Brut Security
14.8K subscribers
920 photos
73 videos
287 files
976 links
βœ…Queries: @wtf_brut
πŸ›ƒWhatsApp: wa.link/brutsecurity
🈴Training: brutsec.com
πŸ“¨E-mail: [email protected]
Download Telegram
β˜„οΈ Exciting News for Aspiring Bug Hunters! β˜„οΈ

πŸ’₯ Enrollments are now open for Brut Ethical Hacking and Basic to Advanced Web Penetration Testing (Bug Bounty) courses, starting January 2025!

Get ready to dive deep into the world of ethical hacking and bug bounty hunting, guided by industry professionals. Whether you are a complete beginner or looking to advance your skills, this course is tailored for you.

Course Highlights:
β€’ Comprehensive training on Business Logic, SQL Injection, and more.
β€’ 40 hours of live, online sessions.
β€’ Practical, hands-on exercises to master real-world vulnerabilities.
β€’ Pathway to becoming a skilled bug hunter and advancing your cybersecurity career.

πŸ—“Classes Begin: January 2025 (PAID COURSE)
πŸ“žContact: Whatsapp for details and enrollment.
🌐Visit: Brut Security
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘3
Extract all endpoints from a JS File and take your bug 🐞

βœ…Method one
waybackurls HOSTS | tac | sed "s#\\\/#\/#g" | egrep -o "src['\"]?
15*[=: 1\5*[ '\"]?[^'\"]+.js[^'|"> ]*" | awk -F '/'
'{if(length($2))print "https://"$2}' | sort -fu | xargs -I '%' sh
-c "curl -k -s \"%)" | sed \"s/[;}\)>]/\n/g\" | grep -Po \" (L'1|\"](https?: )?[/1{1,2}[^'||l"> 1{5,3)|(\.
(get|post|ajax|load)\s*\(\5*['||\"](https?:)?[/1{1,2}[^'||\"> ]
{5,})\"" | awk -F "['|"]" '{print $2}' sort -fu

βœ…Method two
cat JS.txt | grep -aop "(?<=(\"|\'|' ))\/[a-zA-Z0-9?&=\/-#.](?= (\"||'|'))" | sort -u | tee JS.txt


#infosec #cybersec #bugbountytips
1πŸ‘32❀11πŸ”₯10🀨3🐳2
Don’t forget the reactions and stars!
They fuel my energy to post such contentsπŸ”‹βœ¨.
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘17
⚑️A list of companies that accept Responsible Disclosure

βœ…bug-bounties.as93.net

#bugbountytips #bugbounty
πŸ‘7🀨4❀1πŸ”₯1πŸ‘¨β€πŸ’»1
Using TLDFinder with the Netlas Module πŸ”

Check out our latest article, where we walk you through setting up ProjectDiscovery TLDFinder and using it alongside Netlas data for top-level domains and subdomains searching.

πŸ‘‰ Read now: https://netlas.io/blog/tldfinder_and_netlas/
πŸ‘5❀4
⚑️CVE-2024-50379/CVE-2024-56337 : Apache Tomcat Patches Critical RCE Vulnerability

πŸ”₯Exploit : https://github.com/SleepingBag945/CVE-2024-50379

πŸ‘‡Dorks:
HUNTER :/product.name="Apache Tomcat"
FOFA : product="Apache-Tomcat"
SHODAN : product:"Apache-Tomcat"
❀7πŸ‘2
πŸŽ„ Merry Christmas from Brut Security! πŸŽ…

Wishing you and your loved ones a season filled with joy, peace, and happiness. May this festive time bring warmth to your heart and cherished moments with your loved ones.

Thank you for being a part of our community!

Happy Holidays! πŸŽ‰
#MerryChristmas #Cybersecurity #BrutSecurity
1❀14πŸ‘2πŸ”₯2
⚑Broken Access Control to Mass Account Takeover.
πŸ”₯11❀2πŸ‘1
❀10
⚑️Tiny-XSS-Payloads - A collection of tiny XSS Payloads that can be used in different contexts.

βœ…tinyxss.terjanq.me

#xss #BugBounty #CyberSecurity
πŸ‘11
⚑You can use #httpx to request any path and see the status code and other details on the go, filter, or matcher flags if you want to be more specific.

βœ…httpx -path /swagger-api/ -status-code -content-length
πŸ‘16πŸ”₯6❀1
Fuxploider: a free tool for finding and exploiting flaws in file upload forms. It spots allowed file types and finds out the best way to upload malicious files onto a website.

https://t.co/uP1HxJIdpC
❀7πŸ‘4
Thanks Everyone To Grow Our Community So Big <3

#telemetrio2024 #brutsecurity
πŸ”₯7πŸ‘3❀2πŸ‘¨β€πŸ’»2🀝2🐳1
Using theHarvester with the Netlas Module πŸ”

In our latest article, we demonstrate how to leverage the theHarvester framework integrated with Netlas to efficiently discover subdomains.

πŸ‘‰ Read now: https://netlas.io/blog/theharvester_and_netlas/
❀5πŸ‘3
πŸ”– Free Tool for Finding Open S3 Buckets and Files

🎯 Purpose:Search for open Amazon S3 buckets and locate potentially interesting files efficiently.

βœ… Tool Links:
Explore Open S3 Buckets: https://buckets.grayhatwarfare.com

πŸ“Œ Why This is Useful:Helps identify misconfigured S3 buckets.
Uncover sensitive data or files accidentally exposed to the public.
❀10πŸ‘3πŸ”₯2
πŸŽ‰ Happy New Year, Brut Fam! πŸŽ‰

2024 was incredibleβ€”together, we shared 1,500+ resources and grew to an 8.5K+ community! Your support makes it all worthwhile.
πŸ’ͺ
If you’ve found value in this journey, you can support me with a β˜•:
https://buymeacoffee.com/brutsecurity

Wishing you a safe, successful, and prosperous 2025! Let’s make it even bigger and better! πŸš€
❀14πŸ”₯3🀝1
⚑️SqliSniper: Advanced Time-based Blind SQL Injection fuzzer for HTTP Headers

βœ…https://github.com/danialhalo/SqliSniper
πŸ‘8❀5
πŸ””Brut Practical Bug Bounty Training

❀Master Bug Bounty Hunting with Harsh D Ranjan
Learn from a proven bug hunter with extensive experience on platforms like Bugcrowd, HackerOne, and Immunefi.

⭐About the Trainer

Harsh D Ranjan is a recognized expert in bug bounty programs with verified profiles:
β€’ Bugcrowd
β€’ HackerOne
β€’ Immunefi

🌟Training Highlights
β€’ In-depth exploration of bug bounty methodologies
β€’ Practical guidance for platforms like Bugcrowd, HackerOne, and Immunefi
β€’ Real-world examples of impactful vulnerability reports
β€’ Hands-on practice to prepare you for live bug bounty programs

πŸ”΅Details

πŸ•’ Class Timings: Tuesday & Wednesday, 3:00–5:00 PM IST
πŸ“† Duration: 2–3 months
πŸ‘₯ Max Slots: 10 participants per batch
πŸ“ž DM on WhatsApp to Book Your Slot: https://wa.link/7j7p6g

🚫Why Enroll?
β€’ Direct mentorship from an experienced bug hunter
β€’ Small class size for personalized attention
β€’ Gain skills for earning through bug bounty programs

⚑Limited slots available! Sign up now to secure your spot.
Please open Telegram to view this post
VIEW IN TELEGRAM
1πŸ”₯5❀1πŸ‘1πŸ—Ώ1