Brut Security
14.7K subscribers
910 photos
73 videos
287 files
966 links
βœ…Queries: @wtf_brut
πŸ›ƒWhatsApp: wa.link/brutsecurity
🈴Training: brutsec.com
πŸ“¨E-mail: [email protected]
Download Telegram
Bypass WAF using Burp Repeater - Unicode Encoding

Encode payloads into UTF-16 to bypass basic input validation.
❀14πŸ”₯7πŸ‘5
CVE-2024-56529: Session Fixation in Mailcow, 7.5 rating❗️

The application does not disable old session IDs, which allows a remote attacker to use existing IDs in the victim's browser.

Search at Netlas.io:
πŸ‘‰ Link: https://nt.ls/AuyJw
πŸ‘‰ Dork: http.title:"mailcow UI"

Vendor's advisory: https://github.com/mailcow/mailcow-dockerized/security/advisories/GHSA-23c8-4wwr-g3c6
πŸ”₯3πŸ‘2πŸ‘1
Exposed source code is a goldmine but don't limit yourself to just Git , some teams use Subversion, Mercurial, Bazaar & more!
πŸ”₯14πŸ‘2
πŸ”–JSA - Javascript security analysis (JSA) is a program for monitoring javascript files during the web application security assessment.

πŸ“± Github: πŸ”—Link
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯32❀10πŸ‘4
where is the reaction guysss? 🚨🚨🚨
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯12❀2πŸ‘1
πŸ’  Complete Web App Pentesting

πŸ”—
https://hacklido.com/lists/8
πŸ”₯31❀5
⚑️Bugbounty Roadmap
❀13πŸ”₯2
Ultimate Nmap Commands Cheat Sheet 🧿

πŸ”–#infosec #cybersecurity #hacking #pentesting #security
❀12
Unauthorized Data Upload in Alibaba Cloud – PoC by Chirag Artani πŸ”₯

A new video is out on our friend’s channel, showcasing the discovery of a fresh vulnerability. The video includes an interesting query and a practical example of exploitation. Don’t miss it! πŸ”

We also recommend checking out Chirag Artani’s website and Twitter for more cybersecurity insights:

πŸ‘‰ Website: 3rag.com
πŸ‘‰ Twitter: x.com/Chirag99Artani
πŸ‘7
🀣15😒6πŸ—Ώ5πŸ‘¨β€πŸ’»4😁3
One-liner to gather and crawl subdomains, then generate a custom wordlist from the target's discovered URLs πŸ‘‡πŸ½

subfinder -d bugcrowd.com -silent | httpx -silent | hakrawler | tr '[:punct:]' '\n' | sort -u
πŸ‘13❀3
This media is not supported in your browser
VIEW IN TELEGRAM
πŸ‘1
πŸš€ Brut Security Hits 10K Subscribers! πŸŽ‰

Thank you all for being part of this journey! From sharing knowledge and resources to building a strong cybersecurity community, Brut Security has grown beyond expectations.

Your support fuels everything we doβ€”training, tools, research, and challenges like Breaking O-Auth. Whether you’re here for bug bounty tips, pentesting insights, or DFIR knowledge, this is just the beginning.

πŸ”₯ More exclusive content, live bug hunting, and deep-dive discussions coming soon! Stay tuned, stay curious, and keep hacking ethically.

#BrutSecurity #10KStrong #BugBounty #Cybersecurity
πŸ”₯10❀4
⚑Register for our upcoming batch.

βœ…
https://wa.link/5s41l8
πŸ‘1
πŸ”₯RCE via Image File Upload Bug Bounty PoC---> https://t.iss.one/brutsecurity_poc/37
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯4
🀣31😁3πŸ‘1πŸ‘¨β€πŸ’»1🀝1
This media is not supported in your browser
VIEW IN TELEGRAM
πŸ‘€Just because a subdomain exists in public sources doesn’t mean it’s live.

You can chain Subfinder with Shuffledns to enumerate subdomains & resolve only valid ones.
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯18❀6πŸ‘2πŸ‘2
SSTI.txt
17.8 KB
100+ SSTI Payloads
πŸ‘10πŸ”₯6❀1
Recon Skills and Tips.pptx.pdf
825.4 KB
πŸ’΅πŸ’΅πŸ’΅Recon Skills and Tips by Godfather ORWA ⚑️
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯13❀4πŸ‘3