Brut Security
14.8K subscribers
945 photos
75 videos
289 files
990 links
βœ…Queries: @wtf_brut
πŸ›ƒWhatsApp: wa.link/brutsecurity
🈴Training: brutsec.com
πŸ“¨E-mail: [email protected]
Download Telegram
CVE-2024-12365: Missing Authorization in W3 Total Cache WordPress Plugin, 8.5 rating❗️

The vulnerability allows an authenticated attacker to access sensitive data and make unauthorized web requests to collect information from internal services.

Search at Netlas.io:
πŸ‘‰ Link: https://nt.ls/BpOAJ
πŸ‘‰ Dork: http.body:"plugins/w3-total-cache"

Read more: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/w3-total-cache/w3-total-cache-281-authenticated-subscriber-missing-authorization-to-server-side-request-forgery
πŸ‘6πŸ”₯1
πŸ‘13🫑7🐳6πŸ—Ώ6
βœ…Add to the wordlist, and you may get juicy data.
/app_dev.php/_profiler/open?file=app/config/parameters.yml


Credit- Unknown
Please open Telegram to view this post
VIEW IN TELEGRAM
❀16πŸ‘4
⚑️How to find leaks and FUZZ all Endpoints.
🎯Use this Wordlist: https://github.com/Bo0oM/fuzz.txt/blob/master/fuzz.txt

βœ… Credit- H4x0r_fr34k
Please open Telegram to view this post
VIEW IN TELEGRAM
❀10πŸ”₯5πŸ‘3
JWT Token Pentesting.pdf
141.5 KB
πŸ‘18πŸ”₯5❀3
Brut Security pinned Β«Where is the reaction guys? It's a good way to support the channel, so please do leave your reaction to grow this community. Thanks!Β»
Get the hash of favicon of website (by url or file) and search it in Shodan, Censys and Virustotal.

favihash.com
πŸ‘7
Load Balancing, clearly explained !!!
πŸ‘9❀3
Android Pentest Checklist.xlsx
28.1 KB
1❀11πŸ”₯10πŸ‘1