Brut Security
14.8K subscribers
920 photos
73 videos
287 files
976 links
βœ…Queries: @wtf_brut
πŸ›ƒWhatsApp: wa.link/brutsecurity
🈴Training: brutsec.com
πŸ“¨E-mail: [email protected]
Download Telegram
Extract all endpoints from a JS File and take your bug 🐞

βœ…Method one
waybackurls HOSTS | tac | sed "s#\\\/#\/#g" | egrep -o "src['\"]?
15*[=: 1\5*[ '\"]?[^'\"]+.js[^'|"> ]*" | awk -F '/'
'{if(length($2))print "https://"$2}' | sort -fu | xargs -I '%' sh
-c "curl -k -s \"%)" | sed \"s/[;}\)>]/\n/g\" | grep -Po \" (L'1|\"](https?: )?[/1{1,2}[^'||l"> 1{5,3)|(\.
(get|post|ajax|load)\s*\(\5*['||\"](https?:)?[/1{1,2}[^'||\"> ]
{5,})\"" | awk -F "['|"]" '{print $2}' sort -fu

βœ…Method two
cat JS.txt | grep -aop "(?<=(\"|\'|' ))\/[a-zA-Z0-9?&=\/-#.](?= (\"||'|'))" | sort -u | tee JS.txt


#infosec #cybersec #bugbountytips
1πŸ‘32❀11πŸ”₯10🀨3🐳2
Don’t forget the reactions and stars!
They fuel my energy to post such contentsπŸ”‹βœ¨.
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘17
⚑️A list of companies that accept Responsible Disclosure

βœ…bug-bounties.as93.net

#bugbountytips #bugbounty
πŸ‘7🀨4❀1πŸ”₯1πŸ‘¨β€πŸ’»1
Using TLDFinder with the Netlas Module πŸ”

Check out our latest article, where we walk you through setting up ProjectDiscovery TLDFinder and using it alongside Netlas data for top-level domains and subdomains searching.

πŸ‘‰ Read now: https://netlas.io/blog/tldfinder_and_netlas/
πŸ‘5❀4
⚑️CVE-2024-50379/CVE-2024-56337 : Apache Tomcat Patches Critical RCE Vulnerability

πŸ”₯Exploit : https://github.com/SleepingBag945/CVE-2024-50379

πŸ‘‡Dorks:
HUNTER :/product.name="Apache Tomcat"
FOFA : product="Apache-Tomcat"
SHODAN : product:"Apache-Tomcat"
❀7πŸ‘2
πŸŽ„ Merry Christmas from Brut Security! πŸŽ…

Wishing you and your loved ones a season filled with joy, peace, and happiness. May this festive time bring warmth to your heart and cherished moments with your loved ones.

Thank you for being a part of our community!

Happy Holidays! πŸŽ‰
#MerryChristmas #Cybersecurity #BrutSecurity
1❀14πŸ‘2πŸ”₯2
⚑Broken Access Control to Mass Account Takeover.
πŸ”₯11❀2πŸ‘1
❀10
⚑️Tiny-XSS-Payloads - A collection of tiny XSS Payloads that can be used in different contexts.

βœ…tinyxss.terjanq.me

#xss #BugBounty #CyberSecurity
πŸ‘11
⚑You can use #httpx to request any path and see the status code and other details on the go, filter, or matcher flags if you want to be more specific.

βœ…httpx -path /swagger-api/ -status-code -content-length
πŸ‘16πŸ”₯6❀1
Fuxploider: a free tool for finding and exploiting flaws in file upload forms. It spots allowed file types and finds out the best way to upload malicious files onto a website.

https://t.co/uP1HxJIdpC
❀7πŸ‘4
Thanks Everyone To Grow Our Community So Big <3

#telemetrio2024 #brutsecurity
πŸ”₯7πŸ‘3❀2πŸ‘¨β€πŸ’»2🀝2🐳1
Using theHarvester with the Netlas Module πŸ”

In our latest article, we demonstrate how to leverage the theHarvester framework integrated with Netlas to efficiently discover subdomains.

πŸ‘‰ Read now: https://netlas.io/blog/theharvester_and_netlas/
❀5πŸ‘3
πŸ”– Free Tool for Finding Open S3 Buckets and Files

🎯 Purpose:Search for open Amazon S3 buckets and locate potentially interesting files efficiently.

βœ… Tool Links:
Explore Open S3 Buckets: https://buckets.grayhatwarfare.com

πŸ“Œ Why This is Useful:Helps identify misconfigured S3 buckets.
Uncover sensitive data or files accidentally exposed to the public.
❀10πŸ‘3πŸ”₯2
πŸŽ‰ Happy New Year, Brut Fam! πŸŽ‰

2024 was incredibleβ€”together, we shared 1,500+ resources and grew to an 8.5K+ community! Your support makes it all worthwhile.
πŸ’ͺ
If you’ve found value in this journey, you can support me with a β˜•:
https://buymeacoffee.com/brutsecurity

Wishing you a safe, successful, and prosperous 2025! Let’s make it even bigger and better! πŸš€
❀14πŸ”₯3🀝1
⚑️SqliSniper: Advanced Time-based Blind SQL Injection fuzzer for HTTP Headers

βœ…https://github.com/danialhalo/SqliSniper
πŸ‘8❀5
πŸ””Brut Practical Bug Bounty Training

❀Master Bug Bounty Hunting with Harsh D Ranjan
Learn from a proven bug hunter with extensive experience on platforms like Bugcrowd, HackerOne, and Immunefi.

⭐About the Trainer

Harsh D Ranjan is a recognized expert in bug bounty programs with verified profiles:
β€’ Bugcrowd
β€’ HackerOne
β€’ Immunefi

🌟Training Highlights
β€’ In-depth exploration of bug bounty methodologies
β€’ Practical guidance for platforms like Bugcrowd, HackerOne, and Immunefi
β€’ Real-world examples of impactful vulnerability reports
β€’ Hands-on practice to prepare you for live bug bounty programs

πŸ”΅Details

πŸ•’ Class Timings: Tuesday & Wednesday, 3:00–5:00 PM IST
πŸ“† Duration: 2–3 months
πŸ‘₯ Max Slots: 10 participants per batch
πŸ“ž DM on WhatsApp to Book Your Slot: https://wa.link/7j7p6g

🚫Why Enroll?
β€’ Direct mentorship from an experienced bug hunter
β€’ Small class size for personalized attention
β€’ Gain skills for earning through bug bounty programs

⚑Limited slots available! Sign up now to secure your spot.
Please open Telegram to view this post
VIEW IN TELEGRAM
1πŸ”₯5❀1πŸ‘1πŸ—Ώ1