Rezultati pretraživanja
  1. 3. velj
  2. "Mitigation can be difficult, but the best solutions depend on a variety of controls to help prevent issues from known and unknown SSRF vulnerabilities" Dan Ritter looks into the many faces of Server-Side Request Forgery () in his latest article ->

  3. 3. velj
    Odgovor korisniku/ci

    Damn, that's some great info on , thanks

  4. 2. velj
  5. 29. sij
  6. 6. pro 2019.

    Published a short blogpost about how the introduction of affects attempts on instances, especially when attempting to retrieve information. cc:

  7. 25. stu 2019.
  8. 15. stu 2019.

    Bypass if the WAF blocks exact file:///etc/passwd try file:///etc/./passwd

    Prikaži ovu nit
  9. 3. stu 2019.
  10. 7. lis 2019.

    A side from the old tricks to bypass 127.0.0.1 being blacklisted (i.e. 127.1, ::80, A record pointing to localhost etc). Have learned that INET_A(P)TON would consider any IP within the range of 127.0.0.1/8 the same as localhost i.e.~# curl 127.4.142.123

    Prikaži ovu nit
  11. 1. kol 2019.

    And some of you know my "simple-oob-scanner" tool, which I used to find some on Starbucks and other ressources. My private tool for this was also released some minutes ago:

  12. Pown-Duct - Essential Tool For Finding Blind Injection Attacks

  13. 18. tra 2019.

    Bypass filters by using http://127.1 instead of http://127.0.0.1 It resolves to the same but confuses filters blocking localhost/127.0.0.1 specifically!

  14. 8. tra 2019.
    Prikaži ovu nit
  15. 20. ožu 2019.

    Did you find the , but http://169.254.169.254/ is blacklisted? try http://0xA9FEA9FE/, http://0251.0376.0251.0376/ or get more examples from talk

  16. 16. ožu 2019.

    Automatic SSRF fuzzer and exploitation tool

  17. extension is almost done your modules are awesome man, I've used them 👾👾

  18. 16. velj 2019.

    I just published $1.000 SSRF in Slack

Čini se da učitavanje traje već neko vrijeme.

Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.