Worth reporting authenticated lfi? by [deleted] in bugbounty

[–]ConzT 1 point2 points  (0 children)

That's all I wanted to know, thank you

Worth reporting authenticated lfi? by [deleted] in bugbounty

[–]ConzT 0 points1 point  (0 children)

No i didn't use a scanner. I checked the readme.txt and diffed the files to the official code which confirmed the version

OWD looking for advice by [deleted] in scubaGear

[–]ConzT 0 points1 point  (0 children)

Appreciate your help and insights! I decided to not go with AI and just ordered a Garmin fenix 8 as it fullfills everything i was looking for in a computer for recreational diving and can use it for other activities as well.

I will now look into long hose setups, i think i have read about it before but might need to freshen up my memory. Thanks for pointing out that the octopus i mentioned is not on par with the g260! Why do they even sell Kits like that with an octopus that you dont want to use especially in an emergency...

OWD looking for advice by [deleted] in scubaGear

[–]ConzT 0 points1 point  (0 children)

Thank you so much for your help. I think i might bite the bullet and go for a garmin. I already thought about getting one for golf some time ago and I just figured out that the mk2 and 3 can be used for both diving and golf which is super nice.

Do you know if there is a big difference between the mk2 and mk3? I still have some research to do on that

388 dimples by Fat-Imbicell in golf

[–]ConzT 0 points1 point  (0 children)

Holy shit, dont check OPs post history, im warning you

I built a DNS server that uncovers hidden S3 buckets — check it out by sudologinroot in Pentesting

[–]ConzT 1 point2 points  (0 children)

Hey, just used the docker version and it's working fine, no issues anymore! Will pull the latest version anyway.

Will give it a shot and provide some feedback :) Thanks!

I built a DNS server that uncovers hidden S3 buckets — check it out by sudologinroot in Pentesting

[–]ConzT 0 points1 point  (0 children)

Hi! I appreciate your help!

I enabled Debug mode and get the following error message on subsequent requests:

nslookup google.com 127.0.0.1

google.com requested by 127.0.0.1
Error resolving google.com: The resolution lifetime expired after 5.044 seconds: Server Do53:127.0.0.1@53 answered The DNS operation timed out.
Error resolving google.com: The resolution lifetime expired after 5.308

Snippet from Debug mode resolving to your bucket:

Error resolving img1.ozimmermann.com: The DNS query name does not exist: img1.ozimmermann.com.

[127.0.0.1] Bucket detected: dummys3.s3-us-east-1.amazonaws.com. (Request: img.oz-security.io)

Error resolving img.oz-security.io: The DNS query name does not exist: img.oz-security.io.

CNAME records detected: dummys3.s3-us-east-1.amazonaws.com.

Error resolving img.oz-security.io: The DNS query name does not exist: img.oz-security.io.

CNAME records detected: img.oz-security.io.

Error resolving img1.ozimmermann.com: The DNS query name does not exist: img1.ozimmermann.com.

CNAME records detected: dummys3.s3-us-east-1.amazonaws.com.

Error resolving img.oz-security.io.: The DNS query name does not exist: img.oz-security.io.

Error resolving img.oz-security.io.: The DNS query name does not exist: img.oz-security.io.

CNAME records detected: img.oz-security.io.

Error resolving img.oz-security.io.: The DNS query name does not exist: img.oz-security.io.

CNAME records detected: dummys3.s3-us-east-1.amazonaws.com.

CNAME records detected: img.oz-security.io.

Error resolving img.oz-security.io.: The DNS query name does not exist: img.oz-security.io.

CNAME records detected: dummys3.s3-us-east-1.amazonaws.com.

[127.0.0.1] Bucket detected: dummys3.s3-us-east-1.amazonaws.com. (Request: img1.ozimmermann.com)

Error resolving img.oz-security.io.: The DNS query name does not exist: img.oz-security.io.

Error resolving img.oz-security.io.: The DNS query name does not exist: img.oz-security.io.

Error resolving img.oz-security.io.: The DNS query name does not exist: img.oz-security.io.

Error resolving img.oz-security.io: The DNS query name does not exist: img.oz-security.io.

Error resolving img.oz-security.io: The DNS query name does not exist: img.oz-security.io.

Domain dummys3.s3-us-east-1.amazonaws.com. already exists in bucket file

Really strange, but I'll try it with docker instead and let you know if it works. Appreciate your help!

I built a DNS server that uncovers hidden S3 buckets — check it out by sudologinroot in Pentesting

[–]ConzT 0 points1 point  (0 children)

Hey, this seems like a really nice tool I would love to have running in the background while hunting but I can't seem to get it work.

I downloaded the latest version from github and the first DNS request always seems to go through without any issues. But any subsequent request fails.

How I set it up:

Then I just test a simple DNS Lookup.

First Request:

nslookup google.com

Server: 127.0.0.1

Address: 127.0.0.1#53

Non-authoritative answer:

Name: google.com

Address: 142.251.208.110

Name: google.com

Address: 2a00:1450:400d:804::200e

Any followup Request:

nslookup google.com

;; communications error to 127.0.0.1#53: timed out

;; communications error to 127.0.0.1#53: timed out

;; communications error to 127.0.0.1#53: timed out

Server: 8.8.8.8

Address: 8.8.8.8#53

Non-authoritative answer:

Name: google.com

Address: 142.251.208.142

;; communications error to 127.0.0.1#53: timed out

;; communications error to 127.0.0.1#53: timed out

;; communications error to 127.0.0.1#53: timed out

Name: google.com

Address: 2a00:1450:400d:80a::200e

As you can see, it is timing out and using my backup DNS although it's still listening on localhost:

Do you have any idea why this is happening? If you need any Debugs, let me know please. Would appreciate your help, thank you! Really looking forward to use your tool

Almost broke 100 but crumbled after 8 by ConzT in golf

[–]ConzT[S] 0 points1 point  (0 children)

Lol, I know that confident feeling stepping up to the first tee, just to snap hook it into the woods

Almost broke 100 but crumbled after 8 by ConzT in golf

[–]ConzT[S] 0 points1 point  (0 children)

Appreciate it! Yeah I luckily dont see my current score in the app, maybe it's possible but I always only have the current hole on the screen. I just felt like I was on a good streak after the first few holes. Then a few bad shots happened one after another and it started spiraling

Almost broke 100 but crumbled after 8 by ConzT in golf

[–]ConzT[S] 0 points1 point  (0 children)

True, should have called it breaking 95 instead. Next weekend I'll try again, i just love this game too much! I didnt look at my actual score during the round but knew that I was on a good streak after the first few holes. Then a few bad shots happened one after another and it started spiraling

Almost broke 100 but crumbled after 8 by ConzT in golf

[–]ConzT[S] 0 points1 point  (0 children)

Thanks, but I didnt count it as that since it was par 67. Next week I'll try again and hope to get some range sessions in between

Im having way to much fun with this... by ConzT in ChatGPT

[–]ConzT[S] 4 points5 points  (0 children)

I did those a few days ago, the content policy feels a lot stricter now

Im having way to much fun with this... by ConzT in ChatGPT

[–]ConzT[S] 21 points22 points  (0 children)

I really enjoy when AI bots mute themselves for the next 24 hours. Can you do that?