Tiniest blog
Osint to PWN
[X] Cassandra exposed databases auth-free
[X] LDAP anonymous binding allowed
[X] SQLite Web dashboards with no login
[X] Jenkins misconfig leads to RCE
[X] Firebase hardcoded DB URL
[X] Vinchin MySQL default credentials
[X] There are many public S3 buckets
[X] Thousands of misconfigured Elasticsearch instances
[X] Find exposed discord webhooks
[X] Find vulnerable admin login panels
[X] Android Debug Bridge misconfiguration
[X] Find FTP servers with anonymous login allowed
[X] Access SMB servers auth-free
[X] Hunt exposed Files with Directory Listing
[X] Many exposed MongoDBs
[X] Explore AXIS open IP Cameras on Google
[X] ALGO IP Speakers & more with hardcoded passwords
[X] SIMATIC HMI default credentials
[X] Find exposed files on Rsync
[X] Find open Redis istances
[X] BigAnt admin hardcoded credentials
Misc & tools
About Me