Resources

All official content published by AI SPERA is gathered in one place. From product updates to reports and case studies, you can explore it all here.

September 13, 2022

WordPress Vulnerability: Detecting Vulnerable WordPress Sites

This article explains how to find old versions of WordPress web servers that have not been patched for WordPress vulnerabilities and how to scan for vulnerabilities in webpages created with WordPress. What is WordPress Vulnerability? WordPress is a website creation and…

Blog
WordPress Vulnerability: Detecting Vulnerable WordPress Sites

September 8, 2022

How to Find Web Page Specific HTTP Status Code

HTTP status codes tell the client which actions were taken by the server with these requests. Some web pages expose the cause of the error along with the HTTP status code. And this could be a clue to a potential vulnerability that could be used in an attack. In this video, we…

Videos
How to Find Web Page Specific HTTP Status Code

September 6, 2022

Exposed Redis Commander: The Biggest Contributor to Database Leakage

Redis (Remote Dictionary Server) is a BSD license-based open-source project developed by Salvatore Sanfilippo in 2009 that queries data with Key through a Key-Value Store database. Since Redis is a memory-based DBMS, it operates at a faster speed than regular disk storage…

Blog
Exposed Redis Commander: The Biggest Contributor to Database Leakage

September 2, 2022

How to Search for Exposed MFP Admin Pages

MFPs, also known as Multifunction Printers, are printers that can scan and print documents, often while logging personal information on printer-specific admin pages. Given the nature of the documents they handle, any enterprising hacker can take advantage of this vulnerability.…

Videos
How to Search for Exposed MFP Admin Pages

August 30, 2022

Cloud Attack Surfaces: Detect Neglected AWS Assets

Plenty of vulnerable default welcome pages can be found on a cloud attack surface. Software engineers who understand AWS cloud characteristics or users who have encountered AWS’ default welcome pages can detect neglected systems in a default welcome page state using Open Source…

Blog
Cloud Attack Surfaces: Detect Neglected AWS Assets

August 26, 2022

A How to Guide on Identifying Instagram Phishing Scams

Instagram phishing problems are becoming an increasingly serious issue for all users of this social media, especially for business accounts. In this video, we cover how to use Criminal IP’s Domain Search to determine if the login page is real or a phishing scam. ▶️…

Videos
A How to Guide on Identifying Instagram Phishing Scams

August 25, 2022

[Criminal IP v1.2.5] 2022-08-25 Release Notes

An update to Criminal IP v1.2.5 has been released. Major changes include: [Criminal IP v1.2.5] Release Notes Release Date: 2022.08.25 06:00~08:00 AM (UTC) [New Change] Added phishing detection feature “Probability of Phishing URL” to Domain Search Results Summary Added a pop-up…

Release Note
[Criminal IP v1.2.5] 2022-08-25 Release Notes

August 25, 2022

Criminal IP ASM Integration Services now available on Logpresso

Criminal IP Attack Surface Management (ASM) is integrated into the SOAR (Security Orchestration, Automation, and Response) platform Logpresso. Criminal IP ASM can be executed on the Logpresso dashboard through the API provided by Criminal IP. So, IT assets exposed to the attack…

Notice
Criminal IP ASM Integration Services now available on Logpresso

August 24, 2022

Default welcome page exposure: A Significant Security Risk

Default welcome page exposure refers to default settings pages left neglected on the attack surface while the system is active. They are most commonly encountered at the beginning stages of installing and running systems, and are used to perform setup tasks. How Hackers Exploit…

Blog
Default welcome page exposure: A Significant Security Risk

August 18, 2022

How to Check for VPN IP Addresses on an OSINT Search Engine

VPN, an abbreviation for Virtual Private Network, is a data security tool that is widely and legally used in the majority of countries. However, VPNs can also be misused. Hackers often use VPNs to hide their web activity and attempt to track down possible vulnerabilities in…

Videos
How to Check for VPN IP Addresses on an OSINT Search Engine

August 18, 2022

Instagram Phishing Scam: a How to Guide on Identifying Malicious Links

Instagram phishing problems are becoming an increasingly serious issue for all users of this platform, especially for Instagram business accounts. This is because hackers are constantly ‘improving their game’ and their methods of deceiving unwitting users are growing…

Blog
Instagram Phishing Scam: a How to Guide on Identifying Malicious Links

August 16, 2022

Attack Surface Management: Monitoring Unknown Assets and Vulnerabilities

It is well-known that most companies utilize various network equipment, databases, applications, and domains and that these IT properties often operate under a myriad of IP addresses and ports. Hackers with malicious intent, with this knowledge, begin their methods of…

Blog
Attack Surface Management: Monitoring Unknown Assets and Vulnerabilities

Business Customer Reports

Experienced any inconvenience?

Let us know right away.

Contact US

Join AI SPERA

Be part of the AI SPERA journey.

Contact US