Brut Security
15K subscribers
958 photos
76 videos
290 files
1K links
โœ…DM: @wtf_brut
๐Ÿ›ƒWhatsApp: https://wa.link/brutsecurity
๐ŸˆดTraining: https://brutsecurity.com
๐Ÿ“จMail: [email protected]
Download Telegram
๐Ÿ›กStruggling with privilege escalation or Active Directory attacks? Don't waste hoursโ€”use these 4 must-have resources:

โ€ข LOLBAS [Windows LOLBins abuse ] โ†’
https://lolbas-project.github.io/
โ€ข GTFOBins [Linux privilege escalation] โ†’
https://gtfobins.github.io/
โ€ข IppSec Rocks [HTB attack walkthroughs] โ†’
https://ippsec.rocks/?#
โ€ข WADComs [Windows AD enumeration] โ†’
https://wadcoms.github.io/
Please open Telegram to view this post
VIEW IN TELEGRAM
โค19๐Ÿ”ฅ2
Shodan Search Queries Cheat Sheet๐Ÿ”๐Ÿ“
โค31
๐ŸคFrogy 2.0 is an automated external reconnaissance and Attack Surface Management (ASM) toolkit.

๐ŸŽคhttps://github.com/iamthefrogy/frogy2.0

โญ๏ธDemo - https://www.youtube.com/watch?v=LHlU4CYNj1M
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ8
Awesome Sqlmap Tampers-1.pdf
11.8 MB
๐Ÿ”ฅ8โค1๐Ÿ‘1
โœจHackTheBox Certified Penetration Tester Specialist Cheatsheet

๐Ÿคhttps://github.com/zagnox/CPTS-cheatsheet
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ41โค6๐Ÿ‘จโ€๐Ÿ’ป2
Don't forget to give reaction and stars โœจ
1โค19๐Ÿ”ฅ5๐Ÿ˜2
CVE-2024-10441: RCE in Synology products, 9.8 rating ๐Ÿ”ฅ

Synology DSM and BSM are vulnerable to Improper Encoding or Escaping of Output, which could potentially lead to remote execution of arbitrary code.

Search at Netlas.io:
๐Ÿ‘‰ Link: https://nt.ls/KOa1N
๐Ÿ‘‰ Dork: http.favicon.hash_sha256:b8f4bb2e2ba81cb86875fb89db4571278d6e23fd888313d0f4152b1adbc8bd08

Vendor's advisory: https://www.synology.com/en-global/security/advisory/Synology_SA_24_20
๐Ÿ”ฅ7๐Ÿ‘3
๐Ÿ•ต๏ธโ€โ™‚๏ธ Bug Bounty Hunters, Hereโ€™s a Hidden Gem! ๐Ÿ’Ž
๐Ÿ“Œ Grab it now :
https://gowsundar.gitbook.io/book-of-bugbounty-tips

---------------------------------------------------------
๐Ÿš€ ๐‹๐ž๐ฏ๐ž๐ฅ ๐”๐ฉ ๐˜๐จ๐ฎ๐ซ ๐‚๐ฒ๐›๐ž๐ซ๐’๐ž๐œ ๐†๐š๐ฆ๐ž! ๐Ÿ”ฅ
๐ŸŒ brutsec.com
๐Ÿ“ฑ ๐“๐ž๐ฅ๐ž๐ ๐ซ๐š๐ฆ: t.iss.one/brutsecurity
๐Ÿ’ผ ๐—: x.com/brutsecurity
๐Ÿ“– ๐„๐ญ๐ก๐ข๐œ๐š๐ฅ ๐‡๐š๐œ๐ค๐ข๐ง๐  ๐‘๐จ๐š๐๐ฆ๐š๐ฉ: topmate.io/saumadip/1391531
๐ŸŽ“ ๐‚๐จ๐ฎ๐ซ๐ฌ๐ž ๐„๐ง๐ซ๐จ๐ฅ๐ฅ๐ฆ๐ž๐ง๐ญ: wa.link/brutsecurity
โญ ๐‹๐ข๐ค๐ž ๐ญ๐ก๐ข๐ฌ ๐ฉ๐จ๐ฌ๐ญ? โ†’ ๐…๐จ๐ฅ๐ฅ๐จ๐ฐ, ๐‰๐จ๐ข๐ง, ๐’๐ฎ๐›๐ฌ๐œ๐ซ๐ข๐›๐ž & ๐’๐ž๐ง๐ ๐’๐ญ๐š๐ซ๐ฌ ๐ญ๐จ ๐ฌ๐ก๐จ๐ฐ ๐ฒ๐จ๐ฎ๐ซ ๐ฌ๐ฎ๐ฉ๐ฉ๐จ๐ซ๐ญ!
๐Ÿ”ฅ7โค3๐Ÿ—ฟ1
๐Ÿ”–The ultimate 403 Bypass wordlists and tester notes by JHaddix

