Brut Security
14.8K subscribers
946 photos
75 videos
289 files
990 links
βœ…Queries: @wtf_brut
πŸ›ƒWhatsApp: wa.link/brutsecurity
🈴Training: brutsec.com
πŸ“¨E-mail: [email protected]
Download Telegram
⚑Ethical Hacking Study Guide - 2025
βœ…Download -https://topmate.io/saumadip/1391531
πŸ‘1
Should I make a Bug Bounty study guide?
Do give ❀️ reaction to say yes.
❀131πŸ‘9πŸ—Ώ8🐳1
⚑CVE-2024-50603: Aviatrix Controller Unauthenticated Command Injection
πŸ‘‰
https://github.com/th3gokul/CVE-2024-50603/

βœ…Join Telegram-
https://t.iss.one/brutsecurity
❀9
✨Gitleaks: a tool to detect secrets like passwords, API keys, and tokens in git repositories and files.

βœ…https://t.co/BvaiYNWouP
πŸ”₯11❀2πŸ‘1
⭐Ghostscript - Multiple Vulnerabilities

⌨️https://seclists.org/oss-sec/2018/q3/142

πŸ”΅These are critical and trivial remote code execution bugs in things like ImageMagick, Evince, GIMP, and most other PDF/PS tools.

🌟https://www.exploit-db.com/exploits/45243
Please open Telegram to view this post
VIEW IN TELEGRAM
❀1
CVE-2025-22777: Privilege Escalation in GiveWP WordPress Plugin, 9.8 rating πŸ”₯

Unauthenticated PHP Object Injection allows attackers to take control of websites.

Search at Netlas.io:
πŸ‘‰ Link: https://nt.ls/amyWM
πŸ‘‰ Dork: http.body:"plugins/give/assets/dist"

Read more: https://patchstack.com/articles/critical-vulnerability-patched-in-givewp-plugin/
πŸ‘6
Expose localhost to the internet
https://t.co/ZEgxF561zN
πŸ‘5
πŸ—Ώ16❀2
⚑️Bug Bounty Helper
βœ…dorks.faisalahmed.me
❀11πŸ”₯4πŸ‘1🀝1
PoC collection of Atlassian(Jira, Confluence, Bitbucket) products and Jenkins, Solr, Nexus,etc

github.com/shadowsock5/Poc
❀6πŸ‘3
β˜„οΈ Exciting News for Aspiring Bug Hunters! β˜„οΈ

πŸ’₯ Enrollments are now open for Brut Ethical Hacking and Basic to Advanced Web Penetration Testing (Bug Bounty) courses, starting January 2025!

Course Highlights:
β€’ Comprehensive training on Business Logic, SQL Injection, and more.
β€’ 40 hours of live, online sessions.
β€’ Practical, hands-on exercises to master real-world vulnerabilities.
β€’ Pathway to becoming a skilled bug hunter and advancing your cybersecurity career.

πŸ—“Classes Begin: January 2025 (PAID COURSE)
πŸ“žContact: Whatsapp for details and enrollment.
🌐Visit: Brut Security
Please open Telegram to view this post
VIEW IN TELEGRAM
❀6πŸ‘1
Shodan Dork Generator

dorks.s1rn3tz.ovh/shodandorks
πŸ‘14πŸ”₯8
CVE-2025-21598: Out-of-bounds Read in Juniper Junos OS, 8.2 rating❗️

An out-of-bouds read vulnerability in the RDP daemon, fixed last week, could potentially lead to DoS.

Search at
Netlas.io:
πŸ‘‰ Link: https://nt.ls/HqWq2
πŸ‘‰ Dork: http.title:"Juniper"

Vendor's advisory: https://supportportal.juniper.net/s/article/2025-01-Security-Bulletin-Junos-OS-and-Junos-OS-Evolved-When-BGP-traceoptions-are-configured-receipt-of-malformed-BGP-packets-causes-RPD-to-crash-CVE-2025-21598
πŸ‘3
⚑️LazyXss - Cross site scriptiong Testing Automation Tool v1.2

βœ…Link: github.com/iamunixtz/LazyXss
❀12πŸ‘1
πŸ’» All About Bug Bounty - Updated!
πŸ”₯https://github.com/daffainfo/AllAboutBugBounty

#BugBounty #bugbountytips
1❀14πŸ‘4πŸ”₯2
CVE-2025-0066, -0070 and other: Multiple vulnarabilities in SAP, 2.2 - 9.9 rating πŸ”₯πŸ”₯πŸ”₯

Several vulnerabilities in SAP services for every taste and color: SQLi, Improper Authentication, DLL Hijacking, etc.

Search at Netlas.io:
πŸ‘‰ Link: https://nt.ls/zbP5e
πŸ‘‰ Dork: http.headers.server:"SAP"

Vendor's advisory: https://support.sap.com/en/my-support/knowledge-base/security-notes-news/january-2025.html
πŸ‘9
⚑️SHODAN DORK GENERATOR
🌟https://dorks.s1rn3tz.ovh/shodandorks
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯8πŸ‘2πŸ‘¨β€πŸ’»2
Exploiting Leaked Zoom Meeting Links via Wayback Machine.pdf
85.1 KB
πŸ’‘ Bug Bounty Tip: Exploiting Leaked Zoom Meeting Links via Wayback Machine
πŸ’° Credit: Shivam Kumar Singh
πŸ”₯13πŸ‘4πŸ—Ώ1