Brut Security
17.3K subscribers
1.12K photos
97 videos
360 files
1.21K links
DM: @wtf_brut
For Ad: https://tlmtr.io/p/2flAsc
🛃WhatsApp: https://wa.link/brutsecurity
🈴Training: https://brutsecurity.com
📨Mail: info@brutsec.com
Download Telegram
Please open Telegram to view this post
VIEW IN TELEGRAM
9🔥4🗿4
Please open Telegram to view this post
VIEW IN TELEGRAM
10🔥5🤣3👍1
17K+ strong. One community. One mission. ⚡️

Thank you for being part of Brut Security.

Learn. Practice. Hack. Grow.

Here’s to the next milestone. ❤️‍🔥

🔥 https://brutsecurity.com
☄️ https://wa.link/brutsecurity

#BrutSecurity #17K #CyberSecurity #EthicalHacking
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥93👏1
⚠️ Bug Bounty Tip: IDN Homograph → Account Collision

Don’t only test Unicode domains. Test Unicode in email/username fields too.

Try lookalike characters such as:

aá / other Unicode variants

The interesting case is when:

Database: treats the values as equal
Application: identifies the victim account
SMTP: treats them as different addresses

Example:

victim@gmail.com
victim@gmáil.com

If the application finds the victim's account but sends the password-reset email to the attacker-controlled Unicode address, you may have an account-collision / account-takeover vulnerability.

📣**Test normalization at every stage:**
Input → Validation → Database → Token generation → Email delivery

#BugBounty #IDNHomograph #Punycode #WebSecurity
Please open Telegram to view this post
VIEW IN TELEGRAM
7🔥3🤝2🗿1
🚨Nice tricks to bypass 403/401.
#BugBounty #bugbountytips
9👍2
🚨Search for all leaked keys/secrets using one regex!

regex: https://gist.github.com/h4x0r-dz/be69c7533075ab0d3f0c9b97f7c93a59

#BugBounty #bugbountytip
🤨63🔥3🗿1
This media is not supported in your browser
VIEW IN TELEGRAM
🔥 ⛓️ Click2Shell is a one-click unauthenticated remote command execution chain (Preauth RCE) affecting every WordPress website. Wordpress rolled out a fix yesterday! The story about how one preview link made WordPress click Install, load an inactive theme's PHP, and hand us RCE is below.

⚠️https://pwn.ai/blog/click2shell
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥52😱2👏1
Brut Security
🔥 ⛓️ Click2Shell is a one-click unauthenticated remote command execution chain (Preauth RCE) affecting every WordPress website. Wordpress rolled out a fix yesterday! The story about how one preview link made WordPress click Install, load an inactive theme's…
11 new vulnerabilities in WordPress, no CVE assigned yet ❗️

WordPress 7.1.1 security release patches 11 vulnerabilities including stored XSS, path traversal, and other security flaws.

Search at Netlas.io:
👉 Link: https://nt.ls/s3kOE
👉 Dork: tag.name:"wordpress"
5
This media is not supported in your browser
VIEW IN TELEGRAM
🔥HackTools - The all-in-one RedTeam extension for Web Pentester.

https://github.com/LasCC/Hack-Tools
Please open Telegram to view this post
VIEW IN TELEGRAM
5🔥5🗿1
Media is too big
VIEW IN TELEGRAM
FOFA UNLIMITED

🔹 100 Fresh fofa Accounts
🔹 3,000 Credits per Account / Month
🔹 100 × 3,000 = 300,000 Credits / Month
🔹 Chrome Extension with Auto Login

💰 Price: Only $30

All account details and extension are provided together.

Interested?
📩 DM on Telegram:
@fofaseller

#AD
4🤣4
🚨Bypass-403 - A simple script just made for self use for bypassing 403.

https://github.com/iamj0ker/bypass-403

#bugbounty #pentesting
9🔥4😁2
Please open Telegram to view this post
VIEW IN TELEGRAM
🤣13😁53
The new RCE exploit is 100% effective; it has already generated 48 shells in just 10 minutes.

It involves 5 combined exploits affecting over 900,000 sites. 🎯

Affecting +970k websites

DM me to buy  👉 @Mm_fit

Channel: https://t.me/fox_security_cve

#AD
1🔥1🤣1🗿1