Brut Security
14.7K subscribers
919 photos
73 videos
287 files
974 links
โœ…Queries: @wtf_brut
๐Ÿ›ƒWhatsApp: wa.link/brutsecurity
๐ŸˆดTraining: brutsec.com
๐Ÿ“จE-mail: [email protected]
Download Telegram
CyberWarFare Labs is offering 90% OFF for some of its certifications, perfect especially for those looking for their first certification or to improve your skills. I highly recommend it, especially if you want an affordable option for certifications.

#NotAPaidPromotion
๐Ÿ‘4
๐Ÿ˜น๐Ÿ˜น๐Ÿ˜น
๐Ÿณ8๐Ÿ—ฟ4๐Ÿ‘3โค1
๐Ÿ”–The 4M #Methodology for Choosing the Right Bug Bounty Programs to #Hunt On: [Cross-Applying Finance to Bug Bounties]

๐Ÿ“ฑ Notion: ๐Ÿ”—Link
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘4
๐Ÿณ4๐Ÿ‘2
CVE-2024-11667: Directory Traversal in Zyxel Firewalls, 7.3 ratingโ—๏ธ

A vulnerability in the web interface of some firewalls allows an attacker to download or upload files using a special URL.

Search at Netlas.io:
๐Ÿ‘‰ Link: https://nt.ls/agozE
๐Ÿ‘‰ Dork: http.favicon.hash_sha256:9a02f3cf948f9409c25070f2f057b69dda5d0aaf7fa8d056552e8bda8295ca1f

Vendor's advisory: https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-protecting-against-recent-firewall-threats-11-27-2024
๐Ÿ‘9โค1๐Ÿ—ฟ1
โ˜„๏ธURL scrapper from AlienVault

โšก๏ธThe script utilizes the AlienVault OTX API to query URLs linked to the specified domain and saves the results in a structured format for further analysis.

๐Ÿ”— https://github.com/Suryesh/OTX_AlienVault_URL
Please open Telegram to view this post
VIEW IN TELEGRAM
1๐Ÿ‘3๐Ÿ”ฅ2โค1
This media is not supported in your browser
VIEW IN TELEGRAM
โ€œItโ€™s the 1st of December Again!โ€

Another year is slipping by, but guess what? Thereโ€™s still a whole month left to make it count. For all the bug hunters out there, this is your sign to look back and appreciate how far youโ€™ve comeโ€”and to push even harder.

Remember that first bounty? That late-night rush when you cracked a tough challenge? The time you got that โ€œValid Vulnerabilityโ€ email that made the sleepless nights worth it?

Bug bounty is a journey. Itโ€™s a grind, a game of patience, persistence, and passion. Itโ€™s about falling in love with the processโ€”of learning, breaking, fixing, and growing.

If youโ€™re stuck or frustrated, donโ€™t let it define you. Learn from your misses, keep reading, practicing, and hunting. The next breakthrough might be just a scan, payload, or overlooked endpoint away.

December is the perfect month to reflect and refocus. Write those reports, finish that pending recon, or master a new skill. Close the year knowing you gave it your all.

Letโ€™s finish this year strong, hunters. The worldโ€™s full of bugs waiting to be squashedโ€”and the next one could be yours.

โœˆ๏ธBrutSecurity
#KeepHunting #BugBountyLife #1stDecemberMomentum
2๐Ÿ‘14โค5๐Ÿ—ฟ3
Exploit AWS metadata & user data access in Bug Bounty & CTF challenges!

๐Ÿ”— https://github.com/Lu3ky13/Unauthorized-Access-to-Metadata-and-User-Data-like-CTF

#BugBounty #bugbountytip
๐Ÿ‘9
๐Ÿ”–Ex-param - an automated tool designed for finding reflected parameters for XSS vulnerabilities

โœ…
https://github.com/rootDR/ex-param
โค7๐Ÿ‘3๐Ÿ—ฟ1
JavaScript for Hackers.pdf
987.7 KB
JavaScript for Hackers by JOAS ANTONIO
๐Ÿ‘6โค2
This media is not supported in your browser
VIEW IN TELEGRAM
โ˜„๏ธParamScan is a simple Chrome extension for web security enthusiasts and pen testers. It helps you find URL parameters in a webpage's source code and check if any of them are reflected on the page. This is super useful for spotting potential XSS vulnerabilities and other security issues.

๐Ÿ”–https://github.com/ch1y0w0/ParamScan
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ14๐Ÿ‘6โค5๐Ÿคจ1
โ˜„๏ธURLFinder is a high-speed, passive URL discovery tool designed to simplify and accelerate web asset discovery, ideal for penetration testers, security researchers, and developers looking to gather URLs without active scanning.

โšก๏ธhttps://github.com/projectdiscovery/urlfinder
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘12๐Ÿ”ฅ4๐Ÿณ2
โ˜„๏ธ TLDFinder - A focused tool designed for discovering private TLDs, making it an essential resource for security researchers. Simplify your exploration with precision and efficiency!

โš ๏ธhttps://github.com/projectdiscovery/tldfinder
Please open Telegram to view this post
VIEW IN TELEGRAM
โค6๐Ÿ”ฅ4๐Ÿ‘1
๐Ÿ”Morpheus IOC Scanner - A powerful tool for detecting and analyzing suspicious files, including ransomware and Indicators of Compromise (IOCs). With custom-built rules and advanced integrations, it offers detailed insights to identify sophisticated threats and bolster your defense against cyber risks.

๐Ÿ”—https://github.com/phantom0004/morpheus_IOC_scanner
๐Ÿ‘20๐Ÿ”ฅ5
Do give reaction on the post guys, it helped me to stay motivated and to post content like this.๐Ÿฅธ
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘41โค5๐Ÿ”ฅ2
CVE-2024-8672: Code Injection in Widget Options WordPress Plugin, 9.9 rating ๐Ÿ”ฅ

The vulnerability allows an attacker to enter data that is transmitted without proper filtering. This could potentially lead to remote code execution.

Search at Netlas.io:
๐Ÿ‘‰ Link: https://nt.ls/xOEZp
๐Ÿ‘‰ Dork: http.body:"plugins/widget-options"

Read more: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/widget-options/widget-options-the-1-wordpress-widget-block-control-plugin-407-authenticated-contributor-remote-code-execution
โค5๐Ÿ‘5
๐Ÿ’–๐Ÿฆ„ FAVICORN - A versatile tool to search websites using favicons!

๐Ÿ”How it works:
Simply input a favicon, and Favicorn fetches search result links across 10+ platforms, making it a handy tool for researchers and testers alike.

๐Ÿ”—
https://github.com/sharsil/favicorn
๐Ÿ‘14โค1
https://x.com/wtf_brut/status/1863893133379150234
Do Follow Me On
๐Ÿฃ
Have Shared Almost 2000+ Bug Bounty Tips.
๐Ÿ˜ฑ๐Ÿ‡ท๐Ÿ‡บ๐Ÿ‡บ๐Ÿ‡ธ
Please open Telegram to view this post
VIEW IN TELEGRAM