Brut Security
14.7K subscribers
910 photos
73 videos
287 files
967 links
โœ…Queries: @wtf_brut
๐Ÿ›ƒWhatsApp: wa.link/brutsecurity
๐ŸˆดTraining: brutsec.com
๐Ÿ“จE-mail: [email protected]
Download Telegram
Forwarded from Netlas.io
๐Ÿ”ฅ Netlas Private Scanner is Here! ๐Ÿ”ฅ

Now you can perform super fast non-intrusive scan of any attack surface or even single IP address, and analyze up-to-date results ๐Ÿ”

Other improvements:
๐Ÿค Team features (sharing) added to the Discovery and Scanner
๐Ÿ› Fixed the Discovery Download bug
๐Ÿ–ฅ Some minor updates

๐Ÿ‘‰ Read more: https://docs.netlas.io/easm/scanner/
๐Ÿ”ฅ1
CVE-2024-38816: Path Traversal in Spring Framework, 7.5 ratingโ—๏ธ

An attacker can create a malicious HTTP request and use it to gain access to any file accessible by the Spring application process. However, this is easily blocked using the Spring Firewall, so don't forget to enable it.

Search at Netlas.io:
๐Ÿ‘‰ Link: https://nt.ls/jT0JO
๐Ÿ‘‰ Dork: tag.name:"spring"

Vendor's advisory: https://spring.io/security/cve-2024-38816
โค1๐Ÿ‘1
๐Ÿ—ฟ12
๐Ÿ†•CVE-2024-23692:Unauthenticated RCE Flaw in Rejetto HTTP File Server

๐Ÿ”ฅNew PoC:
https://github.com/verylazytech/CVE-2024-23692

๐Ÿ‘‡Dork:
HUNTER: web.body="HttpFileServer"&&header.server=="HFS 2.3m"
โค4๐Ÿ‘3
CVE-2024-38812, -38813: Two vulnerabilities in VMware vCenter, 7.5 - 9.8 rating ๐Ÿ”ฅ

Heap overflow and privilege escalation vulns on unpatched servers allow attackers to easily perform RCE using a specially crafted network packet.

Search at Netlas.io:
๐Ÿ‘‰ Link: https://nt.ls/44tRg
๐Ÿ‘‰ Dork: http.title:"ID_VC_Welcome" OR certificate.issuer.domain_component:"vsphere"

Vendor's advisory: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968
๐Ÿ‘2
Looking for Active Discord Moderators. Do DM Me With Your Past Experiences. ๐Ÿ‘€
Please open Telegram to view this post
VIEW IN TELEGRAM
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿ—ฟ4๐Ÿ”ฅ2
โ˜„๏ธSpideyX a multipurpose Web Penetration Testing tool with asynchronous concurrent performance with multiple mode and configurations.

๐Ÿ“Œhttps://github.com/RevoltSecurities/Spideyx

๐ŸŽค@mrz_0047
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ—ฟ5โค4๐Ÿ”ฅ3
https://github.com/pdelteil/scammy-bbp This repository contains a list of all the bug bounty programs that do not value the time and effort of hackers correctly. (Before you hunt on any target it's better to have reviews from other hackers)
โค10๐Ÿ‘1
Brut Security pinned ยซhttps://github.com/pdelteil/scammy-bbp This repository contains a list of all the bug bounty programs that do not value the time and effort of hackers correctly. (Before you hunt on any target it's better to have reviews from other hackers)ยป
โš ๏ธBypass-Four03 is a powerful bash tool designed to help testers bypass HTTP 403 forbidden errors through various path and header manipulation techniques. It also includes fuzzing for HTTP methods and protocol versions, making it a versatile addition to any web security researcher's toolkit.

๐Ÿ–ฅ https://github.com/nazmul-ethi/Bypass-Four03
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ8โค1๐Ÿ‘1
Brut Security pinned ยซ๐ŸšจIf you're looking for accurate IoT results, then Sign Up On @Netlas ๐Ÿ˜ฎโ€๐Ÿ’จhttps://app.netlas.io/ref/9cc61538/ยป
๐Ÿ‘6๐Ÿ”ฅ3๐Ÿ—ฟ1
โ˜„๏ธSubowner - A Simple python based tool to check for subdomain takeovers in mass scanning. Supports, AWS, Fastly, Shopify, Azure etc.

๐Ÿšจhttps://github.com/ifconfig-me/subowner
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ6
โค2
Finding Hidden Parameter & Potential XSS with Arjun + KXSS

arjun -q -u target -oT arjun && cat arjun | awk -F'[?&]' '{baseUrl=$1; for(i=2; i<=NF; i++) {split($i, param, "="); print baseUrl "?" param[1] "="}}' | kxss
โค13
JS Recon : WaybackURLs & HTTPX

waybackurls url | grep '\.js$' | awk -F '?' '{print $1}' | sort -u | xargs -I{} python lazyegg[.]py "{}" --js_urls --domains --ips > urls && cat urls | grep '\.' | sort -u | xargs -I{} httpx -silent -u {} -sc -title -td
๐Ÿ‘6โค3