Information Security
408 subscribers
157 photos
5 videos
9 files
2.28K links
Information Security News

we are @sec_nerd twin brother
Download Telegram
https://github.com/OWASP/Amass


OWASP Amass Tip

For ASNs:
amass intel -org OrgName

For domain names:
amass intel -active -asn n1,n2

For subdomains and infrastructure:
amass enum -src -ip -df domains.txt
This media is not supported in your browser
VIEW IN TELEGRAM
Henry Chen
@chybeta
CVE-2019-8451 Unauthorized SSRF via REST API /plugins/servlet/gadgets/makeRequest

use @ to bypass the whitelisting !

https://jira.atlassian.com/browse/JRASERVER-70001?filter=13085
vb5.py
820 B
# vBulletin 5.x 0day pre-auth RCE exploit
#
# This should work on all versions from 5.0.0 till 5.5.4
Tesla
PowerPack