Brut Security
14.8K subscribers
919 photos
73 videos
287 files
974 links
βœ…Queries: @wtf_brut
πŸ›ƒWhatsApp: wa.link/brutsecurity
🈴Training: brutsec.com
πŸ“¨E-mail: [email protected]
Download Telegram
drupal-dorkstxt.pdf
4.9 MB
πŸ”₯5πŸ‘2
Hacking IIS - NahamCon.pdf
1.6 MB
❀10πŸ”₯4πŸ‘1
iykyk πŸ˜‚πŸ˜‚πŸ˜‚πŸ˜‚
🀣32😁5😒5πŸ”₯4
Forwarded from Mr Rahim
This media is not supported in your browser
VIEW IN TELEGRAM
Tech industry Right now
🀣10😁1
πŸ”–Essential Browser Extensions for Bug Bounty Hunters

⬇️FireFox
πŸ” Link Gopher
πŸ” Adblock Plus
πŸ” FoxyProxy Standard
πŸ” Video Speed Controller
πŸ” Check XSS
πŸ” HackTools
πŸ” Bulk URL Opener
πŸ” Temp Mail
πŸ” JS Beautify CSS HTML
πŸ” Multi-Account Containers


⬇️Chrome
🌐
TruffleHog

🌐
Code Formatter

🌐
Freedium Extension

🌐
BuiltWith

🌐
Wappalyzer

🌐
WhatRuns

🌐
Retire.js

🌐
Cookie Extractor

🌐
Wayback Machine

🌐
EXIF Data Viwer

🌐
Shodan

🌐
S3 Bucket List

🌐
Ublock Origin

🌐
Resources Saver

🌐
Dot Git

🌐
EndPointer
Please open Telegram to view this post
VIEW IN TELEGRAM
🀝16πŸ”₯7❀4πŸ‘3
🀣25😁2❀1
This media is not supported in your browser
VIEW IN TELEGRAM
πŸ‘2
πŸ”₯Always remember to test the API for existence of addition headers.
X-Originaal-URL: /v1/api/endpoint_here

BOOM => Entire API routes disclosure.
Credit:
@driccosec
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯18❀5πŸ‘1
CVE-2025-22609, -22611, -22612: Multiple vulnerabilities in Coolify, 10.0 rating πŸ”₯πŸ”₯πŸ”₯

Three vulnerabilities of highest severity in Coolify allow for RCE, privilege escalation, and authentication bypass.

Search at Netlas.io:
πŸ‘‰ Link: https://nt.ls/vUWWf
πŸ‘‰ Dork: http.favicon.hash_sha256:eaf648b6000a49599ed58bda49e576d0f981e535a8075d524a4be890edcf96d0 AND uri:*login*

Vendor's advisory: https://github.com/coollabsio/coolify/security/advisories/GHSA-3w2c-jfr2-9pg9
😁10πŸ‘3
Where is the reactions πŸ–₯
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ—Ώ13πŸ™4🐳3πŸ‘2
πŸ’‘Snov finds email addresses on any website. #OSINT

snov.io/email-finder
πŸ‘10πŸ”₯6❀4🀨2
πŸ’‘Blackbird is a powerful OSINT tool designed for fast and efficient searches of user accounts by username or email across multiple platforms, streamlining digital investigations.

https://github.com/p1ngul1n0/blackbird
πŸ”₯10πŸ‘5🀝2
Ninjasworkout:-- Vulnerable NodeJS Web Application.

ADDED BUGS:-
Prototype Pollution βœ…1
No SQL Injection βœ…2
Cross site Scripting βœ…3
Broken Access Control βœ…4
Broken Session Management βœ…5
Weak Regex Implementation βœ… 6
Race Condition βœ…7
CSRF -Cross Site Request Forgery βœ…8
Weak Bruteforce Protection βœ…9
User Enumeration βœ…10
Reset Password token leaking in Referrer βœ…11
Reset Password bugs βœ…12
Sensitive Data Exposure βœ…13
Unicode Case Mapping Collision βœ…14
File Upload βœ… 15
SSRF βœ… 16
XXE
Open Redirection βœ… 17
Directory Traversal βœ… 18
Insecure Deserilization => Remote Code Execution βœ… 19


https://github.com/effortlessdevsec/ninjasworkout
❀17πŸ‘3
🀣20πŸ‘2
πŸ”–Zzl - Collect subdomains from SSL certificates
https://github.com/DEMON1A/zzl
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘6πŸ”₯3πŸ‘3❀1