TGViewer
Channel Public Channel
Netlas.io

Netlas.io

@netlas

Explore the latest in cybersecurity with Netlas.io. Stay ahead with updates on high-profile vulnerabilities, expert tutorials, essential safety tips, and the latest Netlas developments.
Subscribers
2.34K
Photos
439
Videos
3
Links
581

Showing posts older than #54 · Back to latest

Older Posts 20 shown
Post #53 388
Pumps are under attack!!!

Ten vulnerabilities in Osprey pump controllers discovered by Zero Science Lab in February remain unpatched. The list of disclosed vulnerabilities includes RCE and Administrator Backdoor Access. Osprey: door-mounted, irrigation and landscape pump controllers.

Osprey pumps on Netlas.io:
👉🏼 Search: nt.ls/upZRN
👉🏼 Dork: http.title:(Osprey Controller)

https://www.zeroscience.mk/en/vulnerabilities/

#Friday_Horrors
  • 😱 3
Post #52 571
Netlas.io is now integrated with tines.io

Want to use netlas API in your tines.io automations? Just sign in to tines, open the template library and search "Netlas". You can get any IP or domain summary, whois data, scan results and other information from any netlas.io library.

Now it's easy to use netlas.io data within tines.io stories using hundreds of automation templates with no code!
  • 🤝 5
  • 👍 1
Post #51 512
Netlas v.0.21.0 Released!

This new release brings a long awaited feature – Bookmarks. Now you can save your favorite search queries by clicking on the star icon in the search string.

Search by favicon feature is significantly improved. Now can search not only exact matches, but also nearest matches. We use perceptual hash for this. Perceptual hash algorithms are opposite to standard cryptographic hashes — they are optimized to change as little as possible for similar inputs. So you can find answers with favicons that look pretty close to a given input, but use a different color, for example.
  • 🔥 10
  • ❤ 2
  • 👍 2
Post #50 458
A couple of interesting facts about 🔥Jenkins CVE-2023-27898, CVE-2023-27905:
⚠️ Jenkins releases from March, 2021 to March 2023 are affected
⚠️ Even unreachable from the Internet instances could be exploited
⚠️ At least 47,5K vulnerable instances available (directly reachable)

How to search vulnerable Jenkins instances on Netlas.io:
👉🏼 Dork: http.headers.x_jenkins:[2.270 TO 2.393]
👉🏼 Search link: https://tinyurl.com/487t5s8f

Here is the blog post by Aqua Nautilus Security Research Team about these CVE:
https://blog.aquasec.com/jenkins-server-vulnerabilities
  • 🔥 5
  • 👍 1
Post #49 415
Post #46 360
Users of Zoho ManageEngine are being urged to patch their instances against CVE-2022-47966. This vulnerability allows an unauthenticated adversary to execute arbitrary code.

Zoho ManageEngine on Netlas.io:

👉🏼 Dork: tag.name:"manageengine_servicedesk"

👉🏼 Link to search: https://tinyurl.com/yuw2uucn
  • 👍 2
  • 🔥 1
  • 👏 1
Post #45 311
Right now you can purchase Netlas.io subscription with an 80% discount for a month or even a year! In 5 days the prices will go up.

Choose your pricing plan:
https://app.netlas.io/plans/
  • 🔥 4
  • ⚡ 1
  • 🎄 1
Post #43 313
Ron Bowes from Rapid7 published deep-dive into CVE-2022-41622 and CVE-2022-41800
https://tinyurl.com/ysfczh9e

F5 BIG-IP & BIG-IQ on Netlas.io:
👉🏼 Dork: tag.name:(f5_bigip OR f5_big_ip) OR http.favicon.hash_sha256:a8eef57d094fcf99bae2378eb2c2fc2fb15d12f856c028cc979c04451bee84c2
👉🏼 Link to search: https://tinyurl.com/26zn9jdf
Rapid7 CVE-2022-41622 and CVE-2022-41800 (FIXED): F5 BIG-IP and iControl REST Vulnerabilities and Exposures | Rapid7 Blog
  • 👍 2
Post #42 300
Netlas v.0.19.0 brings a referral program!

Use a referral link to invite someone to create netlas.io account. Benefits for invited and inviting, including 10% referral fee 🤑

Help in promotion is another option 💬 👆🏽
  • 👍 4
Post #40 275
ConnectWise Recover and R1Soft Server Backup Manager RCE bug (CVE-2022-36537) disclosure: https://tinyurl.com/ydresab7

They say: “there has been no evidence of exploitation in the wild”, but it is likely a matter of hours or days.

About 5,600 instances potentially affected.

Server Backup Manager on Netlas.io:
👉🏼 Dork: http.body:(("zk.wcs" OR "zk.wpd") AND ("Server Backup")) OR http.favicon.hash_sha256:b7b4ce41a9cc86e1923997f5324b476686c953e87e22424e8375eddeb65e63ec
👉🏼 Search link: https://app.netlas.io/responses/?q=http.body%3A…
Huntress ConnectWise/R1Soft Server Backup Manager Remote Code Execution & Supply Chain Risks | Huntress Huntress has validated an initial report for an authentication bypass and sensitive file leak present in the Java framework “ZK”, used within the ConnectWise R1Soft software Server Backup Manager SE.
  • 🔥 3
  • 🕊 1
Post #39 260
Favicon search is a rarely used but very powerful search tool! Sometimes this is the only way to identify an application.

Try it! It works great 🔎💪🤩

#howto
  • 👍 3
  • 🔥 2
  • ⚡ 1
Post #36 269
Dear Netlas.io users!

The Alpha testing phase is close to completion. There will be a major update to Netlas.io in a few days. This update opens the Beta phase. We believe that the core features of Netlas.io are stable and ready to use. We will continue to develop the service, but now it is extremely important for us to move on to monetization. So, the upcoming update will bring a subscription system. 💵📈

Read more about upcoming update: https://netlas.io/blog/tpost/xv2e7alik1-upcoming-beta-release
  • 🔥 2
  • 🎉 2
  • 👍 1
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →