Search the Community
Showing results for tags 'leak'.
-
DDWPasteRecon Pastesites are websites that allow users to share plain text through public posts called “pastes.” Once attackers compromise the external perimeter and gain access to the internal resources they release the part of data on the “paste” sites like pastebin or hastebin. As these hackers or malicious groups publish dumps on such sites other users can see sensitive information through paste sites. With various malicious groups now using these services as communication channels, temporary storage or sharing, and various other sources being used to trade POC code, I thought it would be a good idea to have an easy tool to help organisations Blue and Red Teams to have visibility into these sites via Google dorks. DDWPasteRecon tool will help you identify code leak, sensitive files, plaintext passwords, and password hashes. It also allows members of SOC & Blue Team to gain situational awareness of the organisation’s web exposure on the pastesites. It Utilises Google’s indexing of pastesites to gain targeted intelligence of the organisation. Blue & SOC teams can collect and analyse data from these indexed pastesites to better protect against unknown threats. [hide][Hidden Content]]
-
- 1
-
- ddwpasterecon:
- identify
- (and 8 more)
-
🐛 A multi threads web application source leak scanner. [hide][Hidden Content]]
-
- 4
-
- sourceleakhacker
- multi
-
(and 6 more)
Tagged with:
-
-
View File Amazon FBA Freedom Formula Course – Leak Includes a lot of information about businesses in general so i recommend you check it out even if u hate Amazon Worth: 400$ Size: 3.4GB Download: free for users PRIV8 Submitter dEEpEst Submitted 16/04/21 Category Libro Online Password ********
-
Oblivion Oblivion is a tool focused on real-time monitoring of new data leaks, notifying if the credentials of the user have been leak out. It’s possible to verify if any credential of the user has been leak out before. It has two modes: Oblivion Client: graphical mode. Oblivion Server: mode with API functionalities. NOTE: The Oblivion Client and the Oblivion Server are independents. 🌀 Features 💪 CVEs scan ☑️ Works with powerful APIs 🔗 Works too with Google Dorks 🔎 Checks your password in Word Lists 👀 Checks the last pastes in Pastebin 📄 Output to txt, docx, pdf, xlsx, json, html, xml, db 🔒 Output to encrypted files 📦 Sends result files to multiples Buckets S3 📁 Upload the result files to Google Drive 📡 Cab send result files by SSH (work with EC2) 📢 Notify by Telegram and e-mail 📌 Includes option to hide passwords for demonstrations 🕒 Works with scheduled scans 🔁 Possible to execute loop scans [hide][Hidden Content]]
-
Gitjacker downloads git repositories and extracts their contents from sites where the .git directory has been mistakenly uploaded. It will still manage to recover a significant portion of a repository even where directory listings are disabled. For educational/penetration testing use only. [hide][Hidden Content]]
-
- 1
-
- gitjacker:
- leak
-
(and 5 more)
Tagged with:
-
-
- 10
-
- blackhatprotools
- hidden
-
(and 2 more)
Tagged with:
-
SourceLeakHacker SourceLeakHacker is a multi-threads web directories scanner. Feature Arguments parser. Store scan result into csv file. Support for multiple urls (from file). Add help comments for every params. Update Usage. Adjust dictionary elements order systematically. Change logger in order to suite for both windows and linux. Add log level. Update Screenshots. [HIDE][Hidden Content]]
-
- 1
-
- sourceleakhacker:
- multi
-
(and 6 more)
Tagged with:
-
WebKit suffers from a user-agent shadow root leak in WebCore::ReplacementFragment::ReplacementFragment. View the full article
-
- webkit
- webcore::replacementfragment::replacementfragment
- (and 4 more)
-
Exploits LastPass Credential Leak From Previous Site
1337day-Exploits posted a topic in Updated Exploits
LastPass suffers from an issue where bypassing do_popupregister() leaks credentials from the previous site. View the full article-
- 3
-
- lastpass
- credential
- (and 4 more)
-
NSKeyedUnarchiver suffers from an information leak when decoding the SGBigUTF8String class using [SGBigUTF8String initWithCoder:]. This class initializes the string using [SGBigUTF8String initWithUTF8DataNullTerminated:] even though there is no guarantee the bytes provided to the decoder are null terminated. It should use [SGBigUTF8String initWithUTF8Data:] instead. View the full article
-
- nskeyedunarchiver
- sgbigutf8string
-
(and 3 more)
Tagged with:
-
This script abuses an unauthenticated information leak in the apcupsd daemon. View the full article
-
- leak
- information
-
(and 1 more)
Tagged with:
-
Spidermonkey IonMonkey can, during a bailout, leak an internal JS_OPTIMIZED_OUT magic value to the running script. This magic value can then be used to achieve memory corruption. View the full article
-
- spidermonkey
- ionmonkey
-
(and 3 more)
Tagged with:
-
Exploits Chrome ReadableStream Internal Object Leak
1337day-Exploits posted a topic in Updated Exploits
Chrome suffers from an internal object leak vulnerability in ReadableStream. View the full article-
- chrome
- readablestream
-
(and 3 more)
Tagged with:
-
KVM suffers from an uninitialized memory leak vulnerability in kvm_inject_page_fault. View the full article
-
- kvm
- kvm_inject_page_fault
-
(and 3 more)
Tagged with:
-
There is an reference leak in Microsoft VBScript that can be turned into an use-after-free given sufficient time. The vulnerability has been confirmed in Internet Explorer on various Windows versions with the latest patches applied. View the full article
-
ImageMagick versions prior to 7.0.8-9 suffers from a memory leak vulnerability. View the full article
-
- imagemagick
- memory
-
(and 1 more)
Tagged with:
-
The Linux kernel suffers from a ptr leak via BPF due to a broken subtraction check. View the full article