Brut Security
14.8K subscribers
919 photos
73 videos
287 files
974 links
βœ…Queries: @wtf_brut
πŸ›ƒWhatsApp: wa.link/brutsecurity
🈴Training: brutsec.com
πŸ“¨E-mail: [email protected]
Download Telegram
🀣25😁2❀1
This media is not supported in your browser
VIEW IN TELEGRAM
πŸ‘2
πŸ”₯Always remember to test the API for existence of addition headers.
X-Originaal-URL: /v1/api/endpoint_here

BOOM => Entire API routes disclosure.
Credit:
@driccosec
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯18❀5πŸ‘1
CVE-2025-22609, -22611, -22612: Multiple vulnerabilities in Coolify, 10.0 rating πŸ”₯πŸ”₯πŸ”₯

Three vulnerabilities of highest severity in Coolify allow for RCE, privilege escalation, and authentication bypass.

Search at Netlas.io:
πŸ‘‰ Link: https://nt.ls/vUWWf
πŸ‘‰ Dork: http.favicon.hash_sha256:eaf648b6000a49599ed58bda49e576d0f981e535a8075d524a4be890edcf96d0 AND uri:*login*

Vendor's advisory: https://github.com/coollabsio/coolify/security/advisories/GHSA-3w2c-jfr2-9pg9
😁10πŸ‘3
Where is the reactions πŸ–₯
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ—Ώ13πŸ™4🐳3πŸ‘2
πŸ’‘Snov finds email addresses on any website. #OSINT

snov.io/email-finder
πŸ‘10πŸ”₯6❀4🀨2
πŸ’‘Blackbird is a powerful OSINT tool designed for fast and efficient searches of user accounts by username or email across multiple platforms, streamlining digital investigations.

https://github.com/p1ngul1n0/blackbird
πŸ”₯10πŸ‘5🀝2
Ninjasworkout:-- Vulnerable NodeJS Web Application.

ADDED BUGS:-
Prototype Pollution βœ…1
No SQL Injection βœ…2
Cross site Scripting βœ…3
Broken Access Control βœ…4
Broken Session Management βœ…5
Weak Regex Implementation βœ… 6
Race Condition βœ…7
CSRF -Cross Site Request Forgery βœ…8
Weak Bruteforce Protection βœ…9
User Enumeration βœ…10
Reset Password token leaking in Referrer βœ…11
Reset Password bugs βœ…12
Sensitive Data Exposure βœ…13
Unicode Case Mapping Collision βœ…14
File Upload βœ… 15
SSRF βœ… 16
XXE
Open Redirection βœ… 17
Directory Traversal βœ… 18
Insecure Deserilization => Remote Code Execution βœ… 19


https://github.com/effortlessdevsec/ninjasworkout
❀17πŸ‘3
🀣20πŸ‘2
πŸ”–Zzl - Collect subdomains from SSL certificates
https://github.com/DEMON1A/zzl
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘6πŸ”₯3πŸ‘3❀1
Price Tampering & Store XSS Bug poc _ Price Manipulation _ CodePrefer ---> https://t.iss.one/brutsecurity_poc/24
πŸ”₯8🀨3πŸ—Ώ2πŸ™1
β˜„οΈCrlfix - An accurate and concurrent CRLF Injection Vulnerability Scanner

▢️https://github.com/RevoltSecurities/Crlfix?tab=readme-ov-file
Please open Telegram to view this post
VIEW IN TELEGRAM
1πŸ”₯6πŸ‘3
What’s the best cybersecurity book you’ve ever read? πŸ“šπŸ”’
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯8❀4
πŸ”₯Robofinder is a powerful Python script designed to search for and retrieve historical robots.txt files from Archive.org for any given website. This tool is ideal for security researchers, web archivists, and penetration testers to uncover previously accessible paths or directories that were listed in a site's robots.txt.

πŸ”–https://github.com/Spix0r/robofinder
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯14πŸ‘2