👑So Russia and Ukraine are seriously at war? Why not just call the 2 presidents, give them a boxing gloves and ask them to battle in the boxing ring all alone. Why put innocent people's lives in danger. Retweet till the presidents get this message👑
CVE-2021-21985/CVE-2021-21986: The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server.
PoC
https://t.co/vWYuwZugx4
Tools designed to automate phishing attacks that are intended to bypass 2FA
evilginx2: https://t.co/9haUXdvpV1
Modlishka: https://t.co/mHNvbvYzF7
KoiPhish: https://t.co/JTA9T4r5yF
ReelPhish https://t.co/FXtzjwgCYG
CredSniper:https://t.co/mFTPZYg8xY
muraena:https://t.co/e5Cl66DsFv
A lot of companies use S3 buckets and here are some GitHub dorks for S3 bucket enumeration:
S3_USER_SECRET=
S3_KEY_ASSETS=
https://t.co/lAxyL3zkxg=
S3_KEY_APP_LOGS=
S3_BUCKET_NAME_APP_LOGS=
happy hacking :)
#bugbountytips
Microsoft says its investigation into malicious SolarWinds code in its systems found no evidence attackers used that to forge single sign-on tokens for its corporate domains. But it did find the intruders viewed (but didn't alter) Microsoft source code. https://t.co/JmneYxbp1D
Chaining file uploads with other vulns:-
Set filename to:-
> ../../../tmp/lol.png for path traversals
> sleep(10)-- -.jpg for SQLi.
> <svg onload=alert(document.comain)>.jpg/png for xss
> ; sleep 10; for command injections
#bugbountytips
👨🏻💻 The long awaited day has finally come, we are closing in on ARPCon 2020 conference. Here we are presenting our timeline for the first day, 11th October, 2020:
4.45 PM to 5.00 PM - Opening Ceremony
5 PM to 5.20 PM - @tandonrakshit
5.30 PM to 6.10 PM - @_shivambathla