , TO OPEN MORE SOFTWARE DEVELOPMENT CENTRES
🌐INSTAGRAM TO SHUT DOWN 'THREADS' BY YEAR END
🌐CLUBHOUSE ROLLS OUT SUPPORT FOR CLOSED CAPTIONING AND LAUNHCES NEW BUG BOUNTY PROGRAM
🌐MICROSOFT EXCHANGE SERVERS HACKED IN INTERNAL REPLY CHAIN ATTACKS
🌐BABY ELEPHANT? CHINESES STATE MEDIA WARNS OF THREAT FROM INDIAN HACKER GROUP
🌐HIGHLY SENSITIVE MEDICAL DOCUMENTS LEAKED ONLINE AS HACKERS 3 MILLION BITCOIN RANSOM REJECTED
🌐PROTOTYPE ROBOTS DEPLOYED AT GOOGLE'S CAMPUSES LEARN TO WIPE TABELS OPEN DOORS
🌐ROLLS-ROYCE SAYS ITS ELECTRIC AIRCRAFT IS WORLD'S FASTEST AS IT TOPS 623 KM/H
🌐CHINA FINES ALIBABA , BAIDU FOR FAILING TO DECLARE 43 DEALS
🌐PAKISTAN LIFTS BANN ON TIK TOK AFTER FOUR MONTHS
🌐FACEBOOK TO PAY CREATORS UP TO $50000 TO USE LIVE AUDIO ROOMS: REPORT
🌐ROCKSTAR GAMES APOLOGISES FOR GTA TRILOGY ISSUES , PROMISES FIXES
DO FOLLOW @cybermonkeyofficials ON INSTAGRAM TO LEARN MORE
LINK TO OUR NEWS CHANNEL
https://www.instagram.com/p/CUCXe1_FfsD/?utm_medium=copy_link
TELEGRAM SUPPORT
https://t.me/cybermonkeyofficials
BY @cybermonkeyofficials
🌐VULNERABILITY IN PNB SERVER EXPOSED CUSTOMER DATA FOR ABOUT SEVEN MONTHS : CYBERX9
🌐GOVT PUTS ON SALE MTNL , BSNL ASSETS AT BASE PRICES OF RS 970 CRORE
🌐MICROSOFT , AWS PREPARE FOR NEW PENTAGON $10 BN CLOUD CONTRACT
🌐NEED TO REVIEW PLI SCHEME FOR ELECTRONIC COMPONENTS , IT HARDWARE TO MAKE IT MORE ATTRACTIVE : MOS IT
🌐IBM BETS BIG ON INDIA , TO OPEN MORE SOFTWARE DEVELOPMENT CENTRES
🌐INSTAGRAM TO SHUT DOWN 'THREADS' BY YEAR END
🌐CLUBHOUSE ROLLS OUT SUPPORT FOR CLOSED CAPTIONING AND LAUNHCES NEW BUG BOUNTY PROGRAM
🌐MICROSOFT EXCHANGE SERVERS HACKED IN INTERNAL REPLY CHAIN ATTACKS
🌐BABY ELEPHANT? CHINESES STATE MEDIA WARNS OF THREAT FROM INDIAN HACKER GROUP
🌐HIGHLY SENSITIVE MEDICAL DOCUMENTS LEAKED ONLINE AS HACKERS 3 MILLION BITCOIN RANSOM REJECTED
🌐PROTOTYPE ROBOTS DEPLOYED AT GOOGLE'S CAMPUSES LEARN TO WIPE TABELS OPEN DOORS
🌐ROLLS-ROYCE SAYS ITS ELECTRIC AIRCRAFT IS WORLD'S FASTEST AS IT TOPS 623 KM/H
🌐CHINA FINES ALIBABA , BAIDU FOR FAILING TO DECLARE 43 DEALS
🌐PAKISTAN LIFTS BANN ON TIK TOK AFTER FOUR MONTHS
🌐FACEBOOK TO PAY CREATORS UP TO $50000 TO USE LIVE AUDIO ROOMS: REPORT
🌐ROCKSTAR GAMES APOLOGISES FOR GTA TRILOGY ISSUES , PROMISES FIXES
DO FOLLOW @cybermonkeyofficials ON INSTAGRAM TO LEARN MORE
LINK TO OUR NEWS CHANNEL
https://www.instagram.com/p/CUCXe1_FfsD/?utm_medium=copy_link
TELEGRAM SUPPORT
https://t.me/cybermonkeyofficials
Forwarded from CYBERMONKEY BACKUP
@cybermonkeyofficials Cyber Crime Laws In India.pdf
14.9 KB
CYBER CRIME LAWS IN INDIA AND
IT ACT
Credits - @cybermonkeyofficials
{Section 52 of the Copyright Act, 1957 stipulates permissible uses of the Copyright without specific authorization from the author. Therefore, the said Section allows legitimate use of the copyrighted work for educational, scientific and cultural advancement of the society}
✍️ Section 43
Dealing with penalties and compensation related to computer theft.
