A vulnerability was found on Nokia's website using Google Dorks
27. 09. 2022 Tuesday / By: Robert Denes / The key / Exact time: BST / Print this page
R ead this article by Jenish Panshal, in this short article he explains the SSL misconfiguration vulnerability and vulnerability using a simple Google Dork on the Nokia and Cambridge University websites.
Misconfiguration of SSL allows a man-in-the-middle attack to be launched by impersonating a web server as long as the client agrees to use SSL 3.0 encryption for the connection. The attacker then obtains the desired information using automated tools that modify the padding blocks and wait for the server to respond.
Bug Bounty is a program implemented by the owner of a website (web application) to involve third-party information security experts in the search for vulnerabilities. When participating in the Bug Bounty Program, you must act ethically and abide by the established rules. Remember that unauthorized hacking is illegal and a crime. Neither the editors of spy-soft.net nor the author are responsible for your actions. Google Dork Queries is a set of search queries for finding the worst security vulnerabilities. Anything that isn't properly hidden from search engines.
For brevity, such requests are referred to as Google Dorks or simply Dorks, such as administrators whose resources have been hacked using GDQ. Learn more about Google Dorks and use cases in the What is Google Dorks article.
Via Link
KIANEWS 

