4300$ Instagram IDOR Bug (2022)
Hello everyone! Today im going to explain how i found a 4300$ IDOR Bug on Instagram.Continue reading on Medium »
Read more...
Hello everyone! Today im going to explain how i found a 4300$ IDOR Bug on Instagram.Continue reading on Medium »
Read more...
4300$ Instagram IDOR Bug (2022)
https://medium.com/@nvmeeet/4300-instagram-idor-bug-2022-5386cf492cad?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@nvmeeet/4300-instagram-idor-bug-2022-5386cf492cad?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
4300$ Instagram IDOR Bug (2022)
Hello everyone! Today im going to explain how i found a 4300$ IDOR Bug on Instagram.
Hello everyone! Today im going to explain how i found a 4300$ IDOR Bug on Instagram.Continue reading on Medium » (https://medium.com/@nvmeeet/4300-instagram-idor-bug-2022-5386cf492cad?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
4300$ Instagram IDOR Bug (2022)
Hello everyone! Today im going to explain how i found a 4300$ IDOR Bug on Instagram.
4300$ Instagram IDOR Bug (2022)
Hello everyone! Today im going to explain how i found a 4300$ IDOR Bug on Instagram.Continue reading on Medium »
Read more...
Hello everyone! Today im going to explain how i found a 4300$ IDOR Bug on Instagram.Continue reading on Medium »
Read more...
Searpy - Search Engine Tookit
1. Install git clone https://github.com/j3ers3/Searpypip install -r requirement.txt配置API及账号 ./config.pypython Searpy -h 2. Help baidu Engine --google Using google Engine --so Using 360so Engine --bing Using bing Engine --shodan Using shodan Engine --fofa Using fofa Engine --zoomeye Using zoomeye Engine --goo Using goo Engine --yahoo Using yahoo Engine SCRIPT: --shodan_icon SHODAN_ICON Get ip list which using the same favicon.ico --fofa_icon FOFA_ICON Get ip list which using the same favicon.ico MISC: -s SEARCH Speciy Keyword -o OUTPUT Specify output file default output.txt -p PAGE Search page (default 1) -l LIMIT Maximum searching results (default:10) Only Shodan">Searpy Engine Tookitoptional arguments: -h, --help show this help message and exitENGINE: --baidu Using baidu Engine --google Using google Engine --so Using 360so Engine --bing Using bing Engine --shodan Using shodan Engine --fofa Using fofa Engine --zoomeye Using zoomeye Engine --goo Using goo Engine --yahoo Using yahoo EngineSCRIPT: --shodan_icon SHODAN_ICON Get ip list which using the same favicon.ico --fofa_icon FOFA_ICON Get ip list which using the same favicon.icoMISC: -s SEARCH Speciy Keyword -o OUTPUT Specify output file default output.txt -p P AGE Search page (default 1) -l LIMIT Maximum searching results (default:10) Only Shodan 2.1 示例 python3 Searpy.py --fofa -s "app=jboss" -p 1python3 Searpy.py --shodan -s "weblogic" -l 10 python3 Searpy.py --google -s "inurl:login.action" -p 1 2.2 其他功能 利用favicon.icon图标hash来寻找使用相同图标的网站,可用于溯源真实IP和资产发现 python3 Searpy.py --shodan_icon https://www.qq.compython3 Searpy.py --fofa_icon https://www.qq.com 3. 模块调用 >>> from Searpy import Bing>>> s = Bing('inurl:php?id=1', 2)>>> s.search()>>> for i in s.result:>>> print(i) 4. 支持搜索引擎 Shodan Fofa Zoomeye Censys Dnsdb Google Baidu Bing 360so Goo Yahoo 6. ChangeLog v2.3 fix some bugs add fofa_icon module v2.2 fix some bugs 7. Donations XMR: 498AoZRwfC11Fa4LwAyVVp3wRD4Zyf1e1HziegczeWeSYVVTZ8gw8CoNPm5yhY91tkDqDMBg6A5KUfyowMtdkQDrDxE5aVN BTC: 1ALWC7rGL4dHgbyy4R8uTVHmDugPDD7Rvt 8. Contact Twitter Download Searpy
Read more...