✍️ Security Practices
✍️Section 65
Tampering with documents or destroying and altering source code with cases
✍️Section 66
Dealing computer theft with criminal intentions and criminal offences
Explanations from 66A to 66F
👉 Previous Notes are Uploaded in Backup Channel
https://t.me/backupcybermonkeyofficials
INSTAGRAM SUPPORT
https://www.instagram.com/p/CQvl6PPDPQy/?utm_medium=share_sheet
TELEGRAM SUPPORT
https://t.me/cybermonkeyofficials
IT ACT
Credits - @cybermonkeyofficials
{Section 52 of the Copyright Act, 1957 stipulates permissible uses of the Copyright without specific authorization from the author. Therefore, the said Section allows legitimate use of the copyrighted work for educational, scientific and cultural advancement of the society}
✍️ Section 43
Dealing with penalties and compensation related to computer theft.
✍️ Security Practices
✍️Section 65
Tampering with documents or destroying and altering source code with cases
✍️Section 66
Dealing computer theft with criminal intentions and criminal offences
Explanations from 66A to 66F
👉 Previous Notes are Uploaded in Backup Channel
https://t.me/backupcybermonkeyofficials
INSTAGRAM SUPPORT
https://www.instagram.com/p/CQvl6PPDPQy/?utm_medium=share_sheet
TELEGRAM SUPPORT
https://t.me/cybermonkeyofficials
Forwarded from CYBERMONKEY BACKUP
USB-Rubber-Ducky_ebook_v21.11 (1).pdf
8.5 MB
HAK5
USB RUBBER DUCKY EBOOK
Credits - @cybermonkeyofficials
{Section 52 of the Copyright Act, 1957 stipulates permissible uses of the Copyright without specific authorization from the author. Therefore, the said Section allows legitimate use of the copyrighted work for educational, scientific and cultural advancement of the society}
✍Keystroke Injection attacks
✍The USB RUBBER ducky
✍Payloads
✍Ducky Scripts
✍Hardware overview
✍Writing Your first Payload
✍The Ducky Script Language
✍Sample Payloads
✍Guide for hacking Password Mr.Robot Style
✍All basic problem solution with USB RUBBER DUCKY
INSTAGRAM SUPPORT
https://www.instagram.com/p/CQvl6PPDPQy/?utm_medium=share_sheet
TELEGRAM SUPPORT
https://t.me/cybermonkeyofficials
USB RUBBER DUCKY EBOOK
Credits - @cybermonkeyofficials
{Section 52 of the Copyright Act, 1957 stipulates permissible uses of the Copyright without specific authorization from the author. Therefore, the said Section allows legitimate use of the copyrighted work for educational, scientific and cultural advancement of the society}
✍Keystroke Injection attacks
✍The USB RUBBER ducky
✍Payloads
✍Ducky Scripts
✍Hardware overview
✍Writing Your first Payload
✍The Ducky Script Language
✍Sample Payloads
✍Guide for hacking Password Mr.Robot Style
✍All basic problem solution with USB RUBBER DUCKY
INSTAGRAM SUPPORT
https://www.instagram.com/p/CQvl6PPDPQy/?utm_medium=share_sheet
TELEGRAM SUPPORT
https://t.me/cybermonkeyofficials
Forwarded from CYBERMONKEYOFFICIAL
LATEST TECHNOLOGY AND CYBERNEWS
BY @cybermonkeyofficials
🌐GOVT to bring bills to ban pvt crypto with some exceptions to promote underlying tech
🌐Wheelchair that can be controlled by eye movements made by Bengaluru students
