Advertisement
xGHOSTSECx

FIREYE.COM 0DAY SOLARWINDS I DID IT 4 MONTHS AGO

Jan 13th, 2021
930
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.97 KB | None | 0 0
  1. I know how they broke into ur site. I tried to send your team the patch 4 months ago I was met with hostility from ur very own RedTeam. I have already 0day'd ur company. Now I see ur info being ransomed for 50k. In case I kept the 0day reports as well as I planned on since the hostility I was gonna leak the Walkthru of the solarwinds attack. Anyways I seriously doubt ur company gives two shots about ur customer base as I found the dev portal where ur devs are talking and basically saying fuck the customers. Ur level 3 data breach is a serious one and could of been avoided had your team not been hostile with GhostSec.
  2.  
  3.  
  4. Location
  5. https://mil-betacloud.fireeye.com/
  6. Server
  7. BigIP. =. 0Day
  8. Connection
  9. Keep-Alive
  10.  
  11. https://console.us.fireeye.com/libs/misc/polyfill.js?build=2.0.0_342
  12.  
  13. Even ur logo is misconfigured.
  14.  
  15. https://sjc.training.fireeye.com/assets/FireEye-9dcedd1cad96eac352ae97a540e7686c72ed45569eece3351f5f94cd7ae5b921.png
  16.  
  17. https://ork.selabs.fireeye.com/
  18.  
  19. The sso is the weak point your sharing all your files and tools.
  20.  
  21. https://ork.selabs.fireeye.com/bootstrap/css/bootstrap.min.css
  22.  
  23. 1 CVE-2019-8331 79 XSS 2019-02-20 2019-06-11 4.3 None Remote Medium Not required None Partial None
  24. In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
  25. 2 CVE-2018-20677 79 XSS 2019-01-09 2019-06-11 4.3 None Remote Medium Not required None Partial None
  26. In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.
  27. 3 CVE-2018-20676 79 XSS 2019-01-09 2019-06-11 4.3 None Remote Medium Not required None Partial None
  28. In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.
  29. 4 CVE-2016-10735 79 XSS 2019-01-09 2019-06-11 4.3 None Remote Medium Not required None Partial None
  30. In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.
  31. Total number of vulnerabilities : 4
  32.  
  33.  
  34.  
  35.  
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement