TGViewer
Channel Public Channel
Netlas.io

Netlas.io

@netlas

Explore the latest in cybersecurity with Netlas.io. Stay ahead with updates on high-profile vulnerabilities, expert tutorials, essential safety tips, and the latest Netlas developments.
Subscribers
2.33K
Photos
435
Videos
3
Links
576

Showing posts older than #274 · Back to latest

Older Posts 20 shown
Post #273 724
Blind Spot in the Fortinet VPNs, no CVE❗️

Researchers from Pentera have discovered a potential vulnerability in Fortinet VPNs, probably allowing an attacker to hide the fact that a brute force attack was successfully completed.

Search at Netlas.io:
👉 Link: https://nt.ls/zJEUh
👉 Dork: http.body_sha256:"6e24d74ebc881e1e97331bb72d6edee8431485a8a0cafd7c4a913a3819817b84"

Read more: https://pentera.io/blog/FortiClient-VPN_logging-blind-spot-revealed/
  • 🔥 4
  • 👾 3
Post #272 635
🚧 Planned Maintenance 🚧
The application will be unavailable for a period of time❗️

The maintenance is scheduled to start on November 24, 2024, at 08:00 UTC ⏰. It is expected to take a couple of hours, and we will do our best to complete it as quickly as possible.

Please remember to save your work before this time.
  • 👾 4
  • 🌚 1
  • 🗿 1
Post #271 656
CVE-2024-48990 and other: Multiple vulnerabilities in Needrestart utility for Ubuntu (including Ubuntu Server), 5.3 - 7.8 rating❗️

Five vulnerabilities discovered by researchers from Qualys allow LPE to be carried out on machines running Ubuntu OS and gain root rights.

Search at Netlas.io:
👉 Link: https://nt.ls/ZhaO6
👉 Dork: http.headers.server:"Ubuntu"

Read more: https://www.qualys.com/2024/11/19/needrestart/needrestart.txt
  • 👾 4
  • 🔥 3
  • 👍 2
Post #270 599
Netlas and Shodan: Comprehensive Analysis 🧮

With Netlas recently emerging from beta and reaching version 1.0, we felt it was the perfect time to conduct a comprehensive comparison with its competitors.

We’ve started with one of the toughest challenges: an in-depth, objective comparison of Netlas and the veteran in the field, Shodan. Using over 10 key indicators, we’ve analyzed both platforms to help you understand pros and cons of the two solutions.

👉 Read now: https://netlas.io/blog/netlas_vs_shodan/
netlas.io Netlas vs Shodan: Platforms Comparison - Netlas Blog Compare IoT search engines Netlas and Shodan, highlighting their features, strengths, and ideal use cases for security research.
  • 🔥 6
  • 👾 2
Post #269 609
PAN-OS RCE PoC by Chirag Artani 🔥

Our friend’s channel posted another interesting video about one of the latest vulnerabilities, where he demonstrated Proof of Concept using Netlas 🔍

We also recommend checking out his website and Twitter for more tips:

👉 Site: 3rag.com
👉 Twitter: x.com/Chirag99Artani
YouTube PAN-OS RCE Again - Authentication Bypass in the Management Web Interface & Command Injection | POC POC written by me - https://github.com/Sachinart/CVE-2024-0012-POC Please do not exploit any target without written permission, that's not ethical way. An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with…
  • 👾 6
  • 👏 2
Post #268 622
Minor App Improvements

In update 1.0.3, we've introduced several features to enhance the payment experience.

Here’s what’s new:
📔 Added a Payment Guide
📌 Clarified subscription options for the Freelancer tier
🖥 A few other minor improvements

👉 Read more: https://docs.netlas.io/changelog/
docs.netlas.io Changelog - Netlas Docs Explore the latest updates, enhancements, and fixes on the Netlas platform. Stay informed with our Changelog for all product and feature developments.
  • 👾 3
  • 👍 1
Post #266 40.8K
Automated search for sites by favicon 🔍

When mapping an attack surface or searching for vulnerable web interfaces, favicon matching often plays a critical role. Some IoT search engines, such as Shodan or Netlas, already offer this functionality.

