Brut Security
14.8K subscribers
927 photos
73 videos
287 files
982 links
βœ…Queries: @wtf_brut
πŸ›ƒWhatsApp: wa.link/brutsecurity
🈴Training: brutsec.com
πŸ“¨E-mail: [email protected]
Download Telegram
β˜„οΈIDOR Forge is an advanced and versatile tool designed to detect Insecure Direct Object Reference (IDOR) vulnerabilities in web applications.

πŸ›https://github.com/errorfiathck/IDOR-Forge
Please open Telegram to view this post
VIEW IN TELEGRAM
1πŸ”₯17❀6πŸ‘4πŸ‘¨β€πŸ’»2
Business Logic POC - Able To Unsubscribe User From Company
https://t.iss.one/brutsecurity_poc/16
❀11πŸ”₯5πŸ‘3
Drop Reactions β˜•οΈβ˜•οΈβ˜•οΈβ˜•οΈβ˜•οΈβ˜•οΈ
Please open Telegram to view this post
VIEW IN TELEGRAM
🫑16πŸ”₯10❀1🀨1πŸ‘¨β€πŸ’»1
πŸ””(Bug-Bounty) How to Know You are Ready for Full-Time Bug Bounty

βœ”οΈhttps://chintangurjar.com/posts/full-time-bug-bounty/
Please open Telegram to view this post
VIEW IN TELEGRAM
❀10🐳4πŸ‘1
Authentication Bypass: βš”οΈ
πŸ‘16πŸ”₯5
πŸ”–OTP Bypass Via Response Manipulation POC__ P3 - https://t.iss.one/brutsecurity_poc/17
Please open Telegram to view this post
VIEW IN TELEGRAM
Bystander: Passive Web Vulnerability Detection Tool

https://github.com/itsdivyanshjain/Bystander
πŸ‘13πŸ”₯3πŸ—Ώ2🐳1🀝1
⚑️⚑️⚑️⚑️Account takeover + OTP Bypass + no rate limit vulnerabilities on same functionality ---> https://t.iss.one/brutsecurity_poc/18
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘7❀5πŸ”₯2🀝2
Don't forget to Join the channel and Drop your Reactions!πŸ‘βœ¨
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘12πŸ”₯8
Brut Security pinned Β«Don't forget to Join the channel and Drop your Reactions!πŸ‘βœ¨Β»
πŸ•΅οΈβ€β™‚οΈ Offensive Google framework.
βœ…https://github.com/mxrch/GHunt
πŸ‘8πŸ”₯4
This media is not supported in your browser
VIEW IN TELEGRAM
Check out Hide Search Result, a tool that lets you filter out unwanted search results with ease πŸ”₯😎

βœ…
https://github.com/husseinphp/Hide-Search-Result
πŸ”₯8❀2πŸ‘2
Free Malware Analysis Course, covers malware concepts, malware analysis, and black-box reverse engineering techniquesπŸ–₯️

- class.malware.re
πŸ”₯28❀2πŸ‘2🐳2🀝1
If you enjoy the posts please don't forget to drop your reactions. It motivates me to post such contents.πŸ—ΏπŸ—ΏπŸ—Ώ
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯27🫑8πŸ‘2🐳2πŸ—Ώ2
πŸ”–2FA bugs setup/implementation, bypass and disable.

πŸ”— What is two-factor authentication?
🌐 Cloudflare
πŸ”— Multi-factor Authentication Labs:
🌐 Portswigger
πŸ”— 2FA/MFA/OTP Bypass:
🌐 Hacktricks
πŸ”— Testing 2 Factor Authentication:
πŸ“±Github
πŸ”— Account Takeover (2FA Bypasses):
πŸ“±Github
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯22❀4πŸ‘3
If you hate wasting time with 2FA, try this:

1. Install github.com/rsc/2fa on your computer/VPS & configure it with your 2FA sites.
2. Install Espanso, then add the config below.

Now, whenever you need an OTP, just type :otp and it’ll auto-fill. Easy and fast!

Credit- sw33tLie
❀14
HuntDB has been updated with:

- Full-text search for efficient exploration
- CVE-to-HackerOne mapping for enhanced vulnerability correlation
- More Data Points

--> : huntdb.com/hackerone
πŸ”₯10πŸ‘3
Time-Base SQL Injection

Payload: (select*from(select(sleep(15)))a)
#bugbountytips #BugBounty #sqli
πŸ‘27πŸ”₯9πŸ—Ώ2🀨1πŸ‘¨β€πŸ’»1
CyberSecurity RoadMAP.pdf
185.3 KB
Cybersecurity Roadmap
πŸ”₯21πŸ‘6❀2πŸ—Ώ2