Has anyone used #projectdiscovery suite, or developed Nuclei templates?

How well does it work compared to other tools like Greenbone or some other similar scanning suites?

It looks.. cumbersome and tech-debt-y full of kludges. I definitely couldn't make anything better or maybe at all, so props for that, however I can see it being a problem in the future, and its weird limitations.

#infosec

🚨 Wiz uncovered CVE-2024-43405, a bypass in #Nuclei enabling code execution. Fixed with #ProjectDiscovery. Update to v3.3.2+, Run tools in isolated environments!

https://www.wiz.io/blog/nuclei-signature-verification-bypass

A Signature Verification Bypass in Nuclei (CVE-2024-43405) | Wiz Blog

Wiz's engineering team discovered a high-severity signature verification bypass in Nuclei which could potentially lead to arbitrary code execution.

wiz.io
For Science: EVE Online ramps up cancer-fighting Project Discovery with new minigames and rewards | Massively Overpowered

Install Go (1.21.0) in Ubuntu 22.04.2 in 5 minutes.

Medium
For Science: EVE Online’s Project Discovery initiative opens signups for mobile testing | Massively Overpowered

Cvemap from ProjectDiscovery
Introduction

Cvemap is a new tool developed by Project Discovery to deliver a structured and easily navigable interface to Common Vulnerabilities and Exposures (CVEs) within multiple databases.

It takes a comprehensive approach to prioritize CVEs, moving beyond the usual Common Vulnerability Scoring System (CVSS) score. It looks at
https://www.rffuste.com/2024/02/05/cvemap-from-projectdiscovery/
#General #Tutoriales #cve #cvemap #projectDiscovery #tools

Cvemap from ProjectDiscovery

Introduction Cvemap is a new tool developed by Project Discovery to deliver a structured and easily navigable interface to Common Vulnerabilities and Exposures (CVEs) within multiple databases. It …

/sec/rffuste

CVEmap

A command-line interface (CLI) tool designed to provide a structured and easily navigable interface to various vulnerability databases

https://blog.projectdiscovery.io/announcing-cvemap-from-projectdiscovery

#bugbounty #cve #infosec #projectdiscovery #security

Announcing cvemap from ProjectDiscovery

Security professionals are constantly on guard against cyber threats, especially given the rising number and sophistication of attacks. However, there's a less obvious, yet increasingly alarming "enemy" in cybersecurity: the surge in reported Common Vulnerabilities and Exposures (CVEs). Though CVEs are vital for identifying and discussing vulnerabilities, their rapid increase

ProjectDiscovery Blog

Looks like the good folks at Project Discovery have implemented the full F5 RCE attack chain in a Nuclei Template already. That didn't take long at all, I suspect we'll be posting the rest of the blog this week.

https://github.com/projectdiscovery/nuclei-templates/pull/8496

#CVE202346747 #f5 #nuclei #projectdiscovery

Added CVE-2023-46747 (5 BIG-IP - Unauthenticated RCE via AJP Smuggling) by ehsandeep · Pull Request #8496 · projectdiscovery/nuclei-templates

Template / PR Information Added CVE-2023-46747 (5 BIG-IP - Unauthenticated RCE via AJP Smuggling) Reference: https://www.praetorian.com/blog/refresh-compromising-f5-big-ip-with-request-smugglin...

GitHub

Best Nuclei scan for beginners.

sudo nuclei -u example. com -as

This uses wapalyzer to check what technologies it can detect then automatically choose the tags and templates for you.

#z0ds3c #nuclei #projectdiscovery #webhacking #webscan