firewall

2 articles
sort: new top best
clear filter
0 7/10

Reflected XSS vulnerability in Avast Desktop AntiVirus (and AVG) via unsanitized SSID name reflection in the Firewall's Network Notification feature popup, allowing attackers to execute arbitrary JavaScript through a malicious wireless network name. The vulnerability was discovered by connecting to a tethering connection with an XSS payload SSID and triggered when the notification feature displayed the network name without proper input filtering, earning a $5,000 bounty.

CVE-2019-18653 CVE-2019-18654 Avast AVG YoKo Kho Brute Logic S0md3v Deral Heiland Windows 10 InfoSec Write-ups
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details
0 5/10

A developer's PostgreSQL instance running in Docker was publicly exposed with default credentials (postgres:postgres), allowing an automated attacker to delete the database and demand ransom. The root causes were Docker's default port binding behavior, missing firewall rules, and default credentials left unchanged.

Akseli Lahtinen scalie.computer linkhut PostgreSQL Docker UFW
akselmo.dev · birdculture · 1 day ago · details · hn