Brut Security
15.2K subscribers
967 photos
76 videos
292 files
1.01K links
βœ…DM: @wtf_brut
πŸ›ƒWhatsApp: https://wa.link/brutsecurity
🈴Training: https://brutsecurity.com
πŸ“¨Mail: info@brutsec.com
Download Telegram
🚨X-Recon: A utility for detecting webpage inputs and conducting XSS scans.🚨

Features:
1. Subdomain Discovery
2. Site-wide Link Discovery
3. Form and Input Extraction
4. XSS Scanning

πŸ”—Link: https://lnkd.in/gfAeBPz7
πŸ’―4πŸ‘2πŸ”₯1
Have Tryhackme vouchers in stock
1 Month Voucher = 500 Rupees
Dm @wtf_yodhha
This media is not supported in your browser
VIEW IN TELEGRAM
🚨noWAFpls🚨
πŸ‘‰Burp Plugin to Bypass WAFs through the insertion of Junk Data

πŸ”— https://github.com/assetnote/nowafpls
πŸ‘3πŸ”₯1🀯1
🚨CVE-2024-23692: Unauthenticated RCE Flaw in Rejetto HTTP File Server

πŸ‘‰It allows remote attackers to execute arbitrary code on affected servers without authentication, potentially leading to data breaches, ransomware attacks, and complete system compromise.

πŸ’₯PoC: https://github.com/rapid7/metasploit-framework/pull/19240

πŸ’₯Dorks:
Hunter: /product.name="HTTP File Server" and web.body="Rejetto"
FOFA: product="HFS"
SHODAN: product:"HttpFileServer httpd"

#Rejetto #HFS #bugbounty #bugbountytips #cybersecurity #pentesting
πŸ”₯2
How are you guys? and how is everything in life?
πŸ‘4🀝2🐳1
This media is not supported in your browser
VIEW IN TELEGRAM
Found this on twitter. The POC is very informative. What you think?
πŸ”₯11πŸ‘2🀯2
Good Morning Everyone!
What topic should I post today. Let me know on discussion:) Thanks!
🀑2🐳2
Surprisingly Havij - SQL injection tool helped me to achieve a error based sqli on ferrari 😳
🐳4
Subdomain Enumeration from different sources
πŸ‘4
Simple but effective method to narrow down your scope, sometimes it helps to think simple.

waybackurls --dates domain(.)com | grep '?id='

Payload : if(now()=sysdate(),SLEEP(8),0)

By:@ynsmroztas

#bugbountytips #bugbounty
πŸ”₯6πŸ‘1
JS Recon Tool : LazyEgg
πŸ‘5πŸ”₯4
🚨CVE-2024-29849~29852: Veeam’s Backup Nightmare, Full System Access Exposed

⚠Veeam Backup Enterprise Manager has been issued 4 critical vulnerabilities, allowing unauthorized access, account takeover, and data exposure.

πŸ’₯PoC: https://github.com/sinsinology/CVE-2024-29849

πŸ’₯Dorks:
Hunter:/product.name="Veeam Backup Enterprise Manager"

FOFA:app="Veeam-Backup-Enterprise-Manager"

SHODAN:http.title:"Veeam Backup Enterprise Manager"

#Veeam #backup #infosec #infosecurity #Infosys #Vulnerability #bugbounty #bugbountytips
🀯3
Thank You Everyone for the Support 🫢
πŸ”₯12πŸ‘4❀‍πŸ”₯1😱1
Nahamsec Reconnaissance Guide
πŸ”₯11
πŸŒπŸ•΅οΈβ€β™‚οΈOminis: OSINT: Web Hunter πŸŒπŸ•΅οΈβ€β™‚οΈ

πŸ‘‰It gathers online information by querying Google with a user-inputted query. The tool then extracts relevant details like titles, URLs, and mentions of the query from the search results.

Targetable and Actionable Results 🎯
1. Identifying Potential Threats 🚨
2. Monitoring Competitors πŸ•΅οΈβ€β™‚οΈ
3. Gathering Human Intelligence πŸ‘₯
4. Detecting Brand Mentions πŸ“£
5. Investigating Individuals πŸ”
6. Uncovering Financial Insights πŸ’°
7. Mapping Digital Footprints πŸ—ΊοΈ
8. Tracking Online Campaigns πŸ“Š
9. Monitoring Regulatory Compliance πŸ“
10. Forecasting Emerging Risks πŸ“ˆ
11. Google Search Filtering πŸ–‡

πŸ”—Download: https://github.com/AnonCatalyst/Ominis-OSINT
πŸ‘6
OS Command Injection.pdf
131.8 KB
πŸ”₯8🫑2πŸ‘1
For Tryhackme and Hackthebox Vip+ Vouchers DM me.
Available For India Only. Dm @wtf_yodhha
XSS Cheat Sheet.pdf
667.3 KB
πŸ‘2
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯2❀1