Brut Security
15.2K subscribers
965 photos
76 videos
292 files
1.01K links
βœ…DM: @wtf_brut
πŸ›ƒWhatsApp: https://wa.link/brutsecurity
🈴Training: https://brutsecurity.com
πŸ“¨Mail: info@brutsec.com
Download Telegram
Brut Security pinned «🌐 Advanced Web Application Penetration Testing Course - Elevate Your Cybersecurity Skills! 🌐 πŸ”— Full Course Curriculum: https://brutsec.com/WebPentesting.pdf πŸ—“οΈ Course Details: Starting: July 16th, 4PM IST Duration: 2 Months Schedule: 3 Days a Week Format:…»
πŸ“£Google Dork - RCE Prone Parameters

inurl:cmd | inurl:exec= | inurl:query= | inurl:code= | inurl:do= | inurl:run= | inurl:read= | inurl:ping= inurl:& site:example[.]com
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘3❀1
⚑️ SQLi One Liner ⚑️


subfinder -dL subdomain.txt | grep -Eo 'https?://[^ ]+\?[a-zA-Z0-9_-]+=\d+['"'"'"]?' wayback_urls.txt > potential_sqli.txt && while read url; do sqlmap -u "$url" --batch --level 5 --risk 3 --all --random-agent --time-sec 10 ; done < potential_sqli.txt
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯6❀2
CVE-2024-6387 (and probably CVE-2006-5051): Unauthenticated RCE in OpenSSH πŸ”₯

The vulnerability, discovered by Qualys researchers, allows an attacker to perform RCE on any OpenSSH server, provided that the operating system contains the glibc library.

Versions 8.5p1 to 9.8p1 ​​are affected, and versions <4.4p are also potentially vulnerable.

Search at Netlas.io:
πŸ‘‰πŸ» Link: https://nt.ls/ySN3C
πŸ‘‰πŸ» Dork: tag.openssh.version:(>=8.5 AND <9.8) OR tag.openssh.version:(<4.4)

Read more: https://www.qualys.com/regresshion-cve-2024-6387/
πŸ‘5
πŸ”₯3
OSCP_PDF.pdf
2.3 MB
⚠️Join Our Discussion Group ⚠️
πŸ”₯ https://t.me/brutsec πŸ”₯
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘2
Brut Security pinned «⚠️Join Our Discussion Group ⚠️ πŸ”₯ https://t.me/brutsec πŸ”₯Β»
This media is not supported in your browser
VIEW IN TELEGRAM
⚠️Subprober - An essential HTTP multi-purpose Probing Tool for Penetration Testers and Security Researchers with Asynchronous httpx client support.

πŸ”₯Download: https://github.com/RevoltSecurities/Subprober
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯3
πŸ“ž Enroll Now: https://wa.me/918945971332
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘3❀1
🚨Payloads - Payload for bug bounty!🚨
πŸ”— Download https://github.com/1BlackLine/Payloads
πŸ‘5πŸ”₯1
πŸ€– Bug Bounty Target - https://bughunters.jahezgroup.com/en
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘3
β˜„οΈWill Drop A New BB Platform If We Reach 4K by Upcoming Weekβ˜„οΈ
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘7
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘6❀‍πŸ”₯1πŸ”₯1πŸ‘1😁1
This media is not supported in your browser
VIEW IN TELEGRAM
⚠️CVE-2024-36991: Path Traversal on the β€œ/modules/messaging/β€œ endpoint in Splunk Enterprise on Windows.

πŸ“£Sign Up On Netlas.io: https://app.netlas.io/ref/9cc61538/
πŸ“£Join Official Netlas Telegram: https://t.me/netlas

πŸ”΄In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise on Windows.

βœ…PoC:
https://github.com/bigb0x/CVE-2024-36991

ℹ️Netlas Dork: http.body:"splunk-Enterprise"
Please open Telegram to view this post
VIEW IN TELEGRAM
❀2πŸ‘1
πŸ“£Understanding Bug Bounty Hunting for NewcomersπŸ“£

🎁Bug bounty hunting can seem appealing, but it’s important to know:

πŸ–±High Skill Level Required: Success in bug bounty hunting demands a very high skill level. It's not just about using tools like Nuclei to scan public programs.

πŸ–±Reality Check: Many see bug bounty hunting as a way to financial freedom or a high-paying job. However, if you have the skills to excel here, you can probably find other well-paying jobs in cybersecurity.

πŸ–±Consider Your Location: Bug bounty hunting might be more attractive if you live in a country with a low average salary. Otherwise, it’s better pursued for fun or experience rather than as your main source of income.

πŸ–±Extra Income and Experience: It can be great for earning extra money and gaining experience, but it’s not a reliable primary income source.

πŸ’³Bottom Line: Bug bounty hunting can be enjoyable and rewarding as a side activity, but it’s not the best choice for a main job once you understand the reality of the work involved.
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘3