Redhotcyber · @redhotcyber
537 followers · 1552 posts · Server mastodon.bida.im
sekurak News · @sekurakbot
30 followers · 232 posts · Server mastodon.com.pl

::ffff:127.0.0.1 – co to za dziwny adres IP? Ano taki, którym udało się zgarnąć od Cloudflare $7500 nagrody bug bounty

Opis na serwisie Hackerone jest dość enigmatyczny: By using IPv4-mapped IPv6 addresses there was a way to bypass Cloudflare server’s network protections and start connections to ports on the loopback (127.0.0.1) or internal IP addresses (such as 10.0.0.1) Cloudflare zdecydował się jednak przygotować nieco dłuższy opis podatności, która została zgłoszona...


sekurak.pl/ffff127-0-0-1-co-to

#wbiegu #cloudflare #ipv6 #ssrf

Last updated 2 years ago

sudoheader :verified: · @sudoheader
14 followers · 46 posts · Server infosec.exchange
Astra Kernel :verified: · @AstraKernel
904 followers · 972 posts · Server infosec.exchange

✨ SSRF bypass list:

-------
Base-Url: 127.0.0.1
Client-IP: 127.0.0.1
Http-Url: 127.0.0.1
Proxy-Host: 127.0.0.1
Proxy-Url: 127.0.0.1
Real-Ip: 127.0.0.1
Redirect: 127.0.0.1
Referer: 127.0.0.1
Referrer: 127.0.0.1
Refferer: 127.0.0.1
Request-Uri: 127.0.0.1
Uri: 127.0.0.1
Url: 127.0.0.1
X-Client-IP: 127.0.0.1
X-Custom-IP-Authorization: 127.0.0.1
X-Forward-For: 127.0.0.1
X-Forwarded-By: 127.0.0.1
X-Forwarded-For-Original: 127.0.0.1
X-Forwarded-For: 127.0.0.1
X-Forwarded-Host: 127.0.0.1
X-Forwarded-Port: 443
X-Forwarded-Port: 4443
X-Forwarded-Port: 80
X-Forwarded-Port: 8080
X-Forwarded-Port: 8443
X-Forwarded-Scheme: http
X-Forwarded-Scheme: https
X-Forwarded-Server: 127.0.0.1
X-Forwarded: 127.0.0.1
X-Forwarder-For: 127.0.0.1
X-Host: 127.0.0.1
X-Http-Destinationurl: 127.0.0.1
X-Http-Host-Override: 127.0.0.1
X-Original-Remote-Addr: 127.0.0.1
X-Original-Url: 127.0.0.1
X-Originating-IP: 127.0.0.1
X-Proxy-Url: 127.0.0.1
X-Real-Ip: 127.0.0.1
X-Remote-Addr: 127.0.0.1
X-Remote-IP: 127.0.0.1
X-Rewrite-Url: 127.0.0.1
X-True-IP: 127.0.0.1

-----

twitter.com/0dayCTF/status/155

Credit: @0dayCTF

#infosec #bugbounty #bugbountytips #redteam #pentesting #ssrf

Last updated 2 years ago

null - Open Security Community · @null0x00
146 followers · 246 posts · Server ioc.exchange

RT @Nullblr
2nd talk of the day : SSRF attacks by Srinivas
@OWASPBangalore @null0x00

#ssrf #infosec

Last updated 2 years ago

Needle and Thread · @doc_on_the_run
66 followers · 141 posts · Server med-mastodon.com

RT @CWISociety@twitter.com

@doc_on_the_run@twitter.com Your comment nailed exactly what is exciting and difficult about research. We have so much great work to do!

🐦🔗: twitter.com/CWISociety/status/

#ssrf #TeamWorkMakesTheDreamWork #chestwallinjury

Last updated 2 years ago

Nikahverse · @nikahverse
141 followers · 309 posts · Server infosec.exchange

Article: How Orca Found Server-Side Request Forgery (SSRF) Vulnerabilities in Four Different Azure Services

orca.security/resources/blog/s

#ssrf #cyber #cybersec #cybersecurity #infosec #infosecurity

Last updated 2 years ago

securityaffairs · @securityaffairs
341 followers · 222 posts · Server infosec.exchange
Astra Kernel :verified: · @AstraKernel
744 followers · 771 posts · Server infosec.exchange

AWS credential abuse, a quick walk through of a web app exploitable by that leads to stolen IAM role credentials.

While this isn’t the latest attack vector it’s still commonly seen in the wild (first hand exp). Being aware of such attacks is key to understanding artefacts you might see even from an EDR perspective.

A bonus to this, is the AWS CIRT labs that were released just before Christmas. While I’ve only been through one (SSRF) they are excellent resources for learning and responding to cloud level attacks (there are 5) aws.amazon.com/blogs/security/

- hope this helps with awareness of this technique (MITRE Unsecured Credentials: Cloud Instance Metadata API) and the impact this can have in your cloud environment. Here are my notes - enjoy;

sneakymonkey.net/cloud-credent

#iam #ssrf #dfir #cloud #aws

Last updated 2 years ago

Marco Ivaldi · @raptor
1495 followers · 611 posts · Server infosec.exchange
Johann · @wuzzi23
2 followers · 11 posts · Server cybervillains.com

IP addresses can be written as integers, e.g. 127.0.0.1 is 2130706433, or the EC2 metadata service is at 2852039166.

More examples:
m.youtube.com/shorts/st9FOr6pt

This can lead to blocklist bypasses + successful Server-Side Request Forgery.

#ssrf #bugbountytips

Last updated 2 years ago

Caitlin Condon · @catc0n
666 followers · 127 posts · Server infosec.exchange
Shielder · @Shielder
29 followers · 2 posts · Server infosec.exchange

🎁-time: Here you go two Cisco BroadWorks CommPilot Application Software vulnerabilities which our team ( @smaury @zi0Black @thezero ) found during an engagement for one of our customers.
CVE-2022-20951: Unauthenticated - shielder.com/advisories/cisco-
CVE-2022-20958: Authenticated - shielder.com/advisories/cisco-

#ssrf #rce

Last updated 2 years ago

Nikahverse · @nikahverse
0 followers · 7 posts · Server infosec.exchange

(Server Side Request Forgery) testing resources
github.com/cujanovic/SSRF-Test

#ssrf #hacking #infosec

Last updated 2 years ago

woFF · @woFF
62 followers · 78 posts · Server infosec.exchange

Finally got some time to play around on h1... Had to refresh my notes around some of the testing tools / infra and bumped into github.com/brannondorsey/whono . I always forget I have a domain + instance for it. IMHO it is absolutely great to quickly test against for .

#dnsrebinding #ssrf #bugbountytips

Last updated 2 years ago

wtfismyip :unverified: · @wtfismyip
40 followers · 23 posts · Server infosec.exchange

Need a quick and dirty way to serve up arbitrary IPv4 or IPv6 embedded IPv4 addresses to exploit an vuln? Check out aaaaize: gitlab.wtfismyip.com/wtfismyip

#ssrf

Last updated 2 years ago

Astra Kernel · @AstraKernel
18 followers · 36 posts · Server infosec.exchange

SSRF bypass by hunter Basavaraj banakar:

Using url shortener to bypass payload detection(i.e /etc/passwd)

#bugbounty #bugbountytips #ssrf #redteam #pentesting

Last updated 2 years ago

Astra Kernel · @AstraKernel
9 followers · 10 posts · Server infosec.exchange