TGViewer
Channel Public Channel
Netlas.io

Netlas.io

@netlas

Explore the latest in cybersecurity with Netlas.io. Stay ahead with updates on high-profile vulnerabilities, expert tutorials, essential safety tips, and the latest Netlas developments.
Subscribers
2.33K
Photos
435
Videos
3
Links
576

Showing posts older than #254 · Back to latest

Older Posts 20 shown
Post #252 831
Pre-Auth RCE CyberPanel 0day by Chirag Artani 🔥

Useful video from our friend's channel about one of the freshest big vulnerabilities with Netlas search 🔎

We also recommend checking out his website and Twitter for more tips:

👉 Site: 3rag.com
👉 Twitter: x.com/Chirag99Artani
YouTube Pre-Auth Remote Code Execution CyberPanel 0day | Live Recon Using Netlas CyberPanel v2.3.6 has a critical vulnerability that allows remote attackers to execute arbitrary commands on the server without prior authentication. Impact: Attackers can exploit this vulnerability by crafting malicious requests that bypass authentication…
  • 🔥 6
  • 👾 4
  • ❤ 2
Post #251 579
CVE-2024-50388: OS Command Injection in QNAP NAS, critical rating 🔥

A vulnerability exploited on Pwn2Own and affecting HBS 3 Hybrid Backup Sync allows attackers to carry out remote command execution.

More then 113k instances at Netlas.io:
👉 Link: https://nt.ls/MBHWB
👉 Dork: certificate.issuer_dn:"QNAP NAS" OR http.body_sha256:4a1815f3e87d6d623c22921d9c39b2de614351d71831976bbc807f571953ff21

Vendor's advisory: https://www.qnap.com/en-us/security-advisory/qsa-24-41
  • 👾 6
  • 👍 3
  • 🔥 2
Post #250 614
CVE-2024-46483: Integer Overflow in Xlight FTP Server, 9.8 rating 🔥

By overflowing the variable, an attacker could cause remote code execution on the host or a denial of service.

Search at Netlas.io:
👉 Link: https://nt.ls/M8D2R
👉 Dork: \*.banner:"Xlight" OR raw_tcp.response_data:"Xlight"

Read more: https://github.com/kn32/cve-2024-46483
  • 🔥 6
  • 👾 2
  • 👍 1
Post #249 576
🔥 Netlas.io beta testing is finally over! 🔥

In version 1.0, we've added a final touch — recurring payments to simplify the payment process for subscribers.

❓ How to enable recurring payments ❓

If you haven’t subscribed yet, simply select the "Recurring Payments" option at checkout.

If you're already a subscriber, wait until the end of your current billing period, then renew your subscription by choosing the "Recurring Payments" option.

👉 Read more in the changelog: https://docs.netlas.io/changelog/
  • 🔥 4
  • ⚡ 2
  • 👾 1
Post #247 665
CVE-2024-20329: Improper Neutralization of Command Delimiters in Cisco ASA, 9.9 rating 🔥🔥🔥

The vulnerability allows an attacker with low privileges to remotely execute commands via SSH and thus gain full control of the system.

More then 140k instances at Netlas.io:
👉 Link: https://nt.ls/Rfjme
👉 Dork: http.body:"/+CSCOE+/logon.html"

Vendor's advisory: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ssh-rce-gRAuPEUF
  • 🔥 5
  • 👍 3
  • 👾 3
Post #246 781
CVE-2024-9264: Execute Arbitrary Code in Grafana, 9.9 rating 🔥🔥🔥

Grafana users at Viewer level and above can perform command injection using a vulnerability in SQL Expressions.

More then 104k instances at Netlas.io:
👉 Link: https://nt.ls/oQJHO
👉 Dork: http.favicon.hash_sha256:80a7f87a79169cf0ac1ed3250d7c509368190a97bc7182cd4705deb8f8c70174 AND http.title:"Grafana"

Vendor's advisory: https://grafana.com/blog/2024/10/17/grafana-security-release-critical-severity-fix-for-cve-2024-9264/
  • 🔥 5
  • 👾 2
  • 👍 1
Post #242 585
CVE-2024-49193: Email Spoofing in Zendesk 🔥

Knowing the support email and ticket id, an attacker can view the entire history of the ticket, thus gaining access to sensitive data.

Search at Netlas.io:
👉 Link: https://nt.ls/dWuES
👉 Dork: http.unknown_headers.key:"x_zendesk_processed_host_header" OR http.unknown_headers.key:"x_zendesk_origin_server"

Read more: https://gist.github.com/hackermondev/68ec8ed145fcee49d2f5e2b9d2cf2e52
  • 👾 3
  • 👍 2
  • 🔥 2
  • 🤔 1
Post #241 683
Google Dorking in Cybersecurity: Examples and Automation 🔥

Discover the most useful dorks, principles for constructing queries, examples, and even a script for automating reconnaissance within a given scope. Mastering Google Dorks has never been easier 🔍

👉 Read now: https://netlas.io/blog/google_dorking_in_cybersecurity
netlas.io Google Dorking in Cybersecurity - Netlas Blog Explore Google dorking techniques to boost your OSINT and penetration testing. Learn automation tricks, best practices, and top analogues.
  • 🔥 3
  • 👾 3
  • ❤ 1
  • 👍 1
Post #240 625
CVE-2024-3656: Exposure of Sensitive Information in Keycloak, 8.1 rating 🔥

A vulnerability in Keycloak's REST API could allow an attacker to execute commands and gain access to sensitive information.

Search at Netlas.io:
👉 Link: https://nt.ls/pcxk7
👉 Dork: http.favicon.hash_sha256:47dcf1f1a8f1afd68297a294a263849069a7a62b2e86550241416c2cc56c5676

Read more: https://access.redhat.com/security/cve/CVE-2024-3656
  • 👍 2
  • 🔥 2
  • 👾 2
Post #239 632
CVE-2024-9164 and other: Multiple vulnerabilitites in Gitlab, 3.7 - 9.6 rating 🔥

Many vulnerabilities have been fixed in Gitlab again! The most critical one this time allows an attacker to run pipelines on arbitrary branches, while the others include XSS, SSRF attacks, etc.

Search at Netlas.io:
👉 Link: https://nt.ls/gqVLn
👉 Dork: host:gitlab.* OR http.favicon.hash_sha256:72a2cad5025aa931d6ea56c3201d1f18e68a8cd39788c7c80d5b2b82aa5143ef

Vendor's advisory: https://about.gitlab.com/releases/2024/10/09/patch-release-gitlab-17-4-2-released/
  • 👾 4
  • 🔥 3
  • 👍 1
Post #235 4.65K
🔥 Improved Interaction with Private Scanner 🔥

Netlas 0.25.1 Update was published. IP/Domain information is now sourced from private scans if they are more relevant than general results. Check out the example in the picture! 👾

👉 Read about other changes: https://docs.netlas.io/changelog/
  • 👍 4
  • 👾 4
  • ❤ 2
Post #234 650
FSCT-2024-0006 and other: Multiple vulnerabilities in DrayTek Vigor Routers, 7.5 - 10.0 rating 🔥🔥🔥

Researchers from Vedere Labs discovered problems in 24 router models. RCE, DoS, XSS - vulnerabilities for every taste. We recommend that owners of these devices take action as quickly as possible.

Search at Netlas.io:
👉 Link: https://nt.ls/PyUd8
👉 Dork: certificate.issuer.common_name:"Vigor Router"

Read more: https://www.forescout.com/resources/draybreak-draytek-research/
  • 🔥 6
  • 👾 2
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →