Brut Security
14.7K subscribers
914 photos
73 videos
287 files
970 links
Queries: @wtf_brut
🛃WhatsApp: wa.link/brutsecurity
🈴Training: brutsec.com
📨E-mail: [email protected]
Download Telegram
Brut Security pinned «Full Walkthrough - https://youtu.be/bDxgilaYcE8»
Forwarded from Brut Security 2.0
Asset inventory of over 800 public bug bounty programs.
https://github.com/trickest/inventory
8👍6
Another one made it. You still watching reels?
27🗿8🤔4🤝1
CVE-2025-53770: Deserialization of Untrusted Data in Microsoft SharePoint, 9.8 rating 🔥

The most high-profile recent vulnerability allows an attacker to perform RCE on a Microsoft SharePoint server. Hackers are already exploiting it, so be careful!

Search at Netlas.io:
👉 Link: https://nt.ls/Ix8gb
👉 Dork: http.headers.microsoftsharepointteamservices:*

Vendor's advisory: https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/
🔥113
2 Seats Left! Enroll Now 😎
Forwarded from Brut Security
🚨 New Batch Starting – August 2025 🚨
Brut Practical Web Penetration Testing (bPWP)

We’re back with a fresh batch of our most in-demand training – Brut Practical Web Penetration Testing – starting this August!

🔍 Learn the art of Web Hacking with:
100% Practical Sessions
Bug Bounty Approach
Real-World Lab Scenarios
Lifetime Community Access
Beginner-Friendly with Advanced Techniques

💻 Ideal for aspiring bug bounty hunters, cybersecurity students, and VAPT professionals.

📆 Limited Seats – Enroll Now
🌐
https://brutsec.com/bPWP

📩 For Queries:
Telegram:
@wtf_brut
WhatsApp:
https://wa.link/brutsecurity | +918945971332
Email:
[email protected]
5
Chrome and Firefox extension that lists Amazon S3 Buckets while browsing

🚨Features:
Filters S3Buckets
Extract ACL permissions
Download recorded buckets
Manage recorded buckets
Tab-specific bucket recording

https://github.com/AlecBlance/S3BucketList
🔥164
PACU - The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

https://github.com/RhinoSecurityLabs/pacu
13🔥8
CYFARE-Reconner - Advanced Link Reconnaissance Extension For Firefox

Features
Deep Discovery
Secret Detection
URL Analysis

https://github.com/CYFARE/CYFARE-Reconner
12👍2
Akamai CloudTest - XXE Injection

Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection through the /concerto/services/RepositoryService SOAP endpoint.

Get: https://github.com/MuhammadWaseem29/CVE-2025-49493-Poc

References:
1. https://xbow.com/blog/xbow-akamai-cloudtest-xxe/
2. https://techdocs.akamai.com/cloudtest/changelog/june-2-2025-enhancements-and-bug-fixes
🔥54
😥
🗿20😁10🔥6👍3😱3🫡3🐳2
Looking for a freelancer, familiar with FB, Instagram and Whatsapp marketing.

Send your resume to [email protected]
🚨CVE-2025-0133 : Payload + Template

Payload: %3Csvg%20xmlns%3D%22http%3A%2F%https://2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Cscript%3Eprompt%28%22XSS%22%29%3C%2Fscript%3E%3C%2Fsvg%3E

Write-up: https://codewithvamp.medium.com/cve-2025-0133-reflected-xss-vulnerability-in-palo-alto-globalprotect-gateway-portal-028128f2f5b9

Template: https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-0133.yaml
7👍4
Bug Bounty Tip: HTTP Parameter Pollution (HPP)

Some apps mishandle duplicate parameters. You can bypass logic or elevate privileges by injecting multiple values:

GET /transfer?amount=100&admin=true&amount=1

⚠️ Always test:
•param=value1&param=value2
•Encoded (%26,)
20
Please open Telegram to view this post
VIEW IN TELEGRAM