Brut Security
14.7K subscribers
919 photos
73 videos
287 files
974 links
Queries: @wtf_brut
🛃WhatsApp: wa.link/brutsecurity
🈴Training: brutsec.com
📨E-mail: [email protected]
Download Telegram
https://cyfare.net/

- ExploitDB - Exploits, Shellcodes, Dorks
- Malware Query Engine - Download, Search, Hunt & Intel
- Sandbox - Best Free Deep File Scanner with Unlimited file scans, 100+ yara rules, based on OPSWAT next-gen sandbox
👍5
Brut Security pinned «https://cyfare.net/ - ExploitDB - Exploits, Shellcodes, Dorks - Malware Query Engine - Download, Search, Hunt & Intel - Sandbox - Best Free Deep File Scanner with Unlimited file scans, 100+ yara rules, based on OPSWAT next-gen sandbox»
🤣22👍1
Due to an error the giveaway is restarted.
Participate Here-
https://discord.gg/GZBsQMY6
👍1
If you're into generating subdomains quickly 🚀
check out this website:
husseinphp.github.io/subdomain/

#bugbountytips #bugbountytip #BugBounty
6
🔥Quick NextJS Website Recon Tip by renniepak

A quick way to find "all" paths for Next.js websites:

👇DevTools->Console

console.log(__BUILD_MANIFEST.sortedPages)

javascript​:console.log(__BUILD_MANIFEST.sortedPages.join('\n'));
23👍1
🤣5🫡2😁1
Thank You All Who Wished Me A Happy Teacher's Day 🙌
Please open Telegram to view this post
VIEW IN TELEGRAM
4
Some of the BEST Extensions for Burp Suite,

1. Autorize
2. Turbo Intruder
3. JS Link Finder
4. SQLiPy Sqlmap Integration
5. Burp NoSQLi Scanner
6. InQL Scanner
7. Logger++
8. Param Miner
9. Upload Scanner
10. Auto Repeater
👍64
CVE-2024-44000: Unauthenticated Account Takeover in LiteSpeed Cache plugin for WordPress, 9.8 rating 🔥

A vulnerability in the debug log allows attackers to gain access to user sessions, potentially leading to complete control over a website.

Search at Netlas.io:
👉 Link: https://nt.ls/syLAy
👉 Dork: http.body:"plugins/litespeed-cache"

Read more: https://securityonline.info/cve-2024-44000-cvss-9-8-litespeed-cache-flaw-exposes-millions-of-wordpress-sites-to-takeover-attacks/
👍4
🚨 Breaking O-Auth: 2 Days Challenge 🚨
Are you ready to dive into the world of OAuth attacks? Join us for an intense 2-day challenge where you'll master the art of breaking OAuth through hands-on practicals and solid theory!

💡 What’s in store?

🔍 Day 1: Learn the fundamentals of OAuth and how it's implemented across applications. We’ll cover OAuth flows, token types, scopes, and common pitfalls.

🛠️ Day 2: Get your hands dirty with real-world OAuth vulnerabilities. Experience first-hand how attackers exploit misconfigurations and weaknesses, and learn how to patch them!

This challenge is for hackers and security professionals looking to level up their skills in OAuth security. Whether you’re a beginner or a pro, this challenge will help you understand the inner workings of OAuth and its vulnerabilities.

👩‍💻 Practical + Theory: Each day is a balanced mix of hands-on exercises and deep-dive discussions to help you truly understand OAuth’s attack surface.

📍 Where: https://nas.io/brutsecurity/challenges/breaking-oauth-4-days-challenge-copy
Don’t miss out on this opportunity to learn and conquer OAuth!
Brut Security pinned «🚨 Breaking O-Auth: 2 Days Challenge 🚨 Are you ready to dive into the world of OAuth attacks? Join us for an intense 2-day challenge where you'll master the art of breaking OAuth through hands-on practicals and solid theory! 💡 What’s in store? 🔍 Day 1: Learn…»
POV : Your o auth bug is so complex that report goes to NMI 4 times. Even worst when the staff is confused what is going on and how it's happening 😂
👍7🗿2
Filed another report explaining the root cause in detail. If we get 200 members in the O-auth challenge I'll disclose the report exclusively here
1
📮 NetScan CLI is a command-line tool for retrieving and analyzing IP address information. It provides detailed subnet and organization data for given IP addresses using various online services.

🔗https://github.com/nullenc0de/netscan
🔥61