🌐Whatsapp rolls out flash calls,message levels reporting safety features in India
🌐Amazon apple fined £200 MN for colluding over sale of products in Italy
🌐12 lakh WordPress users data exposed in security breach since September:Go Daddy
🌐Parliamentary Panel adopts report on data protection bill amid dissent by MPs
🌐Adele gets Spotify to remove default shuffle button from all albums
🌐NASA to crash spacecraft into asteroid in 1st planetary defense test mission
🌐Meta delays end to end encryption for Messenger Instagram until 2023
🌐Airtel , Idea ,Vodafone,Idea to increase Tariff by upto 25 Perc from November 25
🌐Qualcomm separates Snapdragon as separate brand to introduce new chip names
🌐Punjab National Bank denies any data theft ,system breach
🌐Winzo kalari to launch 'The Gaming Lab'
🌐Apple patents foldable device with split screen
🌐New duck duck Go tool might prevent apps from tracking Android users
🌐Apple sues company known for hacking iPhone on behalf of governments
DO FOLLOW @cybermonkeyofficials ON INSTAGRAM TO LEARN MORE
LINK TO OUR NEWS CHANNEL
https://www.instagram.com/p/CUCXe1_FfsD/?utm_medium=copy_link
TELEGRAM SUPPORT
https://t.me/cybermonkeyofficials
BY @cybermonkeyofficials
🌐GOVT to bring bills to ban pvt crypto with some exceptions to promote underlying tech
🌐Wheelchair that can be controlled by eye movements made by Bengaluru students
🌐Whatsapp rolls out flash calls,message levels reporting safety features in India
🌐Amazon apple fined £200 MN for colluding over sale of products in Italy
🌐12 lakh WordPress users data exposed in security breach since September:Go Daddy
🌐Parliamentary Panel adopts report on data protection bill amid dissent by MPs
🌐Adele gets Spotify to remove default shuffle button from all albums
🌐NASA to crash spacecraft into asteroid in 1st planetary defense test mission
🌐Meta delays end to end encryption for Messenger Instagram until 2023
🌐Airtel , Idea ,Vodafone,Idea to increase Tariff by upto 25 Perc from November 25
🌐Qualcomm separates Snapdragon as separate brand to introduce new chip names
🌐Punjab National Bank denies any data theft ,system breach
🌐Winzo kalari to launch 'The Gaming Lab'
🌐Apple patents foldable device with split screen
🌐New duck duck Go tool might prevent apps from tracking Android users
🌐Apple sues company known for hacking iPhone on behalf of governments
DO FOLLOW @cybermonkeyofficials ON INSTAGRAM TO LEARN MORE
LINK TO OUR NEWS CHANNEL
https://www.instagram.com/p/CUCXe1_FfsD/?utm_medium=copy_link
TELEGRAM SUPPORT
https://t.me/cybermonkeyofficials
Forwarded from CYBERMONKEYOFFICIAL
GET YOUR HANDS ON WINDOWS SECURITY FULL COURSE
Credits - @cybermonkeyofficials
{Section 52 of the Copyright Act, 1957 stipulates permissible uses of the Copyright without specific authorization from the author. Therefore, the said Section allows legitimate use of the copyrighted work for educational, scientific and cultural advancement of the society}
👉Direct link
LINK TO DOWNLOAD
https://t.me/backupcybermonkeyofficials
INSTAGRAM SUPPORT
https://www.instagram.com/p/CQvl6PPDPQy/?utm_medium=share_sheet
