Brut Security
14.7K subscribers
911 photos
73 videos
287 files
967 links
βœ…Queries: @wtf_brut
πŸ›ƒWhatsApp: wa.link/brutsecurity
🈴Training: brutsec.com
πŸ“¨E-mail: [email protected]
Download Telegram
Unauthorized Data Upload in Alibaba Cloud – PoC by Chirag Artani πŸ”₯

A new video is out on our friend’s channel, showcasing the discovery of a fresh vulnerability. The video includes an interesting query and a practical example of exploitation. Don’t miss it! πŸ”

We also recommend checking out Chirag Artani’s website and Twitter for more cybersecurity insights:

πŸ‘‰ Website: 3rag.com
πŸ‘‰ Twitter: x.com/Chirag99Artani
πŸ‘7
🀣15😒6πŸ—Ώ5πŸ‘¨β€πŸ’»4😁3
One-liner to gather and crawl subdomains, then generate a custom wordlist from the target's discovered URLs πŸ‘‡πŸ½

subfinder -d bugcrowd.com -silent | httpx -silent | hakrawler | tr '[:punct:]' '\n' | sort -u
πŸ‘13❀3
This media is not supported in your browser
VIEW IN TELEGRAM
πŸ‘1
πŸš€ Brut Security Hits 10K Subscribers! πŸŽ‰

Thank you all for being part of this journey! From sharing knowledge and resources to building a strong cybersecurity community, Brut Security has grown beyond expectations.

Your support fuels everything we doβ€”training, tools, research, and challenges like Breaking O-Auth. Whether you’re here for bug bounty tips, pentesting insights, or DFIR knowledge, this is just the beginning.

πŸ”₯ More exclusive content, live bug hunting, and deep-dive discussions coming soon! Stay tuned, stay curious, and keep hacking ethically.

#BrutSecurity #10KStrong #BugBounty #Cybersecurity
πŸ”₯10❀4
⚑Register for our upcoming batch.

βœ…
https://wa.link/5s41l8
πŸ‘1
πŸ”₯RCE via Image File Upload Bug Bounty PoC---> https://t.iss.one/brutsecurity_poc/37
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯4
🀣31😁3πŸ‘1πŸ‘¨β€πŸ’»1🀝1
This media is not supported in your browser
VIEW IN TELEGRAM
πŸ‘€Just because a subdomain exists in public sources doesn’t mean it’s live.

You can chain Subfinder with Shuffledns to enumerate subdomains & resolve only valid ones.
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯18❀6πŸ‘2πŸ‘2
SSTI.txt
17.8 KB
100+ SSTI Payloads
πŸ‘10πŸ”₯6❀1
Recon Skills and Tips.pptx.pdf
825.4 KB
πŸ’΅πŸ’΅πŸ’΅Recon Skills and Tips by Godfather ORWA ⚑️
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯13❀4πŸ‘3
Browser Syncjacking
Check it out: lnkd.in/gBnd-YJu
πŸ”₯18🀨7πŸ‘4
Where is the reactions guys??
❀19
Cross Site Scripting (XSS) Through File Upload SVG ---> https://t.iss.one/brutsecurity_poc/38
❀15
🀣26πŸ—Ώ4πŸ‘3🐳3❀2
⚠️Data Breach Alert - OpenAI⚠️

A threat actor claims to be in possession of login credentials (email and password) for 20 million OpenAI accounts.
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ—Ώ25πŸ”₯3😱3πŸ‘1πŸ‘¨β€πŸ’»1
πŸ”₯Gourlex is a simple tool that can be used to extract URLs and paths from web pages. It can be helpful during web application assessments to uncover additional targets.

βœ…https://github.com/trap-bytes/gourlex
Please open Telegram to view this post
VIEW IN TELEGRAM
❀13πŸ‘3🐳1
πŸ”₯ CRTO Aspirants & Red Teamers – Must-Check Resource!

⚑If you're preparing for the Certified Red Team Operator (CRTO) or want to refine your red teaming skills, this GitHub repo is a goldmine.

https://github.com/h3ll0clar1c3/CRTO
πŸ‘13❀8πŸ”₯3
β˜„οΈβ˜„οΈUser information Leak Vulnerability in GitHub P1 Bug Bounty live __ POC

https://t.iss.one/brutsecurity_poc/39
Please open Telegram to view this post
VIEW IN TELEGRAM
❀13πŸ”₯7πŸ‘1πŸ—Ώ1
Reactions Please πŸ‘€
Please open Telegram to view this post
VIEW IN TELEGRAM
❀18🀝2πŸ‘1