Please open Telegram to view this post
VIEW IN TELEGRAM
1β€7π3π₯2
This media is not supported in your browser
VIEW IN TELEGRAM
π₯8π³3πΏ1
CVE-2024-55579, -55580: RCE and Broken Access Control in Qlik Sense, 7.5 - 8.8 ratingβοΈ
Vulnerabilities discovered in Qlik Sense allow attackers to run EXE files on the server, as well as remotely execute commands, potentially affecting confidentiality and integrity.
Search at Netlas.io:
π Link: https://nt.ls/9ok2E
π Dork: http.title:"Qlik Sense"
Vendor's advisory: https://community.qlik.com/t5/Official-Support-Articles/High-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows-CVEs/tac-p/2496004
Vulnerabilities discovered in Qlik Sense allow attackers to run EXE files on the server, as well as remotely execute commands, potentially affecting confidentiality and integrity.
Search at Netlas.io:
π Link: https://nt.ls/9ok2E
π Dork: http.title:"Qlik Sense"
Vendor's advisory: https://community.qlik.com/t5/Official-Support-Articles/High-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows-CVEs/tac-p/2496004
π8
CENT Tool
Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one place.
π± CENT Tool π±
Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one place.
Please open Telegram to view this post
VIEW IN TELEGRAM
π₯6β€4π4
dorki.io
taksec.github.io/google-dorks-bug-bounty/
dorksearch.com
dorkme.comdorkgenius.com
Please open Telegram to view this post
VIEW IN TELEGRAM
π₯3
BLACKFRIDAY2024 SALE: Get all of our malware development and red teaming courses bundle for only $199.
β$400
β $199
Start your new year with developing malware and building offensive tools
redteamsorcery.teachable.com/p/learnthemall
β$400
β $199
Start your new year with developing malware and building offensive tools
redteamsorcery.teachable.com/p/learnthemall
π€¨3π2β€1
CVE-2024-11274, -8233, other: Multiple vulnerabilities in GitLab, 7.5 - 8.7 ratingβ
In a new release, GitLab talked about two important vulnerabilities. One of them allows attacker to carry out DoS, the second allows to steal session data and potentially gain unauthorized access to accounts. Several smaller vulnerabilities are also mentioned.
Search at Netlas.io:
π Link: https://nt.ls/xM1vs
π Dork: http.favicon.hash_sha256:72a2cad5025aa931d6ea56c3201d1f18e68a8cd39788c7c80d5b2b82aa5143ef OR http.headers.set_cookie:"gitlab" OR http.headers.location:"gitlab"
Vendor's advisory: https://about.gitlab.com/releases/2024/12/11/patch-release-gitlab-17-6-2-released/
In a new release, GitLab talked about two important vulnerabilities. One of them allows attacker to carry out DoS, the second allows to steal session data and potentially gain unauthorized access to accounts. Several smaller vulnerabilities are also mentioned.
Search at Netlas.io:
π Link: https://nt.ls/xM1vs
π Dork: http.favicon.hash_sha256:72a2cad5025aa931d6ea56c3201d1f18e68a8cd39788c7c80d5b2b82aa5143ef OR http.headers.set_cookie:"gitlab" OR http.headers.location:"gitlab"
Vendor's advisory: https://about.gitlab.com/releases/2024/12/11/patch-release-gitlab-17-6-2-released/
π4π€¨2
Please open Telegram to view this post
VIEW IN TELEGRAM
GitHub
GitHub - mrmtwoj/apache-vulnerability-testing: Apache HTTP Server Vulnerability Testing Tool | PoC for CVE-2024-38472 , CVE-2024β¦
Apache HTTP Server Vulnerability Testing Tool | PoC for CVE-2024-38472 , CVE-2024-39573 , CVE-2024-38477 , CVE-2024-38476 , CVE-2024-38475 , CVE-2024-38474 , CVE-2024-38473 , CVE-2023-38709 - mrmt...
β€10π2
Please open Telegram to view this post
VIEW IN TELEGRAM
β€10π₯4π1
π Dnsbruter - A powerful tool for active subdomain enumeration and discovery.
β¨ Features:
Dnsbruter uses DNS resolution to bruteforce and identify subdomains efficiently. Its multithreading capability allows users to control concurrency for faster and more effective results. Perfect for researchers and pen testers targeting domain reconnaissance.
π https://github.com/RevoltSecurities/Dnsbruter/
β¨ Features:
Dnsbruter uses DNS resolution to bruteforce and identify subdomains efficiently. Its multithreading capability allows users to control concurrency for faster and more effective results. Perfect for researchers and pen testers targeting domain reconnaissance.
Please open Telegram to view this post
VIEW IN TELEGRAM
π₯12π4
Please open Telegram to view this post
VIEW IN TELEGRAM
π11β€3