TELEGRAM SUPPORT
https://t.me/cybermonkeyofficials
Credits - @cybermonkeyofficials
{Section 52 of the Copyright Act, 1957 stipulates permissible uses of the Copyright without specific authorization from the author. Therefore, the said Section allows legitimate use of the copyrighted work for educational, scientific and cultural advancement of the society}
👉Direct link
LINK TO DOWNLOAD
https://t.me/backupcybermonkeyofficials
INSTAGRAM SUPPORT
https://www.instagram.com/p/CQvl6PPDPQy/?utm_medium=share_sheet
TELEGRAM SUPPORT
https://t.me/cybermonkeyofficials
Forwarded from CYBERMONKEY BACKUP
@cybermonkeyoffcial Cyber Crime laws in India - 2 (1).pdf
20.2 KB
CYBER CRIME LAWS IN INDIA AND AMENDMENTS
Credits - @cybermonkeyofficials
{Section 52 of the Copyright Act, 1957 stipulates permissible uses of the Copyright without specific authorization from the author. Therefore, the said Section allows legitimate use of the copyrighted work for educational, scientific and cultural advancement of the society}
✍Section 67
Dealing with publishing or transmitting obscene material in electronic from
✍Section 69
✍Commentaries on the power to intercep monitor and block websites
✍Other Acts Amended by ITA
THE INDIAN PENAL CODE 1860
THE INDIAN EVIDENCE ACT 1871
THE BANKERS BOOKS EVIDENCE ACT 1891
RESERVE BANK OF INDIA ACT 1934
Previous Notes are Uploaded in -
https://t.me/backupcybermonkeyofficials
INSTAGRAM SUPPORT
https://www.instagram.com/p/CQvl6PPDPQy/?utm_medium=share_sheet
TELEGRAM SUPPORT
https://t.me/cybermonkeyofficials
Credits - @cybermonkeyofficials
{Section 52 of the Copyright Act, 1957 stipulates permissible uses of the Copyright without specific authorization from the author. Therefore, the said Section allows legitimate use of the copyrighted work for educational, scientific and cultural advancement of the society}
✍Section 67
Dealing with publishing or transmitting obscene material in electronic from
✍Section 69
✍Commentaries on the power to intercep monitor and block websites
✍Other Acts Amended by ITA
THE INDIAN PENAL CODE 1860
THE INDIAN EVIDENCE ACT 1871
THE BANKERS BOOKS EVIDENCE ACT 1891
RESERVE BANK OF INDIA ACT 1934
Previous Notes are Uploaded in -
https://t.me/backupcybermonkeyofficials
INSTAGRAM SUPPORT
https://www.instagram.com/p/CQvl6PPDPQy/?utm_medium=share_sheet
TELEGRAM SUPPORT
https://t.me/cybermonkeyofficials
⚠️⚠️ Joker Malware Is Back And Found In These 15 Apps⚠️⚠️
👉🏻 Delete These Apps Immediately!!!
1. Easy PDF Scanner
2. Now QR Code Scan
3. Super-Click VPN
4. Volume Booster Louder Sound Equalizer
5. Battery Charging Animation Bubble Effects
6. Smart TV Remote
7. Volume Boosting Hearing Aid
8. Flashlight Flash Alert on Call
9. Halloween Coloring
10. Classic Emoji Keyboard
11. Super Hero-Effect
12. Dazzling Keyboard
13. EmojiOne Keyboard
14. Battery Charging Animation Wallpaper
15. Blender Photo Editor-Easy Photo Background Editor
⚠️Take Care ⚠️
❤️❤️ Enjoy and Share ❤️❤️
Support Us ❤️
Channel : @freelearningtech
Group : @freelearningtech21
Website : https://freelearningtech.in/
👉🏻 Delete These Apps Immediately!!!
1. Easy PDF Scanner
2. Now QR Code Scan
3. Super-Click VPN
4. Volume Booster Louder Sound Equalizer
5. Battery Charging Animation Bubble Effects
6. Smart TV Remote
7. Volume Boosting Hearing Aid
8. Flashlight Flash Alert on Call
9. Halloween Coloring
10. Classic Emoji Keyboard
11. Super Hero-Effect
12. Dazzling Keyboard
13. EmojiOne Keyboard
14. Battery Charging Animation Wallpaper
15. Blender Photo Editor-Easy Photo Background Editor
⚠️Take Care ⚠️
❤️❤️ Enjoy and Share ❤️❤️
Support Us ❤️
Channel : @freelearningtech
Group : @freelearningtech21
Website : https://freelearningtech.in/
💻 1.75 GB of books pdfs 💻
Hacking Ebooks by HateHacker
https://mega.nz/folder/ygkkmCwY#CGF5BGk-9Tmt96fCk-5YAg
❤️❤️ Enjoy and Share ❤️❤️
Support Us ❤️
Channel : @freelearningtech
Group : @freelearningtech21
Website : https://freelearningtech.in/
Hacking Ebooks by HateHacker
https://mega.nz/folder/ygkkmCwY#CGF5BGk-9Tmt96fCk-5YAg
❤️❤️ Enjoy and Share ❤️❤️
Support Us ❤️
Channel : @freelearningtech
Group : @freelearningtech21
Website : https://freelearningtech.in/
mega.nz
File folder on MEGA
😱 The Biggest collections of E-books | More than 1000+ books 😱
Part-01👇 (10.44GB)
https://drive.google.com/file/d/151mbhFeaNesYC4lh3UaTOrDkVy0GIi76/view?usp=drivesdk
Part-02 👇 (153.9MB)
https://drive.google.com/file/d/1YcIgMo5KTVxna9Z5VhmBT_1yqylB7u4N/view?usp=drivesdk
😘 Password:-) @H4CKT3R_bot
❤️❤️ Enjoy and Share ❤️❤️
Support Us ❤️
Channel : @freelearningtech
Group : @freelearningtech21
Website : https://freelearningtech.in/
Part-01👇 (10.44GB)
https://drive.google.com/file/d/151mbhFeaNesYC4lh3UaTOrDkVy0GIi76/view?usp=drivesdk
Part-02 👇 (153.9MB)
https://drive.google.com/file/d/1YcIgMo5KTVxna9Z5VhmBT_1yqylB7u4N/view?usp=drivesdk
😘 Password:-) @H4CKT3R_bot
❤️❤️ Enjoy and Share ❤️❤️
Support Us ❤️
Channel : @freelearningtech
Group : @freelearningtech21
Website : https://freelearningtech.in/
Forwarded from CYBERMONKEY BACKUP
Top Database Bundle: MySQL, PostgreSQL, SQLite3, SQL Server Free Download
Credits - @cybermonkeyofficials
{Section 52 of the Copyright Act, 1957 stipulates permissible uses of the Copyright without specific authorization from the author. Therefore, the said Section allows legitimate use of the copyrighted work for educational, scientific and cultural advancement of the society}
What Is A Database
How To Install Each Database
How To Install Git Bash Terminal
How To Connect To Your Database
How To Create A Database
After that, we'll move into more intermediate topics like:
How To Create A Table
How To Insert One Record Into Table
How To Insert Many Records Into Table
Understanding Data Types
How To Select Data From Table
How To Format Our Results
How To Use The Where Clause
How To Use The Like Clause and Wildcards
How To Use AND and OR
How To Updating Records
How To Limit and Order Results
How To Delete Records
How To Delete (Drop) A Table And Backups
Finally, we'll finish up with more advanced topics like:
Foreign Keys
👉Link to download
https://bit.ly/3FGWEu0
INSTAGRAM SUPPORT
https://www.instagram.com/p/CQvl6PPDPQy/?utm_medium=share_sheet
TELEGRAM SUPPORT
https://t.me/cybermonkeyofficials
Credits - @cybermonkeyofficials
{Section 52 of the Copyright Act, 1957 stipulates permissible uses of the Copyright without specific authorization from the author. Therefore, the said Section allows legitimate use of the copyrighted work for educational, scientific and cultural advancement of the society}
What Is A Database
How To Install Each Database
How To Install Git Bash Terminal
How To Connect To Your Database
How To Create A Database
After that, we'll move into more intermediate topics like:
How To Create A Table
How To Insert One Record Into Table
How To Insert Many Records Into Table
Understanding Data Types
How To Select Data From Table
How To Format Our Results
How To Use The Where Clause
How To Use The Like Clause and Wildcards
How To Use AND and OR
How To Updating Records
How To Limit and Order Results
How To Delete Records
How To Delete (Drop) A Table And Backups
Finally, we'll finish up with more advanced topics like:
Foreign Keys
👉Link to download
https://bit.ly/3FGWEu0
INSTAGRAM SUPPORT
https://www.instagram.com/p/CQvl6PPDPQy/?utm_medium=share_sheet
TELEGRAM SUPPORT
https://t.me/cybermonkeyofficials
Forwarded from Network Slutter ™ 🥷
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from Network Slutter ™ 🥷
Please open Telegram to view this post
VIEW IN TELEGRAM