๐Ÿ“ฑ Github: ๐Ÿ”— Link

---------------------------------------------------------
๐Ÿš€ ๐‹๐ž๐ฏ๐ž๐ฅ ๐”๐ฉ ๐˜๐จ๐ฎ๐ซ ๐‚๐ฒ๐›๐ž๐ซ๐’๐ž๐œ ๐†๐š๐ฆ๐ž! ๐Ÿ”ฅ
๐ŸŒ brutsec.com
๐Ÿ“ฑ ๐“๐ž๐ฅ๐ž๐ ๐ซ๐š๐ฆ: t.iss.one/brutsecurity
๐Ÿ’ผ ๐—: x.com/brutsecurity
๐Ÿ“– ๐„๐ญ๐ก๐ข๐œ๐š๐ฅ ๐‡๐š๐œ๐ค๐ข๐ง๐  ๐‘๐จ๐š๐๐ฆ๐š๐ฉ: topmate.io/saumadip/1391531
๐ŸŽ“ ๐‚๐จ๐ฎ๐ซ๐ฌ๐ž ๐„๐ง๐ซ๐จ๐ฅ๐ฅ๐ฆ๐ž๐ง๐ญ: wa.link/brutsecurity
โญ ๐‹๐ข๐ค๐ž ๐ญ๐ก๐ข๐ฌ ๐ฉ๐จ๐ฌ๐ญ? โ†’ ๐…๐จ๐ฅ๐ฅ๐จ๐ฐ, ๐‰๐จ๐ข๐ง, ๐’๐ฎ๐›๐ฌ๐œ๐ซ๐ข๐›๐ž & ๐’๐ž๐ง๐ ๐’๐ญ๐š๐ซ๐ฌ ๐ญ๐จ ๐ฌ๐ก๐จ๐ฐ ๐ฒ๐จ๐ฎ๐ซ ๐ฌ๐ฎ๐ฉ๐ฉ๐จ๐ซ๐ญ!

#bugbounty #bugbountytips #cybersecurity #infosec #brutsecurity
๐Ÿ”ฅ8โค2
๐Ÿ‘ปCVE-2025-24071: Windows Explorer initiates an SMB authentication request upon extracting a .library-ms file from a .rar archive, exposing NTLM hashes. Extraction alone triggers the vulnerability.

โญ๏ธPOC- https://t.iss.one/brutsecurity_poc/45
Please open Telegram to view this post
VIEW IN TELEGRAM
1๐Ÿ”ฅ17๐Ÿ˜ฑ4โค3
dON'T fORGET tO gIVE rEACTIONS
๐Ÿ˜ฑ11๐Ÿ”ฅ7โค5๐Ÿ‘4
โšกThe Ultimate PNPT Study Guide โ€“ Master Pentesting & Crush the Exam!

๐Ÿ”—Link:
https://github.com/TrshPuppy/PNPT-study-guide
โค10๐Ÿ”ฅ4๐Ÿ‘3
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘10โค3๐Ÿ”ฅ3
โšกSubDomain Grabber - A bug bounty tool to download, unzip, and clean subdomains from Chaos ProjectDiscovery.

๐ŸšจConverts *.
abc.com to https://abc.com, organizes into directories, and removes ZIPs. Offers a colorful CLI, filters (BugCrowd, HackerOne, etc.), sorting, and pagination.

โœ…
https://github.com/MuhammadWaseem29/SubDomain-Grabber
๐Ÿ”ฅ10๐Ÿ‘6
Subdominator - Unleash the Power of Subdomain Enumeration

https://github.com/RevoltSecurities/Subdominator
โค19๐Ÿ‘3
๐Ÿ‘ป Looking for a Discord Moderator!๐Ÿ‘ป

โš ๏ธWe need an active mod to help manage the Brut Security server. Based on performance, youโ€™ll be rewarded with swags, gift cards, or TryHackMe vouchers!

๐Ÿ”ฅJoin & Apply Now: https://discord.gg/u7uMFV833h
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘4
Brut Security pinned ยซ๐Ÿ‘ป Looking for a Discord Moderator!๐Ÿ‘ป โš ๏ธWe need an active mod to help manage the Brut Security server. Based on performance, youโ€™ll be rewarded with swags, gift cards, or TryHackMe vouchers! ๐Ÿ”ฅJoin & Apply Now: https://discord.gg/u7uMFV833hยป
๐Ÿ›กResearch Paper ๐Ÿ“–Next.js and the corrupt middleware: the authorizing artifact

๐Ÿ”ฅhttps://zhero-web-sec.github.io/research-and-things/nextjs-and-the-corrupt-middleware
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ14โค4
โ˜บ๏ธYour support keeps me motivated to share more valuable content! If you found this helpful, drop a like & send stars โญ to help me keep going.

๐Ÿ’ฌ For queries, message me on Telegram: @wtf_brut
๐ŸŽ“ For course enrollment, reach out on WhatsApp: wa.link/brutsecurity
4๐Ÿ‘31๐Ÿ”ฅ9โค3๐Ÿ‘จโ€๐Ÿ’ป1๐Ÿซก1