Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
kyoung3412
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
kyoung3412
4y ago
Hackers can use those auomated scans to target security unpatched WordPress web servers. There are approximately 134 IP addresses of v4.8.2 applied websites that have not been vulnerability patched.
2.
▲
by
kyoung3412
4y ago
It is not necessary to know specific product names to find AWS assets on a cloud attack surface.
3.
▲
Show HN: How to find Access Key confidential data on AWS easily
(ifh.cc)
2 points
by
kyoung3412
4y ago
|
0 comments
4.
▲
by
kyoung3412
4y ago
Method to determining whether a login page is real or a phishing scam.
5.
▲
by
kyoung3412
4y ago
The 403 error denies access to clients regardless of their credentials and can act as an indication that the server contains sensitive information.
6.
▲
by
kyoung3412
4y ago
K-Pop Deepfake 19 Sites hidden by Cloudflare : Sneaky Criminals Hiding Real IP Address with Cloudflare
7.
▲
by
kyoung3412
4y ago
With a simple HTML meta description search, it was easy to find an SCADA server open to an external network. It's kind a seruious problem due to weak security.
8.
▲
by
kyoung3412
4y ago
There are many IP's with exposed credentials, many of which are of either Oauth or RESTfull API. A regular check-up with developers need to be conducted. One little mistake such as set up errors can lead to credential leakage, causing
9.
▲
by
kyoung3412
4y ago
Perhaps the collab tools are one of the most important servers that must be managed appropriately. But there are so many exposed, opened colla tools without any authentication process. https://blog.criminalip.io/2022/07
10.
▲
by
kyoung3412
4y ago
Should be ware of exposed, vulnerable open source automation CI & CD server like Jenkins or RunDeck. One vulnerable open source CI & CD server leads to major cybersecurity flaws where attackers grasp hundreds of servers in their han
11.
▲
by
kyoung3412
4y ago
Jenkins is one of the most famous Continuous Integration tools and an integral part of DevOps that is often used to integrate various DevOps stages. Recently, Jenkins securiy team disclosed tens of flaws affecting 29 plugins for the Jenkis
12.
▲
by
kyoung3412
4y ago
Redis commander is a node.js web application used to view, edit, and manage a Redis Database. Let's make authentication a life
13.
▲
by
kyoung3412
4y ago
a methodology for detecting exposed open source products such as nginx, apache, microsoft-iis and lighttpd
14.
▲
by
kyoung3412
4y ago
Mincraft Server port: "25565" Even after the log4j disaster, security of minecraft seems weak.. just searched by open source intelligence(criminalip.io) there were over 50 vulnerable mincraft servers, It seems possible to penetrat
15.
▲
by
kyoung3412
4y ago
patch has been released couple of days ago. But by scanning the net, there were still lots of servers that were not patched yet
16.
▲
by
kyoung3412
4y ago
exact
17.
▲
Zero-Day Vulnerability in Atlassian Confluence
17 points
by
kyoung3412
4y ago
|
6 comments
18.
▲
by
kyoung3412
4y ago
CVE-2021-3393 is one of the postgresql vulnerability. This is vulnerability of information leak. As a matter of fact, using internally vulnerable apps may not be a big problem. However, This IP open 5432 port outside. These IPs are at risk
19.
▲
Show HN: Search for Remote Management Systems Exposed to Attack Surface
(blog.criminalip.io)
3 points
by
kyoung3412
4y ago
|
0 comments
20.
▲
by
kyoung3412
4y ago
Search for information about IP addresses, domains, malicious links, phishing sites and more
21.
▲
Show HN: Search Query, How to Find Exposed HFS HTTP File Server
(blog.criminalip.io)
2 points
by
kyoung3412
4y ago
|
1 comments
22.
▲
Show HN: Detection of vulns within dev tools such as Docker and Kubernetes
(blog.criminalip.io)
1 points
by
kyoung3412
4y ago
|
0 comments
23.
▲
Show HN: Analysis report on Certification expiration status of Russian sites
(blog.criminalip.io)
1 points
by
kyoung3412
4y ago
|
1 comments