port-enumeration

2 articles
Sort: New Top Best
clear filter
0

A security researcher describes discovering and exploiting a Server-Side Request Forgery (SSRF) vulnerability using DNS rebinding techniques to bypass IP filtering, access AWS metadata endpoints, enumerate internal ports, and discover a buffer overread vulnerability in a Monit admin interface. The writeup details the exploitation chain and introduces dnsFookup, a GUI tool for automating DNS rebinding attacks.

CVE (Monit buffer overread) AWS Monit OpenSSH lock.cmpxchg8b.com/rebinder.html Fireshell CTF 2019 dnsFookup gel0.space
geleta.eu · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
bug-bounty

A Server-Side Request Forgery (SSRF) vulnerability was discovered in DownNotifier that allowed enumeration of local services through XSPA attacks by bypassing loopback address filters using the 0.0.0.0 address. The vulnerability enabled detection of running services like FTP and HTTP on the server.

DownNotifier downnotifier.com OpenBugBounty PayloadsAllTheThings mqt
m-q-t.github.io · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details