Brut Security
15.3K subscribers
968 photos
76 videos
292 files
1.01K links
βœ…DM: @wtf_brut
πŸ›ƒWhatsApp: https://wa.link/brutsecurity
🈴Training: https://brutsecurity.com
πŸ“¨Mail: info@brutsec.com
Download Telegram
πŸ”«Smap - passive Nmap like scanner built with shodan.io

😠Smap is a port scanner built with shodan.io's free API. It takes same command line arguments as Nmap and produces the same output which makes it a drop-in replacament for Nmap.

🀨 Read more: https://github.com/s0md3v/Smap

😐#infosec #cybersecurity #hacking #pentesting #security
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯3❀‍πŸ”₯1
βš”οΈPentest-Windows
πŸ”°Windows11 Penetration Suite Toolkit

πŸ“ŒA Windows penetration testing environment that works out of the box.

⚠️This project was created for educational purposes and should not be used in environments without legal authorization.

πŸ”—Link: https://lnkd.in/gtX3GbR8

πŸ”–#infosec #cybersecurity #hacking #pentesting #security #infosec #cybersecurity #hacking #pentesting #security #oscp #ceh #nmap #infosec #hackingtools #networksecurity
πŸ”₯1
⚑️Burp Suite for Pentester

ℹ️This cheat sheet is built for Bug Bounty Hunters and penetration testers to help them hunt the vulnerabilities. It is designed such that beginners can understand the fundamentals and professionals can brush up their skills with the advanced options.

πŸ”Ή Web Scanner & Crawler
πŸ”ΉFuzzing with Intruder (Part3)
πŸ”ΉFuzzing with Intruder (Part2)
πŸ”ΉFuzzing with Intruder (Part1)
πŸ”ΉXSS Validator
πŸ”ΉConfiguring Proxy
πŸ”ΉBurp Collaborator
πŸ”ΉHackBar
πŸ”ΉBurp Sequencer
πŸ”ΉTurbo Intruder
πŸ”ΉEngagement Tools
πŸ”ΉPayload Processing Rule (Part2)
πŸ”ΉPayload Processing Rule (Part1)
πŸ”ΉBeginners Guide to Burpsuite Payloads (Part2)
πŸ”ΉBeginners Guide to Burpsuite Payloads (Part1)
πŸ”ΉEncoder & Decoder Tutorial
πŸ”ΉActive Scan++
πŸ”ΉSoftware Vulnerability Scanner
πŸ”ΉBurp’s Project Management
πŸ”ΉRepeater

πŸ”—Link: https://github.com/Ignitetechnologies/BurpSuite-For-Pentester

πŸ”–#infosec #cybersecurity #hacking #pentesting #security
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘4πŸ”₯2🫑1
πŸ”List of GitHub Dorks for bug bounties.

πŸ“‹Finding
target Files, Languages, API Keys,
Tokens, Usernames, Passwords, Information using
Dates, Extension πŸ““

πŸ”–#infosec #cybersecurity #hacking #pentesting #security
πŸ”₯7πŸ‘1
πŸ› οΈGuide to Active Directory Hacking

πŸ“Active Directory (AD) is a directory service developed by Microsoft to manage and store network information, offering a central location for access control and network security.

πŸ“° Read more: https://en.iguru.gr/odigos-gia-active-directory-hacking/

πŸ”–#infosec #cybersecurity #hacking #pentesting #security
CVE-2024-33533, -33535, -33536: Multiple vulns in Zimbra, 5.4 - 7.5 rating❗️

The vulnerabilities could allow an attacker to perform path traversal or create XSS injection, which could compromise sensitive data.

Search at Netlas.io:
πŸ‘‰ Link: https://nt.ls/0aGwL
πŸ‘‰ Dork: http.favicon.hash_sha256:1afd891aacc433e75265e3ddc9cb4fc63b88259977811384426c535037711637 OR \*.banner:"Zimbra"

Vendor's advisory: https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.8#Security_Fixes
πŸ‘4❀2
πŸ”Top 10 Shodan Dorks

πŸ”–#infosec #cybersecurity #hacking #pentesting #security
πŸ‘3πŸ‘1
Ultimate Nmap Commands Cheat Sheet 🧿

πŸ”–#infosec #cybersecurity #hacking #pentesting #security
❀12
Dalfox v2.10.0 released! It uses way less CPU while XSS scanning even faster than before.

github.com/hahwul/dalfox

#DAST #Security #BugBounty
πŸ—Ώ27πŸ‘10
🚨 CVE-2025-53652: Jenkins Git Parameter Plugin Unvalidated Input Vulnerability

πŸ”₯PoC :https://github.com/pl4tyz/CVE-2025-53652-Jenkins-Git-Parameter-Analysis

πŸ‘‡Dorks
HUNTER : http://product.name="Jenkins"

πŸ“°Refer:https://jenkins.io/security/advisory/2025-07-09/#SECURITY-3419

https://github.com/advisories/GHSA-qcj2-99cg-mppf
❀8