___________________________
@hacking_Attack
@Hacking_Video
1. Install git clone https://github.com/j3ers3/Searpypip install -r requirement.txt配置API及账号 ./config.pypython Searpy -h 2. Help baidu Engine --google Using google Engine --so Using 360so Engine --bing Using bing Engine --shodan Using shodan Engine --fofa Using fofa Engine --zoomeye Using zoomeye Engine --goo Using goo Engine --yahoo Using yahoo Engine SCRIPT: --shodan_icon SHODAN_ICON Get ip list which using the same favicon.ico --fofa_icon FOFA_ICON Get ip list which using the same favicon.ico MISC: -s SEARCH Speciy Keyword -o OUTPUT Specify output file default output.txt -p PAGE Search page (default 1) -l LIMIT Maximum searching results (default:10) Only Shodan">Searpy Engine Tookitoptional arguments: -h, --help show this help message and exitENGINE: --baidu Using baidu Engine --google Using google Engine --so Using 360so Engine --bing Using bing Engine --shodan Using shodan Engine --fofa Using fofa Engine --zoomeye Using zoomeye Engine --goo Using goo Engine --yahoo Using yahoo EngineSCRIPT: --shodan_icon SHODAN_ICON Get ip list which using the same favicon.ico --fofa_icon FOFA_ICON Get ip list which using the same favicon.icoMISC: -s SEARCH Speciy Keyword -o OUTPUT Specify output file default output.txt -p P AGE Search page (default 1) -l LIMIT Maximum searching results (default:10) Only Shodan 2.1 示例 python3 Searpy.py --fofa -s "app=jboss" -p 1python3 Searpy.py --shodan -s "weblogic" -l 10 python3 Searpy.py --google -s "inurl:login.action" -p 1 2.2 其他功能 利用favicon.icon图标hash来寻找使用相同图标的网站,可用于溯源真实IP和资产发现 python3 Searpy.py --shodan_icon https://www.qq.compython3 Searpy.py --fofa_icon https://www.qq.com 3. 模块调用 >>> from Searpy import Bing>>> s = Bing('inurl:php?id=1', 2)>>> s.search()>>> for i in s.result:>>> print(i) 4. 支持搜索引擎 Shodan Fofa Zoomeye Censys Dnsdb Google Baidu Bing 360so Goo Yahoo 6. ChangeLog v2.3 fix some bugs add fofa_icon module v2.2 fix some bugs 7. Donations XMR: 498AoZRwfC11Fa4LwAyVVp3wRD4Zyf1e1HziegczeWeSYVVTZ8gw8CoNPm5yhY91tkDqDMBg6A5KUfyowMtdkQDrDxE5aVN BTC: 1ALWC7rGL4dHgbyy4R8uTVHmDugPDD7Rvt 8. Contact Twitter Download Searpy
Read more...
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Log4Shell Makes the Case for Runtime Application Self-Protection
Dive into the case for RASP to combat Log4Shell and why Web app firewalls aren't great for these types of attacks.
___________________________
@hacking_Attack
@Hacking_Video
Log4Shell Makes the Case for Runtime Application Self-Protection
Dive into the case for RASP to combat Log4Shell and why Web app firewalls aren't great for these types of attacks.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Log4Shell Makes the Case for Runtime Application Self-Protection
Dive into the case for RASP to combat Log4Shell and why Web app firewalls aren't great for these types of attacks.
Dark Reading: Attacks/Breaches
Protecting Field Programmable Gate Arrays From Attacks
FPGAs can be part of physical systems in the aerospace, medical, or industrial fields, so a security compromise can be potentially serious.
___________________________
@hacking_Attack
@Hacking_Video
Protecting Field Programmable Gate Arrays From Attacks
FPGAs can be part of physical systems in the aerospace, medical, or industrial fields, so a security compromise can be potentially serious.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Protecting Field Programmable Gate Arrays From Attacks
FPGAs can be part of physical systems in the aerospace, medical, or industrial fields, so a security compromise can be potentially serious.
Searpy - Search Engine Tookit
http://www.kitploit.com/2022/03/searpy-search-engine-tookit.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/03/searpy-search-engine-tookit.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Searpy - Search Engine Tookit
1. Install git clone https://github.com/j3ers3/Searpy
pip install -r requirement.txt
配置API及账号 ./config.py
python Searpy -h
2. Help baidu Engine --google Using google Engine --so Using 360so Engine --bing Using bing (https://www.kitploit.com/search/label/Bing) Engine --shodan Using shodan (https://www.kitploit.com/search/label/Shodan) Engine --fofa Using fofa (https://www.kitploit.com/search/label/Fofa) Engine --zoomeye Using zoomeye (https://www.kitploit.com/search/label/Zoomeye) Engine --goo Using goo Engine --yahoo Using yahoo Engine SCRIPT: --shodan_icon SHODAN_ICON Get ip list which using the same favicon.ico --fofa_icon FOFA_ICON Get ip list which using the same favicon.ico MISC: -s SEARCH Speciy Keyword -o OUTPUT Specify output file default output.txt -p PAGE Search page (default 1) -l LIMIT Maximum searching results (default:10) Only Shodan">
Searpy Engine Tookit
optional arguments:
-h, --help show this help message and exit
ENGINE:
--baidu Using baidu Engine
--google Using google Engine
--so Using 360so Engine
--bing Using bing Engine
--shodan Using shodan Engine
--fofa Using fofa Engine
--zoomeye Using zoomeye Engine
--goo Using goo Engine
--yahoo Using yahoo Engine
SCRIPT:
--shodan_icon SHODAN_ICON
Get ip list which using the same favicon.ico
--fofa_icon FOFA_ICON
Get ip list which using the same favicon.ico
MISC:
-s SEARCH Speciy Keyword
-o OUTPUT Specify output file default output.txt
-p P AGE Search page (default 1)
-l LIMIT Maximum searching results (default:10) Only Shodan
2.1 示例 python3 Searpy.py --fofa -s "app=jboss" -p 1
python3 Searpy.py --shodan -s "weblogic" -l 10
python3 Searpy.py --google -s "inurl:login.action" -p 1
🥀 Search Engine Tookit,URL采集、Favicon哈希值查找真实IP、子域名查找 (10)">
___________________________
@hacking_Attack
@Hacking_Video
pip install -r requirement.txt
配置API及账号 ./config.py
python Searpy -h
2. Help baidu Engine --google Using google Engine --so Using 360so Engine --bing Using bing (https://www.kitploit.com/search/label/Bing) Engine --shodan Using shodan (https://www.kitploit.com/search/label/Shodan) Engine --fofa Using fofa (https://www.kitploit.com/search/label/Fofa) Engine --zoomeye Using zoomeye (https://www.kitploit.com/search/label/Zoomeye) Engine --goo Using goo Engine --yahoo Using yahoo Engine SCRIPT: --shodan_icon SHODAN_ICON Get ip list which using the same favicon.ico --fofa_icon FOFA_ICON Get ip list which using the same favicon.ico MISC: -s SEARCH Speciy Keyword -o OUTPUT Specify output file default output.txt -p PAGE Search page (default 1) -l LIMIT Maximum searching results (default:10) Only Shodan">
Searpy Engine Tookit
optional arguments:
-h, --help show this help message and exit
ENGINE:
--baidu Using baidu Engine
--google Using google Engine
--so Using 360so Engine
--bing Using bing Engine
--shodan Using shodan Engine
--fofa Using fofa Engine
--zoomeye Using zoomeye Engine
--goo Using goo Engine
--yahoo Using yahoo Engine
SCRIPT:
--shodan_icon SHODAN_ICON
Get ip list which using the same favicon.ico
--fofa_icon FOFA_ICON
Get ip list which using the same favicon.ico
MISC:
-s SEARCH Speciy Keyword
-o OUTPUT Specify output file default output.txt
-p P AGE Search page (default 1)
-l LIMIT Maximum searching results (default:10) Only Shodan
2.1 示例 python3 Searpy.py --fofa -s "app=jboss" -p 1
python3 Searpy.py --shodan -s "weblogic" -l 10
python3 Searpy.py --google -s "inurl:login.action" -p 1
🥀 Search Engine Tookit,URL采集、Favicon哈希值查找真实IP、子域名查找 (10)">
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - j3ers3/Searpy: 🥀 Search Engine Tookit,URL采集、Favicon哈希值查找真实IP、子域名查找
