Brut Security
14.7K subscribers
919 photos
73 videos
287 files
974 links
βœ…Queries: @wtf_brut
πŸ›ƒWhatsApp: wa.link/brutsecurity
🈴Training: brutsec.com
πŸ“¨E-mail: [email protected]
Download Telegram
CVE-2024-55573, -53923: SQLi in Centreon, 9.1 rating πŸ”₯

The vulnerabilities allow an attacker with high privileges to perform SQL injection into a form for uploading media.

Search at Netlas.io:
πŸ‘‰ Link: https://nt.ls/NETLB
πŸ‘‰ Dork: http.favicon.hash_sha256:795c0f8c1ff23b992d6ccb91df5e6488d4c259585da58b2e2f8eeee71147516a OR http.favicon.hash_sha256:c95e0dc8a2cc9a45d29c5381e62e48bde88f661408d4b811e72933fa7da32d4e

Vendor's advisory: https://thewatch.centreon.com/latest-security-bulletins-64/cve-2024-55573-centreon-web-critical-severity-4264
πŸ”₯6πŸ‘1🫑1
Fortinet FortiOS Authentication Bypass CVE-2024-55591

Query:
HUNTER:/product.name="Fortinet Firewall"
FOFA: product="FORTINET-Firewall"
SHODAN: instances running fortigate:
http.favicon.hash:945408572
ZoomEye Dork: app="Fortinet Firewall"

#BugBounty #CyberSecurity
πŸ‘9❀4πŸ”₯1
Extract all endpoints from a JS File and take your bug 🐞

βœ…Method one
waybackurls HOSTS | tac | sed "s#\\\/#\/#g" | egrep -o "src['\"]?
15*[=: 1\5*[ '\"]?[^'\"]+.js[^'|"> ]*" | awk -F '/'
'{if(length($2))print "https://"$2}' | sort -fu | xargs -I '%' sh
-c "curl -k -s \"%)" | sed \"s/[;}\)>]/\n/g\" | grep -Po \" (L'1|\"](https?: )?[/1{1,2}[^'||l"> 1{5,3)|(\.
(get|post|ajax|load)\s*\(\5*['||\"](https?:)?[/1{1,2}[^'||\"> ]
{5,})\"" | awk -F "['|"]" '{print $2}' sort -fu

βœ…Method two
cat JS.txt | grep -aop "(?<=(\"|\'|' ))\/[a-zA-Z0-9?&=\/-#.](?= (\"||'|'))" | sort -u | tee JS.txt

#infosec #cybersec #bugbountytips
πŸ‘11πŸ”₯3❀2
πŸ”₯HackTheBox themed linux box config and setup.
πŸ”—Config Repo-
https://github.com/shellvik/shvbox/
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯4πŸ‘2
πŸ”₯πŸ”₯πŸ”₯Physics Wallah Website OTP Bypass Vulnerability __ Bug Bounty POC ---> https://t.iss.one/brutsecurity_poc/22
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯4
drupal-dorkstxt.pdf
4.9 MB
πŸ”₯5πŸ‘2
Hacking IIS - NahamCon.pdf
1.6 MB
❀10πŸ”₯4πŸ‘1
iykyk πŸ˜‚πŸ˜‚πŸ˜‚πŸ˜‚
🀣32😁5😒5πŸ”₯4
Forwarded from Mr Rahim
This media is not supported in your browser
VIEW IN TELEGRAM
Tech industry Right now
🀣10😁1
πŸ”–Essential Browser Extensions for Bug Bounty Hunters

⬇️FireFox
πŸ” Link Gopher
πŸ” Adblock Plus
πŸ” FoxyProxy Standard
πŸ” Video Speed Controller
πŸ” Check XSS
πŸ” HackTools
πŸ” Bulk URL Opener
πŸ” Temp Mail
πŸ” JS Beautify CSS HTML
πŸ” Multi-Account Containers


⬇️Chrome
🌐
TruffleHog

🌐
Code Formatter

🌐
Freedium Extension

🌐
BuiltWith

🌐
Wappalyzer

🌐
WhatRuns

🌐
Retire.js

🌐
Cookie Extractor

🌐
Wayback Machine

🌐
EXIF Data Viwer

🌐
Shodan

🌐
S3 Bucket List

🌐
Ublock Origin

🌐
Resources Saver

🌐
Dot Git

🌐
EndPointer
Please open Telegram to view this post
VIEW IN TELEGRAM
🀝16πŸ”₯7❀4πŸ‘3
🀣25😁2❀1
This media is not supported in your browser
VIEW IN TELEGRAM
πŸ‘2
πŸ”₯Always remember to test the API for existence of addition headers.
X-Originaal-URL: /v1/api/endpoint_here

BOOM => Entire API routes disclosure.
Credit:
@driccosec
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯18❀5πŸ‘1
CVE-2025-22609, -22611, -22612: Multiple vulnerabilities in Coolify, 10.0 rating πŸ”₯πŸ”₯πŸ”₯

Three vulnerabilities of highest severity in Coolify allow for RCE, privilege escalation, and authentication bypass.

Search at Netlas.io:
πŸ‘‰ Link: https://nt.ls/vUWWf
πŸ‘‰ Dork: http.favicon.hash_sha256:eaf648b6000a49599ed58bda49e576d0f981e535a8075d524a4be890edcf96d0 AND uri:*login*

Vendor's advisory: https://github.com/coollabsio/coolify/security/advisories/GHSA-3w2c-jfr2-9pg9
😁10πŸ‘3
Where is the reactions πŸ–₯
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ—Ώ13πŸ™4🐳3πŸ‘2
πŸ’‘Snov finds email addresses on any website. #OSINT

snov.io/email-finder
πŸ‘10πŸ”₯6❀4🀨2
πŸ’‘Blackbird is a powerful OSINT tool designed for fast and efficient searches of user accounts by username or email across multiple platforms, streamlining digital investigations.

https://github.com/p1ngul1n0/blackbird
πŸ”₯10πŸ‘5🀝2