internal-network-access

4 articles
sort: new top best
clear filter
0 7/10

A researcher discovered a Server-Side Request Forgery (SSRF) vulnerability using DNS rebinding to bypass IP-based access controls, escalating through AWS metadata enumeration and Monit admin interface exploitation to achieve instance shutdown and memory disclosure. The writeup details the methodology, tool creation, and real-world exploitation chain that combined multiple vulnerabilities.

CVE (buffer overread in Monit) AWS metadata service (169.254.169.254) Monit Admin interface Fireshell CTF 2019 Jan Masarik dnsFookup tool lock.cmpxchg8b.com/rebinder.html
geleta.eu · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details
0 6/10

A researcher demonstrates an SSRF bypass technique against Microsoft's Bing Webmaster Central by using the nip.io DNS service to resolve non-standard loopback addresses (127.127.127.127) and bypass IP-based filters, allowing enumeration of internal ports and directories on the application server.

Microsoft Bing Bing Webmaster Central nip.io Elber Andre 0daylabs
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details
0 7/10

Multi-stage vulnerability chain exploiting GitHub credential leaks, password pattern analysis, and CVE-2019-11580 in outdated Atlassian Crowd to achieve RCE and internal network access at a major ICT company. The attacker combined reconnaissance, Google dorking, and public exploits to breach the internal network perimeter.

CVE-2019-11580 Atlassian Crowd Github Th3g3nt3lman Bugcrowd University PayPal Xoom YoKo Kho
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details
0 9/10

A researcher discovered a critical SSRF vulnerability in Google Sites/Caja that allowed fetching arbitrary content from Google's internal production network (Borg cluster infrastructure). By exploiting the server-side JavaScript resource fetching mechanism combined with a Google App Engine URL, they gained unauthorized access to internal Borglet monitoring pages and sensitive configuration data including job details, resource allocation, and system architecture information.

Google Sites Google Caja Google App Engine Borg Kubernetes Borglet Google VRP Gvisor MapReduce BitTable Flume GFS CVE data not provided
opnsec.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details