Brut Security
14.7K subscribers
918 photos
73 videos
287 files
973 links
โœ…Queries: @wtf_brut
๐Ÿ›ƒWhatsApp: wa.link/brutsecurity
๐ŸˆดTraining: brutsec.com
๐Ÿ“จE-mail: [email protected]
Download Telegram
โš ๏ธGoby is a new generation network security assessment tool. It can efficiently and practically scan vulnerabilities while sorting out the most complete attack surface information for a target enterprise. Goby can also quickly penetrate the company intranet based on a company's vulnerabilities exposed to the Internet. We strive for Goby to become a more vital tool that can benchmark against hackers' actual attack methods and help companies effectively understand and respond to cyber-attacks.

๐Ÿ’ฅhttps://github.com/gobysec/Goby
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ7โšก1๐Ÿ‘1
https://cyfare.net/

- ExploitDB - Exploits, Shellcodes, Dorks
- Malware Query Engine - Download, Search, Hunt & Intel
- Sandbox - Best Free Deep File Scanner with Unlimited file scans, 100+ yara rules, based on OPSWAT next-gen sandbox
๐Ÿ‘5
Brut Security pinned ยซhttps://cyfare.net/ - ExploitDB - Exploits, Shellcodes, Dorks - Malware Query Engine - Download, Search, Hunt & Intel - Sandbox - Best Free Deep File Scanner with Unlimited file scans, 100+ yara rules, based on OPSWAT next-gen sandboxยป
๐Ÿคฃ22๐Ÿ‘1
Due to an error the giveaway is restarted.
Participate Here-
https://discord.gg/GZBsQMY6
๐Ÿ‘1
If you're into generating subdomains quickly ๐Ÿš€
check out this website:
husseinphp.github.io/subdomain/

#bugbountytips #bugbountytip #BugBounty
โค6
๐Ÿ”ฅQuick NextJS Website Recon Tip by renniepak

A quick way to find "all" paths for Next.js websites:

๐Ÿ‘‡DevTools->Console

console.log(__BUILD_MANIFEST.sortedPages)

javascriptโ€‹:console.log(__BUILD_MANIFEST.sortedPages.join('\n'));
โค23๐Ÿ‘1
๐Ÿคฃ5๐Ÿซก2๐Ÿ˜1
Thank You All Who Wished Me A Happy Teacher's Day ๐Ÿ™Œ
Please open Telegram to view this post
VIEW IN TELEGRAM
โค4
Some of the BEST Extensions for Burp Suite,

1. Autorize
2. Turbo Intruder
3. JS Link Finder
4. SQLiPy Sqlmap Integration
5. Burp NoSQLi Scanner
6. InQL Scanner
7. Logger++
8. Param Miner
9. Upload Scanner
10. Auto Repeater
๐Ÿ‘6โค4
CVE-2024-44000: Unauthenticated Account Takeover in LiteSpeed Cache plugin for WordPress, 9.8 rating ๐Ÿ”ฅ

A vulnerability in the debug log allows attackers to gain access to user sessions, potentially leading to complete control over a website.

Search at Netlas.io:
๐Ÿ‘‰ Link: https://nt.ls/syLAy
๐Ÿ‘‰ Dork: http.body:"plugins/litespeed-cache"

Read more: https://securityonline.info/cve-2024-44000-cvss-9-8-litespeed-cache-flaw-exposes-millions-of-wordpress-sites-to-takeover-attacks/
๐Ÿ‘4
๐Ÿšจ Breaking O-Auth: 2 Days Challenge ๐Ÿšจ
Are you ready to dive into the world of OAuth attacks? Join us for an intense 2-day challenge where you'll master the art of breaking OAuth through hands-on practicals and solid theory!

๐Ÿ’ก Whatโ€™s in store?

๐Ÿ” Day 1: Learn the fundamentals of OAuth and how it's implemented across applications. Weโ€™ll cover OAuth flows, token types, scopes, and common pitfalls.

๐Ÿ› ๏ธ Day 2: Get your hands dirty with real-world OAuth vulnerabilities. Experience first-hand how attackers exploit misconfigurations and weaknesses, and learn how to patch them!

This challenge is for hackers and security professionals looking to level up their skills in OAuth security. Whether youโ€™re a beginner or a pro, this challenge will help you understand the inner workings of OAuth and its vulnerabilities.

๐Ÿ‘ฉโ€๐Ÿ’ป Practical + Theory: Each day is a balanced mix of hands-on exercises and deep-dive discussions to help you truly understand OAuthโ€™s attack surface.

๐Ÿ“ Where: https://nas.io/brutsecurity/challenges/breaking-oauth-4-days-challenge-copy
Donโ€™t miss out on this opportunity to learn and conquer OAuth!
Brut Security pinned ยซ๐Ÿšจ Breaking O-Auth: 2 Days Challenge ๐Ÿšจ Are you ready to dive into the world of OAuth attacks? Join us for an intense 2-day challenge where you'll master the art of breaking OAuth through hands-on practicals and solid theory! ๐Ÿ’ก Whatโ€™s in store? ๐Ÿ” Day 1: Learnโ€ฆยป
POV : Your o auth bug is so complex that report goes to NMI 4 times. Even worst when the staff is confused what is going on and how it's happening ๐Ÿ˜‚
๐Ÿ‘7๐Ÿ—ฟ2
Filed another report explaining the root cause in detail. If we get 200 members in the O-auth challenge I'll disclose the report exclusively here
โค1
๐Ÿ“ฎ NetScan CLI is a command-line tool for retrieving and analyzing IP address information. It provides detailed subnet and organization data for given IP addresses using various online services.

๐Ÿ”—https://github.com/nullenc0de/netscan
๐Ÿ”ฅ6โค1