TGViewer
Channel Public Channel
Netlas.io

Netlas.io

@netlas

Explore the latest in cybersecurity with Netlas.io. Stay ahead with updates on high-profile vulnerabilities, expert tutorials, essential safety tips, and the latest Netlas developments.
Subscribers
2.33K
Photos
437
Videos
3
Links
578

Showing posts older than #134 · Back to latest

Older Posts 20 shown
Post #133 927
CVE-2023-39336: SQL injection and RCE in Ivanti EPM, 9.6 rating 🔥

An attacker can use SQL injection without authentication. Additionally, if the core server is configured to use Microsoft SQL Express, this might lead to RCE on the core server.

Search at Netlas.io:
👉🏻 Link: https://nt.ls/fSOY9
👉🏻 Dork: http.headers.set_cookie:("JSESSIONID" "Path" "/mifs")

Vendor's advisory: https://forums.ivanti.com/s/article/SA-2023-12-19-CVE-2023-39336?language=en_US
  • 🔥 6
  • 👾 4
  • 👍 2
Post #132 998
Tomorrow the new year begins, and Netlas.io wants to share with you the results of the outgoing year! 🎄

Are you ready to little statistic?

👉 Total requests: > 3.447.000
👉 New users: 8.970
👉 Total coins spent: > 11.300.000
👉 Total graphs saved: 515

📖 Most popular article: https://medium.com/osint-ambition/how-to-find-online-cameras-with-netlas-io-c68cdf5f327f
❗ Most popular CVE post: CVE-2023-3128 (https://twitter.com/Netlas_io/status/1672167625617727488)

Thank you for being with us. Stay in touch, conduct reconnaissance, read about vulnerabilities. See you next year!
  • 🎄 11
  • 👍 4
Post #131 858
How to detect unprotected databases? About this in our new article 🔥

Databases accessible from the Internet are an attractive target for attackers. In new article, we will tell you how to find them using Netlas and make sure that you are invulnerable to this.

👉 Article: https://netlas.medium.com/how-to-find-unprotected-databases-with-netlas-io-2bf186e9fc2d
Medium How to find unprotected databases with Netlas.io? Databases accessible from the Internet are an attractive target for attackers. How to make sure you are invulnerable?
  • 👍 6
  • 👾 6
Post #130 904
CVE-2023-7102: vulnerability in Barracuda ESG, 8.8 rating🔥

An ACE vulnerability in the third-party library Spreadsheet::ParseExcel allowed hackers to deploy a backdoor on an unknown number of devices.

Search at Netlas.io:
👉 Link: https://nt.ls/fJ3H9
👉 Dork: http.favicon.hash_sha256:555e2bc263107f6869c0e1f6b907369b2dff25d001ebd8432d60062dc9699197

Vendor's advisory: https://www.barracuda.com/company/legal/esg-vulnerability
  • 👾 5
  • 👍 2
Post #129 1.08K
CVE-2023-35384, -36710: RCE and Bypass in Microsoft Outlook, 5.4 - 7.8 rating 🔥

Despite the fact that only one of the vulnerabilities has a Network attack vector, combining them could allow an attacker to carry out a full-fledged 0-click RCE against Outlook users.

Search at Netlas.io:
👉🏻 Link: https://nt.ls/imL2R
👉🏻 Dork: http.favicon.hash_sha256:cf0808a61ec571e0c4975663903b288009d55502ac0445d9948983b339a5cf6e

Read more: https://www.akamai.com/blog/security-research/chaining-vulnerabilities-to-achieve-rce-part-one
  • 👾 4
  • 👍 2
Post #127 3.06K
CVE-2023-42325, -42326, -42327: XSS and RCE in pfSense Security, 5.4 - 8.8 rating 🔥

By combining vulnerabilities, an attacker can force a user to activate XSS payload and thereby achieve RCE. pfSense CE 2.7.0 and below, pfSense Plus 23.05.1 and below are vulnerable.

Search at
Netlas.io:
👉
Link (tag, more results): https://nt.ls/BRDDo
👉 Link (no tag): https://nt.ls/Mr8WD
👉 Dork: http.favicon.hash_sha256:b2dd935235013a51fde0a2afc12ba965952e384b7ab43fe1746cc21c7eafc38c

Vendor's advisory:
https://docs.netgate.com/downloads/pfSense-SA-23_08.webgui.asc
  • 👾 6
  • 👍 1
Post #126 872
CVE-2023-45316, -45847, -46701 and other: Multiple vuln in Mattermost, 3.7 - 7.3 rating ❗️

DoS, Path Traversal, Improper Access Control and much more: seven fresh vulnerabilities in the Mattermost chat application.

Search at Netlas.io:
👉🏻 Link: https://nt.ls/83sLi
👉🏻 Dork: http.meta:"mattermost"

Vendor's advisory: https://mattermost.com/security-updates/
  • 👾 4
  • 👍 1
Post #125 819
Dear Netlas users,

We have been experiencing problems with the site for the last two days. We sincerely apologize for this.

This is because we are migrating our application to new hardware, doubling the computing power. We promise that after the move is completed, Netlas will work faster and more stable.

Thank you for your patience ❤️
  • 💊 12
  • 😭 2
Post #124 858
Full attack surface reconnaissance with reNgine & Netlas.io 🔥

New article on our blog, in which we will talk about using the reNgine intelligence framework in conjunction with Netlas.io. Subdomains, endpoints, OSINT information and much more will be found 🔍

👉 Read here: https://netlas.medium.com/using-rengine-with-netlas-io-module-436e764a5495

Enjoy reading!
Medium Using reNgine with Netlas.io module reNgine is a fairly powerful intelligence framework. In this article I will tell you how to configure it for use in conjunction with…
  • 👾 5
  • 👍 3
  • 🔥 1
Post #123 765
CVE-2023-22522, -25524: Two RCE in Atlassian Confluence Data&Server, 9.0 rating 🔥

More problems with Atlassian software. This time, an authorized attacker (even an anonymous one) can inject code and achieve RCE. We recommend updating.

Search at Netlas.io:
👉🏻 Link (tag, more results): https://nt.ls/DZHaW
👉🏻 Link (no tag, less results): https://nt.ls/Siajm

👉🏻 Dork №1: tag.name:"atlassian_confluence"
👉🏻 Dork №2: http.meta:"confluence-base-url"

Vendor's advisory: https://confluence.atlassian.com/security/december-2023-security-advisories-overview-1318892103.html
  • 👾 4
  • 👍 3
  • 🔥 1
Post #121 874
CVE-2023-48121: Auth Bypass in Hikvision, 8.2 rating ❗️

Some Hikvision products have been affected by an authentication bypass vulnerability in the Hik-Connect Module, which could allow remote attackers to consume services by sending crafted messages to the affected devices.

Search at Netlas.io:
👉🏻 Link: https://nt.ls/hbCPs
👉🏻 Dork: http.favicon.hash_sha256:7d249b2fca8ab8d5ab373444732b8bc9104ab597976640f3441ddfd70148b527

Vendor's advisory: https://www.hikvision.com/hk/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-products/
  • 👾 4
  • 🔥 3
  • 👍 2
Post #119 875
New article on our blog. And this time with the fresh script 🔥

Today we will tell how you can use Netlas to search for potentially vulnerable objects in your attack surface. Do not miss the Github link at the end of the article!

👉🏻 Link: https://netlas.medium.com/how-to-find-probably-vulnerable-objects-in-your-own-surface-with-netlas-io-7f3448363892
Medium How to find probably vulnerable objects in your own surface with Netlas.io? Quickly and easily check organization’s surface for vulnerabilities using Netlas.io.
  • 👾 5
  • 🔥 3
Post #118 770
CVE-2023-46849, -46850: DoS and use-after-free in OpenVPN Access Server ❗️

If the --fragment parameter is present in the target device's configuration, an attacker can crash the software by dividing by zero and also gain access to sensitive information.

Search at Netlas.io:
👉🏻 Link: https://nt.ls/GpBD3
👉🏻 Dork: http.headers.server:"OpenVPN-AS"

Vendor's advisory: https://openvpn.net/security-advisory/access-server-security-update-cve-2023-46849-cve-2023-46850/
  • 👾 4
  • ❤ 1
  • 👍 1
  • 🔥 1
Post #116 851
CVE-2023-22518: Improper Authorization in Atlassian Confluence Data&Server, 9.1 rating 🔥

Not a very fresh vulnerability, but the recently released PoC makes it worthy of attention.

Search at Netlas.io:
👉🏻 Link (tag, more results): https://nt.ls/MwYfk
👉🏻 Link (no tag, less results): https://nt.ls/nysj9

👉🏻 Dork №1: tag.name:"atlassian_confluence"
👉🏻 Dork №2: http.meta:"confluence-base-url"

Vendor's advisory: https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html
More about PoC: https://github.com/sanjai-AK47/CVE-2023-22518
  • 👾 5
  • 👍 1
Post #115 841
Do you remember that Netlas can be used as an extension for Google Chrome?

Well, from today our plugin is also available for the Mozilla Firefox browser! 🦊

Now it's users can explore the site they are on at any time with a couple of clicks. Find out potential vulnerabilities, host data, and much more.

👉🏻 Read more (updated): https://netlas.medium.com/netlas-io-chrome-extension-65a8e3d03bc0
👉🏻 Add-on: https://addons.mozilla.org/en-GB/firefox/addon/netlas-io/
  • 👾 7
  • 👏 2
Post #114 4.61K
New cheatsheet 📄

Today we have prepared for you useful search filters that will greatly facilitate the creation of queries for Netlas.io 🔍
  • 👾 5
  • 👍 1
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →