service-enumeration

1 article
sort: new top best
clear filter
0 6/10
bug-bounty

A researcher discovered and exploited an SSRF vulnerability in DownNotifier's website monitoring service, using the 0.0.0.0 loopback address to bypass filters and enumerate local services (FTP, HTTP) via XSPA timing analysis.

DownNotifier downnotifier.com OpenBugBounty PayloadsAllTheThings mqt
m-q-t.github.io · devanshbatham/Awesome-Bugbounty-Writeups · 6 hours ago · details