Brut Security
15.6K subscribers
1.01K photos
82 videos
295 files
1.08K links
βœ…DM: @wtf_brut
πŸ›ƒWhatsApp: https://wa.link/brutsecurity
🈴Training: https://brutsecurity.com
πŸ“¨Mail: info@brutsec.com
Download Telegram
⚠️A web pentesting batch started this weekend.

β˜„οΈ50% discount for this batch only!

πŸ””Starting from Saturday 1.30 PM IST

DM on WhatsApp - wa.link/brutsecurity
Please open Telegram to view this post
VIEW IN TELEGRAM
😁2❀1
πŸ”” A PoC/exploit has been discovered for vulnerability CVE-2026-35616

PT ID: PT-2026-30288

Vendor: Fortinet
Product: FortiClientEMS
Description: A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

Link: https://github.com/Alaatk/CVE-2026-35616
❀5
πŸ”₯πŸ‘‰Get Web Application Bug Bounty Methodology + Bug Bounty Masterclass + Ethical Hacking Study Guide at 50% Discount
https://topmate.io/saumadip/2054509?coupon_code=awxe
Please open Telegram to view this post
VIEW IN TELEGRAM
❀1
⚑️PoC collection of Atlassian(Jira, Confluence, Bitbucket) products and Jenkins, Solr, Nexus,etc

βœ…http://github.com/shadowsock5/Poc
πŸ”₯8❀6🐳2πŸ‘1
🦊 BRUT SECURITY – NEW BATCH STARTING FROM JUNE

πŸ‘ΎMaster Practical Web Pentesting & Bug Bounty Hunting from scratch to advanced level.

βœ… Real-world web attacks
βœ… Live practical sessions
βœ… Bug bounty methodology
βœ… Recon to exploitation
βœ… Report writing & workflow
βœ… Beginner friendly + advanced concepts

πŸ“… Batch Starts: June 2026
πŸ“ Online Live Classes, Weekend Batch
πŸ“© Limited seats available

πŸ”™πŸ”œDM http://wa.link/brutsecurity
Please open Telegram to view this post
VIEW IN TELEGRAM
❀5
Hey Hunter’s,
DarkShadow is here back again!

if you got any api endpoint and showing you unauthorized then use fake perameter like:

/api/public = unauthorized
/api/public/latest?anything=/api/public


you can FUZZ like:
?admin=true,
?bypass=1,
debug=true,
OR try to add header β€œX-Custom-IP-Authorization: 127.0.0.1”

these are some underrated but very effective method which i use to check api endpoints.


if you guy’s really enjoy to read such method then show your love to react here πŸ”₯❀️
πŸ”₯6❀4πŸ‘2