On 5 Jun 2020, at 11:24, Jukka Pakkanen <jukka.pakkanen@qnet.fi> =wrote:
=20too.
Complete scam, ignore.
=20
Just check the =E2=80=9Csecurityfocus=E2=80=9D link, it=E2=80=99s fake =
=20<bind-users-bounces@lists.isc.org> Puolesta Ejaz Ahmed
Jukka
=20
L=C3=A4hett=C3=A4j=C3=A4: bind-users =
L=C3=A4hetetty: 5. kes=C3=A4kuuta 2020 10:55vulnerable with below information is this true
Vastaanottaja: bind-users@lists.isc.org
Aihe: Fwd: DNS Misconfiguration on- http://cyberia.net.sa/
=20
=20
=20
=20
Some one is is claiming that our name server 212.118.64.2 is =
=20vulnerability on your website that is DNS Misconfiguration .
Any suggestions would be appreciated
=20
Thanks a n advance
=20
Ejaz
=20
=20
=20
=20
Dear CYBERIA GROUP Security Team ,
=20
I Rahul a Ethical Hacker and Security Researcher. I found a =
=20lead to "Same- Site" Scripting. I can also ping the localhost network.
Your localhost.cyberia.net.sa has address 127.0.0.1 and this may =
=20http://www.securityfocus.com/archive/1/486606/30/0/threaded
=20
Here is detailed description of this minor security issue : =
=20Appreciation letter for my work and effort which I have given for
Find attached POC Video.
=20
Dear Team Waiting for your response and I want bounty(money) with an =
=20unsubscribe from this list
=20
Thanks in advance
Ejaz
=20
=20
=20
=20
_______________________________________________
Please visit https://lists.isc.org/mailman/listinfo/bind-users to =
=20subscriptions. Contact us at https://www.isc.org/contact/ for more = information.
ISC funds the development of this software with paid support =
=20
=20
bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users
The localhost.<foo> is not scam, but the--
„I found this on HackerOne and I now want money“ is scam.
Remove the localhost entry from the zone, but you should not pay money
for issues that can be produced by automated scanners.
HackerOne is doing everyone disfavor by paying nonsensical amounts of money[*] for small issues like this. They (and other wealthy companies) should be paying money only for original security research and not this nonsense.
* $100 is a helluva money in some economies...
Ondrej
--
Ondřej Surý
ondrej@isc.org
Thx for the info, had missed this one and actually we have that minor misconfiguration too. Have had since 1995 when started our nameservers and never noticed…If it makes you feel better, it wasn't an error in 1995.
Sysop: | DaiTengu |
---|---|
Location: | Appleton, WI |
Users: | 991 |
Nodes: | 10 (0 / 10) |
Uptime: | 81:41:08 |
Calls: | 12,949 |
Calls today: | 3 |
Files: | 186,574 |
Messages: | 3,264,673 |