However, today we want to introduce a tool that simplifies this process, developed by a member of the Netlas community. This utility supports searching for favicons across several search engines, including Shodan, Netlas, ZoomEye, and more.

Introducing FAVICORN – a collaborative creation by @soxoj, @seelwersowl, and @osint_mindset 🦄

👉 FAVICORN's GitHub: https://github.com/sharsil/favicorn
GitHub GitHub - sharsil/favicorn: All-sources tool to search websites by favicons All-sources tool to search websites by favicons. Contribute to sharsil/favicorn development by creating an account on GitHub.
  • 👾 4
  • 👍 2
  • 👏 2
Post #264 819
CVE-2024-39710 and other: Multiple vulnerabilities in Ivanti Connect Secure, 4.4 - 9.1 rating 🔥

Lots (25!) of vulnerabilities in the latest Ivanti bulletin. DoS, RCE, Auth Bypass - vulnerabilities on every taste.

Search at Netlas.io:
👉 Link: https://nt.ls/v0fEW
👉 Dork: http.body:"welcome.cgi?p=logo"

Vendor's advisory: https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs?language=en_US
  • 🔥 2
  • 👾 2
  • 👍 1
Post #263 990
CVE-2024-45763 and other: Multiple vulnerabilities in Dell Sonic OS, 9.0 - 9.1 rating 🔥

Some Sonic OS entities are vulnerable to OS Command Injection. Additionally, the vulnerabilities include a weakness in the authentication process that could allow a remote attacker to gain unauthorized access.

Search at Netlas.io:
👉 Link: https://nt.ls/TAX1W
👉 Dork: http.favicon.hash_sha256:d39342cbe7b9717529eb07f697779c55cdae7e0fc26c9672f64c49cbd8411eea

Vendor's advisory: https://www.dell.com/support/kbdoc/en-us/000245655/dsa-2024-449-security-update-for-dell-enterprise-sonic-distribution-vulnerabilities
  • 🔥 3
  • 👾 3
  • 👍 2
Post #262 821
PAN-SA-2024-0015: RCE in Palo Alto PAN-OS 🔥

In a recent advisory from Palo Alto, developers warn about the emergence of an RCE vulnerability. Administrators of potentially vulnerable devices are advised to take action as quickly as possible to minimize the damage.

Search at Netlas.io:
👉 Link: https://nt.ls/UdzF8
👉 Dork: http.body_sha256:"7bc15a9ba71464596444ad648fa144937b848b302459c4103deae105cf42ce42" OR http.favicon.hash_sha256:a03ff6778b0535b9c4388e88c674eeeac91c0cc4b25bd23bf30f8d0bd98ac854

Vendor's advisory: https://security.paloaltonetworks.com/PAN-SA-2024-0015
  • 👾 5
  • 🔥 3
Post #260 690
🚧 Planned Maintenance 🚧
The application will be unavailable for a period of time❗️

The maintenance is scheduled to start on November 10, 2024, at 08:00 UTC ⏰. It is expected to take about an hour, and we will do our best to complete it as quickly as possible.

Please remember to save your work before this time.
  • 👍 1
Post #258 613
💯 Planned Maintenance completed 💯

Netlas.io is online again and you can get back to your projects! 👾
  • 🔥 4
  • 👾 4
Post #257 640
Reminder: The maintenance begins in one hour. Netlas will be temporarily offline. We apologize for any inconvenience caused.
  • 👌 3
Post #256 830
🚧 Planned Maintenance 🚧
The application will be unavailable for a period of time❗️

The maintenance is scheduled to start on November 6, 2024, at 08:00 UTC ⏰. It is expected to take about an hour, and we will do our best to complete it as quickly as possible.

Please remember to save your work before this time.
  • 👎 2
  • 👾 2
  • 😴 1
Post #255 857
CVE-2024-46538: XSS in pfSense, 9.3 rating 🔥

XSS injection allows an attacker to perform arbitrary code execution in the user's browser. The vulnerability is not the freshest, but now it has a PoC!

Search at Netlas.io:
👉 Link: https://nt.ls/BuwaN
👉 Dork: http.title:"pfSense - Login"

Vendor's advisory: https://redmine.pfsense.org/issues/15778
  • 🔥 4
  • 👍 3
  • 👾 3
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →