Hunter4Good

21 Followers
12 Following
18 Posts
Internet search engine for security researchers
https://hunter.how/
Twitter: @HunterMapping
Telegram Channel: http://t.me/hunter4good

๐ŸšจAlert๐Ÿšจ CVE-2023โ€“29357 CVE-2023โ€“24955 #SharePoint's Pre-Auth RCE chain
๐Ÿงทhttps://hunter.how/list?searchValue=protocol.banner%3D%22MicrosoftSharePointTeamServices%22

Dorks ๐Ÿ‘‡๐Ÿ‘‡๐Ÿ‘‡
FOFA app="Microsoft-SharePoint"
Shodan http.headers_hash:-1968878704

๐Ÿ’ก๐Ÿ’ก๐Ÿ’กDeep-dive from
@starlabs_sg

https://twitter.com/starlabs_sg/status/1706267228436599185
#infosec #infosecurity #Infosys

Hunter Search Engine

Internet Search Engines For Security Researchers

๐ŸšจAlert๐Ÿšจ CVE-2023-41892 #Craft CMS's CVSS ๐Ÿ”ฅ10.0๐Ÿ”ฅ Vulnerability
๐Ÿงทhttps://hunter.how/list?searchValue=web.body%3D%22SEOmatic%22

Dorks ๐Ÿ‘‡๐Ÿ‘‡๐Ÿ‘‡
FOFA body="SEOmatic"
Shodan http.html:"SEOmatic"

๐Ÿ™Œ๐Ÿ™Œ๐Ÿ™Œ @chybeta has reproduced this vulnerability
https://twitter.com/chybeta/status/1703685169637704121
#infosec #infosecurity #Infosys

Hunter Search Engine

Internet Search Engines For Security Researchers

๐ŸšจAlert๐Ÿšจ CVE-2023-37895 Apache Jackrabbit RMI #RCE

๐Ÿงทhttps://hunter.how/list?searchValue=web.body%3D%22webdav-jcr.jsp%22

Other Dorks ๐Ÿ‘‡๐Ÿ‘‡๐Ÿ‘‡
FOFA app="Apache-Jackrabbit-JCR-Server"
Shodan http.html:webdav-jcr.jsp

Credit to @Y4er_ChaBug
https://y4er.com/posts/cve-2023-37895-apache-jackrabbit-rmi-rce/
#Infosys #infosec #infosecurity

Hunter Search Engine

Internet Search Engines For Security Researchers

๐ŸšจAlert๐Ÿšจ CVE-2023-37895 Apache Jackrabbit RMI #RCE

๐Ÿงทhttps://hunter.how/list?searchValue=web.body%3D%22webdav-jcr.jsp%22

Other Dorks ๐Ÿ‘‡๐Ÿ‘‡๐Ÿ‘‡
FOFA app="Apache-Jackrabbit-JCR-Server"
Shodan http.html:webdav-jcr.jsp

Credit to @Y4er_ChaBug
https://y4er.com/posts/cve-2023-37895-apache-jackrabbit-rmi-rce/
#Infosys #infosec #infosecurity

Hunter Search Engine

Internet Search Engines For Security Researchers

๐ŸšจAlert๐Ÿšจ CVE-2023-40068 #WordPress custom field(ACF) plugin #XSS vulnerability

๐Ÿงท https://hunter.how/list?searchValue=web.body%3D%22%2Fwp-content%2Fplugins%2Facf-frontend-form-element%2F%22

Dork ๐Ÿ‘‡๐Ÿ‘‡๐Ÿ‘‡
"/wp-content/plugins/acf-frontend-form-element/"

Refer to ๐Ÿ“ฐ
https://securityonline.info/wordpress-custom-field-plugin-bug-cve-2023-40068-exposes-1m-sites-to-xss-attacks/
#infosec #infosys #infosecurity

Hunter Search Engine

Internet Search Engines For Security Researchers

๐Ÿ™…Rejected๐Ÿ™…โ€โ™‚๏ธ CVE-2023-39848 Feel free to laugh out loud ๐Ÿคฃ๐Ÿคฃ๐Ÿคฃ, unless your instances are exposed ๐Ÿ‘€

๐Ÿงทhttps://hunter.how/list?searchValue=web.body%3D%22Damn%20Vulnerable%20Web%20Application%20%28DVWA%29%22

Dork ๐Ÿ‘‡๐Ÿ‘‡๐Ÿ‘‡
"Damn Vulnerable Web Application (DVWA)"

https://twitter.com/digininja/status/1692208663329484859
#infosec #infosys #BugBounty

Hunter Search Engine

Internet Search Engines For Security Researchers

๐ŸšจAlert๐Ÿšจ CVE-2023-26067 #Printer #Lexmark Command Injection
๐ŸŒป๐ŸŒป๐ŸŒป Credit to
@JamesHorseman2
and
@hacks_zach
. They just give their speech at #DEFCON

๐Ÿงทhttps://hunter.how/list?searchValue=product.name%3D%22Lexmark%20Printer%20Firmware%22

https://twitter.com/JamesHorseman2/status/1689739672334094339
#infosec #infosys #BugBounty

Hunter Search Engine

Internet Search Engines For Security Researchers

๐ŸšจAlert๐Ÿšจ ๐Ÿฉน#Microsoft Patch Tuesday๐Ÿ”จโš™๏ธ
Critical #RCE in Microsoft Message Queuing Services(#MSMQ)
CVE-2023-35385 CVE-2023-36911 CVE-2023-36910

๐Ÿงท https://hunter.how/list?searchValue=ip.port%3D%3D%221801%22%20and%20protocol%3D%3D%22msmq%22

๐Ÿ”– Refer to:
https://bleepingcomputer.com/news/microsoft/microsoft-august-2023-patch-tuesday-warns-of-2-zero-days-87-flaws/

๐ŸตA must-read on #MSMQ from
@fortinet

https://fortinet.com/blog/threat-research/microsoft-message-queuing-service-vulnerabilities

Hunter Search Engine

Internet Search Engines For Security Researchers

๐ŸšจAlert๐Ÿšจ CVE-2023-3718 #Aruba CX #Switches #RCE

๐Ÿงท https://hunter.how/list?searchValue=web.body%3D%22%2Fassets%2Freact-grid-layout.css%22

๐Ÿ‘‡๐Ÿป Other Dorks๐Ÿ‘‡๐Ÿป
FOFA: body="/assets/react-grid-layout.css"
Sodan http.html_hash:-799642671

โš™๏ธSecurity Advisoryโš™๏ธ
https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbnw04498en_us

#Infosys #infosec #infosecurity #cve

Hunter Search Engine

Internet Search Engines For Security Researchers

๐ŸšจAlert๐Ÿšจ CVE-2023-35078 #Ivanti(#MobileIron) zero-day was used to hack ๐Ÿ‡ณ๐Ÿ‡ด govt IT systems
๐Ÿ“Ž https://hunter.how/list?searchValue=protocol.banner%3D%22%2Fmics%2Fmics.html%22

Other Dorks
๐Ÿ“FOFA icon_hash="967636089"
๐Ÿ“Shodan http.favicon.hash:"967636089"

Refer to ๐Ÿ—’๏ธ:
https://bleepingcomputer.com/news/security/norway-says-ivanti-zero-day-was-used-to-hack-govt-it-systems/
#infosec #CyberSecurity #intelligence

Hunter Search Engine

Internet Search Engines For Security Researchers