Sharing some goodies. 🔥
XSS vulnerability in Adminer versions 4.6.1 to 4.8.0 affects users of MySQL, MariaDB, PgSQL, and SQLite.
CVE-2021-29625
Base Score: 7.5 HIGH
Search by the technology name: spyse.com/target/technol…
Tired of answering the same questions every time. Below answers to the most common questions asked by @SpyseHQ users:
- No, we don’t help to hack socials of your GF/ex;
- We don’t know how to find the phone you lost;
- We don’t know how to delete your private photos from the web
This was a simple bug but yet very effective and could have been used to build a data set of FB users and their added phone numbers similarly to how the recent leak was built.
Identify a Facebook user by his phone number despite privacy settings set ( $9K)
ysamm.com/?p=691
CVE-2021-29456
In Authelia v4.27.4 and earlier, utilizing HTTP query parameter attacker can redirect users from the web application to any domain.
Base Score: 5.7 MEDIUM
Patch released 9 days ago; still, enough time to get your bounty.
Search query:
spyse.com/advanced-searc…
CVE-2020-2501
A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station.
Base Score: 9.8 CRITICAL ⚠️
Search query:
spyse.com/advanced-searc…
Easy #BugBounty for those who have Pro.
CVE-2020-23762
XSS vulnerability in the Larsens Calender plugin Version <= 1.2 for WordPress.
An old plugin that didn't update for a long time.
Query: spyse.com/advanced-searc…
Spending some time with Spyse, you start to find interesting stuff... Does anyone know why "Markus Koch" needs his own AS with heaps of Tor IP addresses?
AS: spyse.com/target/as/2082…
CVE-2021-28925, CVE-2021-28924.
SQL injection vulnerability in Nagios Network Analyzer before 2.4.3 and Self Authenticated XSS before 2.4.2.
Base Score: really bad🤷♂️
Search query:
spyse.com/advanced-searc…
CVE-2021-27329
Friendica 2021.01 allows SSRF via parse_url?binurl= for DNS lookups or HTTP requests to arbitrary domain names.
Score: 10.0 CRITICAL 🔥
Search query: spyse.com/advanced-searc…
4 Followers 160 FollowingRecruiting webshell engineers to penetrate websites, with a monthly salary of up to $100,000. If interested, please contact https://t.co/wnVDDwQRGn
49 Followers 366 FollowingYeah, raildex1 was already taken xD Into WebSec, PenTesting and all that good stuff. Blog at https://t.co/XBDDT8fJul - They're popular like it's 2010!
235K Followers 1K FollowingCofounder @hackinghub_io | Advisor @CaidoIO. I hack companies and make content about it. #NahamCon organizer. ex @hacker0x01🇮🇷
43K Followers 900 FollowingCo-founder of @centrahq/@detectify/@poweredbyingrid. I do not advertise doing hacking services, do not trust the ones telling you I do.
326K Followers 3K FollowingThe only official HackerOne Twitter account.
A global leader in offensive security solutions. #HackForGood #togetherwehitharder
37K Followers 530 FollowingHacker, bug bounty hunter, guy behind https://t.co/TBAtP71Cop. 1st in Meta bug bounty program for the last 6 years. YES Team Member
4K Followers 4K FollowingFounder @FleetSportsAI - a platform that leverages autonomous AI agents to transform complex sports data into actionable intelligence.
11K Followers 1K FollowingCensys is the source for real-time Internet intelligence and actionable threat insights for governments, F500 companies, and leading threat intel providers
37K Followers 183 FollowingNuclei uses a vast templating library to scan applications, cloud infrastructure, and networks to find and remediate vulnerabilities.