Brut Security
14.7K subscribers
918 photos
73 videos
287 files
972 links
βœ…Queries: @wtf_brut
πŸ›ƒWhatsApp: wa.link/brutsecurity
🈴Training: brutsec.com
πŸ“¨E-mail: [email protected]
Download Telegram
This media is not supported in your browser
VIEW IN TELEGRAM
⚑Scanning github repos is a great way to find juicy information, secrets and credentials!

Trufflehog makes this easy.

With one scan you can find AWS keys, FTP creds, crypto keys and more!

βœ…Check this out - https://github.com/trufflesecurity/trufflehog
❀24πŸ”₯7πŸ‘2
dON'T fORGET tO gIVE rEACTIONS
❀25πŸ”₯4🫑2πŸ€”1
🚨Multi-target unauthenticated RCE scanner for CVE-2025-34085 affecting WordPress Simple File List plugin. Uploads, renames, and triggers PHP webshells across large target sets.

βœ…
https://github.com/ill-deed/CVE-2025-34085-Multi-target
πŸ‘6❀4
🚨 CVE-2025-47812: Wing FTP Server Remote Code Execution (RCE) vulnerability

πŸ”₯PoC :
https://github.com/4m3rr0r/CVE-2025-47812-poc

πŸ‘‰Dorks:
HUNTER:
https://product.name="Wing FTP Server"
πŸ”₯11❀4πŸ‘4
😁28❀13πŸ‘3
🚨 New Batch Starting – August 2025 🚨
Brut Practical Web Penetration Testing (bPWP)

We’re back with a fresh batch of our most in-demand training – Brut Practical Web Penetration Testing – starting this August!

πŸ” Learn the art of Web Hacking with:
βœ… 100% Practical Sessions
βœ… Bug Bounty Approach
βœ… Real-World Lab Scenarios
βœ… Lifetime Community Access
βœ… Beginner-Friendly with Advanced Techniques

πŸ’» Ideal for aspiring bug bounty hunters, cybersecurity students, and VAPT professionals.

πŸ“† Limited Seats – Enroll Now
🌐
https://brutsec.com/bPWP

πŸ“© For Queries:
Telegram:
@wtf_brut
WhatsApp:
https://wa.link/brutsecurity | +918945971332
Email:
[email protected]
❀9😒2πŸ‘1
⚑AllForOne allows bug bounty hunters and security researchers to collect all Nuclei YAML templates from various public repositories.

🚨https://github.com/AggressiveUser/AllForOne
πŸ”₯19❀4πŸ‘3
⚑Bug Bounty Dorks
βœ…https://dorkking.blindf.com/
❀23πŸ‘5
πŸ‘»SpoofProof helps security professionals detect email domain spoofing vulnerabilities and validate DMARC, SPF, and DKIM configurations, making email security assessments seamless and efficient.

⭐Extension Name: SpoofProof - Domain Spoofing Validation

πŸ”— BApp Store:
https://portswigger.net/bappstore/a321360c6e114b3dab6f2c67d68c241a

πŸ’» Source Code:
https://github.com/portswigger/spoofproof
❀13πŸ”₯5
Dropping Soon
πŸ”₯13❀5
⚑BrutDroid 2.0 is a powerful, Windows-optimized toolkit designed specifically for Android Studio, streamlining the setup of a mobile penetration testing lab. Built to make Android pentesting effortless, it automates emulator creation, rooting, Frida server setup, and Burp Suite certificate installation. With a vibrant new UI and support for custom Frida scripts, BrutDroid empowers security researchers to focus on testing, not setup. Linux support is coming soon!

βœ…
https://github.com/Brut-Security/BrutDroid

⭐Don't forget to leave a star :)
❀31πŸ”₯2
Brut Security pinned Β«Full Walkthrough - https://youtu.be/bDxgilaYcE8Β»
Forwarded from Brut Security 2.0
Asset inventory of over 800 public bug bounty programs.
https://github.com/trickest/inventory
❀8πŸ‘6
Another one made it. You still watching reels?
❀27πŸ—Ώ8πŸ€”4🀝1
Recon like a Boss.pdf
1.3 MB
πŸ‘13❀3πŸ”₯3
CVE-2025-53770: Deserialization of Untrusted Data in Microsoft SharePoint, 9.8 rating πŸ”₯

The most high-profile recent vulnerability allows an attacker to perform RCE on a Microsoft SharePoint server. Hackers are already exploiting it, so be careful!

Search at Netlas.io:
πŸ‘‰ Link: https://nt.ls/Ix8gb
πŸ‘‰ Dork: http.headers.microsoftsharepointteamservices:*

Vendor's advisory: https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/
πŸ”₯11❀3