Brut Security
14.6K subscribers
907 photos
73 videos
287 files
962 links
βœ…Queries: @wtf_brut
πŸ›ƒWhatsApp: wa.link/brutsecurity
🈴Training: brutsec.com
πŸ“¨E-mail: [email protected]
Download Telegram
If you liked the posts, tap the heart. That tiny click means a lot. ❀️
Please open Telegram to view this post
VIEW IN TELEGRAM
❀49πŸ”₯5
πŸ₯³DiffRays is a research-oriented tool for binary patch diffing, designed to aid in vulnerability research, exploit development, and reverse engineering.

🟒 https://github.com/pwnfuzz/diffrays
Please open Telegram to view this post
VIEW IN TELEGRAM
❀10
Hey Hunter's,
Darkshadow here back again!

☠️Non-parameter LFIπŸ”₯

if you try: target.com/../../../../../../etc/passwd
browser redirect to = target.com/etc/passwd

try url encoding:
target.com/..%2F..%2F..%2F..%2Fetc%2Fpasswd
now browser not redirect you to back directory.

#bugbountytips #fli
❀22πŸ‘5πŸ—Ώ5
Forwarded from Bug Bounty POC's
A quick way to find "all" paths for Next.js websites:

console.log(__BUILD_MANIFEST.sortedPages)
javascript​:console.log(__BUILD_MANIFEST.sortedPages.join('\n'));
πŸ”₯19❀8
If you liked the posts, tap the heart. That tiny click means a lot. ❀️
Please open Telegram to view this post
VIEW IN TELEGRAM
❀30
Forwarded from Brut Security
Common Security Issues in FinanciallyOriented Web Applications
πŸ”₯6❀3
Brut Security pinned Deleted message
⚑Bug Bounty Tip πŸš€

βœ…Level up your recon with GitHub's new regex search on cs.github.com! Hunt for hardcoded credentials like SSH & FTP connection strings.

🚨Example Dorks:
/ssh:\/\/.*:.*@.*target\.com/
/ftp:\/\/.*:.*@.*target\.com/
❀21πŸ‘1
If you liked the posts, tap the heart. That tiny click means a lot. ❀️
Please open Telegram to view this post
VIEW IN TELEGRAM
❀15
CVE-2025-42944, -42937, -42910, and other: Multiple vulnerabilities in SAP NetWeaver, 5.3 - 10.0 πŸ”₯πŸ”₯πŸ”₯

In its October bulletin, SAP published a list of 13 new vulnerabilities affecting NetWeaver, NetWeaver AS Java, and other products. These vulnerabilities include Insecure Deserialization, Information Disclosure, etc.

Search at Netlas.io:
πŸ‘‰ Link: https://nt.ls/aBHGg
πŸ‘‰ Dork: http.headers.server:"NetWeaver"

Vendor's advisory: https://support.sap.com/en/my-support/knowledge-base/security-notes-news/october-2025.html
❀8πŸ‘2
🚨 Critical zero-day tagged as CVE-2025-61882 (CVSS 9.8) affecting Oracle E-Business Suite

πŸ₯³Nuclei Vulnerability Detection Script:
https://github.com/rxerium/CVE-2025-61882

🟒This vulnerability is remotely exploitable without authentication.
Please open Telegram to view this post
VIEW IN TELEGRAM
❀13πŸ”₯3
πŸ₯³Oracle just disclosed a new vulnerability tagged CVE-2025-61884 - remotely exploitable vuln without requiring authentication

πŸ‘‰Nuclei detection for CVE-2025-61884 -https://gist.github.com/rxerium/6c70bc6b72fc0d1365c85937d35d9550
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯10❀3
😘dON'T fORGET tO gIVE rEACTIONS🫑
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯12
🟒Awesome MLSecOps - A curated list of MLSecOps tools, articles and other resources on security applied to Machine Learning and MLOps systems.

🚨https://github.com/RiccardoBiosas/awesome-MLSecOps
Please open Telegram to view this post
VIEW IN TELEGRAM
❀9πŸ”₯4
Media is too big
VIEW IN TELEGRAM
Backdoor vs WAF 🀣
As like the same think happens when WAF try to detect backdoor and the backdoor hide there self using encoding etc.πŸ˜‚
😁13❀2πŸ‘2🀨2
This media is not supported in your browser
VIEW IN TELEGRAM
🚨CVE-2025-24071 // CVE-2025-24054: PoC for NTLM Hash Leak via RAR/ZIP Extraction and .library-ms File

🟒POC: https://github.com/0x6rss/CVE-2025-24071_PoC
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯14πŸ‘2❀1