Brut Security
14.8K subscribers
946 photos
75 videos
289 files
990 links
โœ…Queries: @wtf_brut
๐Ÿ›ƒWhatsApp: wa.link/brutsecurity
๐ŸˆดTraining: brutsec.com
๐Ÿ“จE-mail: [email protected]
Download Telegram
๐Ÿ”ฅMagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this saving the results obtained in an organized way in directories and with various formats.

โœ…
https://github.com/robotshell/magicRecon
๐Ÿ‘5
โšกGoogle Dorks - Cloud Storage: site:https://s3.amazonaws.com "target[.]com" site:https://blob.core.windows.net "target[.]com" site:https://googleapis.com "target[.]com" site:https://drive.google.com "target[.]com"

๐Ÿ‘‰Find buckets and sensitive data.
Combine:

site:
https://s3.amazonaws.com | site:https://blob.core.windows.net | site:https://googleapis.com | site:https://drive.google.com "target[.]com"

Add something to narrow the results: "confidentialโ€ โ€œprivileged" โ€œnot for public releaseโ€

โœ…Credit- Mike Takahashi
๐Ÿ”ฅ9๐Ÿ‘7
This media is not supported in your browser
VIEW IN TELEGRAM
OffSec Train ๐Ÿ˜‚๐Ÿ˜‚
1๐Ÿ—ฟ19๐Ÿ‘จโ€๐Ÿ’ป4๐Ÿณ2๐Ÿ”ฅ1
โšกEthical Hacking Study Guide - 2025
โœ…Download -
https://topmate.io/saumadip/1391531
๐Ÿ—ฟ4
Just Flexing, what everyone have :P
๐Ÿ”ฅ9๐Ÿ‘5
Brut Security
โšกEthical Hacking Study Guide - 2025 โœ…Download -https://topmate.io/saumadip/1391531
Sorry to close the free download for everyone, many spammers are trying to spam by random name, email and phone number. I have to add 1 INR / 0.012$ to avoid spam on my mail. Sorry for the inconvenience!
๐Ÿ—ฟ2
๐Ÿšจ Top 50 Google Dorks for Bug Bounty Hunters!
โค10
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ—ฟ8โค6๐Ÿ”ฅ3๐Ÿณ1
Scan for WordPress, Joomla, Drupal and Moodle bugs via CMSmap.
โค6๐Ÿ‘6
โšกEthical Hacking Study Guide - 2025
โœ…Download -https://topmate.io/saumadip/1391531
๐Ÿ‘1
Should I make a Bug Bounty study guide?
Do give โค๏ธ reaction to say yes.
โค131๐Ÿ‘9๐Ÿ—ฟ8๐Ÿณ1
โšกCVE-2024-50603: Aviatrix Controller Unauthenticated Command Injection
๐Ÿ‘‰
https://github.com/th3gokul/CVE-2024-50603/

โœ…Join Telegram-
https://t.iss.one/brutsecurity
โค9
โœจGitleaks: a tool to detect secrets like passwords, API keys, and tokens in git repositories and files.

โœ…https://t.co/BvaiYNWouP
๐Ÿ”ฅ11โค2๐Ÿ‘1
โญGhostscript - Multiple Vulnerabilities

โŒจ๏ธhttps://seclists.org/oss-sec/2018/q3/142

๐Ÿ”ตThese are critical and trivial remote code execution bugs in things like ImageMagick, Evince, GIMP, and most other PDF/PS tools.

๐ŸŒŸhttps://www.exploit-db.com/exploits/45243
Please open Telegram to view this post
VIEW IN TELEGRAM
โค1
CVE-2025-22777: Privilege Escalation in GiveWP WordPress Plugin, 9.8 rating ๐Ÿ”ฅ

Unauthenticated PHP Object Injection allows attackers to take control of websites.

Search at Netlas.io:
๐Ÿ‘‰ Link: https://nt.ls/amyWM
๐Ÿ‘‰ Dork: http.body:"plugins/give/assets/dist"

Read more: https://patchstack.com/articles/critical-vulnerability-patched-in-givewp-plugin/
๐Ÿ‘6
Expose localhost to the internet
https://t.co/ZEgxF561zN
๐Ÿ‘5
๐Ÿ—ฟ16โค2
โšก๏ธBug Bounty Helper
โœ…dorks.faisalahmed.me
โค11๐Ÿ”ฅ4๐Ÿ‘1๐Ÿค1
PoC collection of Atlassian(Jira, Confluence, Bitbucket) products and Jenkins, Solr, Nexus,etc

github.com/shadowsock5/Poc
โค6๐Ÿ‘3