🥀 Search Engine Tookit,URL采集、Favicon哈希值查找真实IP、子域名查找 - j3ers3/Searpy
2.2 其他功能 利用favicon.icon图标hash来寻找使用相同图标的网站,可用于溯源真实IP和资产发现 python3 Searpy.py --shodan_icon https://www.qq.com
python3 Searpy.py --fofa_icon https://www.qq.com
🥀 Search Engine Tookit,URL采集、Favicon哈希值查找真实IP、子域名查找 (11)">
___________________________
@hacking_Attack
@Hacking_Video
python3 Searpy.py --fofa_icon https://www.qq.com
🥀 Search Engine Tookit,URL采集、Favicon哈希值查找真实IP、子域名查找 (11)">
___________________________
@hacking_Attack
@Hacking_Video
Qq
腾讯网
腾讯网从2003年创立至今,已经成为集新闻信息,区域垂直生活服务、社会化媒体资讯和产品为一体的互联网媒体平台。腾讯网下设新闻、科技、财经、娱乐、体育、汽车、时尚等多个频道,充分满足用户对不同类型资讯的需求。同时专注不同领域内容,打造精品栏目,并顺应技术发展趋势,推出网络直播等创新形式,改变了用户获取资讯的方式和习惯。
3. 模块调用 >> from Searpy import Bing >>> s = Bing('inurl:php?id=1', 2) >>> s.search() >>> for i in s.result: >>> print(i)">>>> from Searpy import Bing
>>> s = Bing('inurl:php?id=1', 2)
>>> s.search()
>>> for i in s.result:
>>> print(i) 4. 支持搜索引擎 Shodan Fofa Zoomeye Censys Dnsdb Google Baidu Bing 360so Goo Yahoo 6. ChangeLog v2.3 fix some bugs add fofa_icon module v2.2 fix some bugs 7. Donations XMR: 498AoZRwfC11Fa4LwAyVVp3wRD4Zyf1e1HziegczeWeSYVVTZ8gw8CoNPm5yhY91tkDqDMBg6A5KUfyowMtdkQDrDxE5aVN BTC: 1ALWC7rGL4dHgbyy4R8uTVHmDugPDD7Rvt 8. Contact Twitter (https://twitter.com/j3ers3)
Download Searpy (https://github.com/j3ers3/Searpy)
___________________________
@hacking_Attack
@Hacking_Video
>>> s = Bing('inurl:php?id=1', 2)
>>> s.search()
>>> for i in s.result:
>>> print(i) 4. 支持搜索引擎 Shodan Fofa Zoomeye Censys Dnsdb Google Baidu Bing 360so Goo Yahoo 6. ChangeLog v2.3 fix some bugs add fofa_icon module v2.2 fix some bugs 7. Donations XMR: 498AoZRwfC11Fa4LwAyVVp3wRD4Zyf1e1HziegczeWeSYVVTZ8gw8CoNPm5yhY91tkDqDMBg6A5KUfyowMtdkQDrDxE5aVN BTC: 1ALWC7rGL4dHgbyy4R8uTVHmDugPDD7Rvt 8. Contact Twitter (https://twitter.com/j3ers3)
Download Searpy (https://github.com/j3ers3/Searpy)
___________________________
@hacking_Attack
@Hacking_Video
Twitter
J3ers3 (@j3ers3) | Twitter
The latest Tweets from J3ers3 (@j3ers3). Security
hacking: security in practice
Finding “secret” directories on local servers
I found out that sonos and rokus have “secret” webpages with information.
Sonos you can log in at “http://sonosIP:1400/support/review” and you can get a lot of information about the network, and their connections.
With Roku, you can log in at “http://rokuIP:8060/query/apps” and get an XML file of the apps that are installed on it and app IDs so you can send a quick launch command to it using the ID.
I’ve done a port scan on these devices and found these open ports but that’s as far as I could take it… how would you go about finding these “hidden pages” on servers like this? Or find out if there are any other hidden gems on them?
submitted by /u/thesongdoctor
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Finding “secret” directories on local servers
I found out that sonos and rokus have “secret” webpages with information.
Sonos you can log in at “http://sonosIP:1400/support/review” and you can get a lot of information about the network, and their connections.
With Roku, you can log in at “http://rokuIP:8060/query/apps” and get an XML file of the apps that are installed on it and app IDs so you can send a quick launch command to it using the ID.
I’ve done a port scan on these devices and found these open ports but that’s as far as I could take it… how would you go about finding these “hidden pages” on servers like this? Or find out if there are any other hidden gems on them?
submitted by /u/thesongdoctor
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Finding “secret” directories on local servers
I found out that sonos and rokus have “secret” webpages with information. Sonos you can log in at “http://sonosIP:1400/support/review” and you...