Thrilled to release my latest research on Apache HTTP Server, revealing several architectural issues! https://t.co/7ygwWXY0pd
Highlights include:
⚡ Escaping from DocumentRoot to System Root
⚡ Bypassing built-in ACL/Auth with just a '?'
⚡ Turning XSS into RCE with legacy code from 1996
Check out my Bulk Path Traversal Scanner on GitHub! It's a simple tool with settings for batch size, delay, timeout, and retry attempts. It shows the successful url and auto-saves vulnerable endpoints to an external file with PoC. Feed it your list and go to sleep. #BugBounty
Burp Ex
403 Bypasser
5GC API Parser
Active Scan++
Backslash Powered Scanner
CO2
IP Rotate
J2EEScan
JS Link Finder
JS Miner
Logger++
Log Viewer
GAP
Distribute Damage
IIS Tilde
Look Over There
Param Miner
Software Vulnerability Scanner
SAML Raider
Autorize
Encode IP
Asset Discovery
CVE-2024-6387: OpenSSH 'regreSSHion Vulnerabilidad crítica, permite ejecución de comandos, RCE no autenticado, afecta y expone al servidor de OpenSSH (sshd) en sistemas Linux
https://t.co/TKLkQ5XIir
Afectadas las versiones de OpenSSH anteriores a la 8.10p2.