Brut Security
15.2K subscribers
967 photos
76 videos
292 files
1.01K links
βœ…DM: @wtf_brut
πŸ›ƒWhatsApp: https://wa.link/brutsecurity
🈴Training: https://brutsecurity.com
πŸ“¨Mail: info@brutsec.com
Download Telegram
Do Sign Up for Top Notch Results 😎
Please open Telegram to view this post
VIEW IN TELEGRAM
🀣15😁3❀2🀯1
Best App For Sql Injection
Link -
https://github.com/darknethaxor/DH-HackBar
πŸ‘4πŸ†’3
🀯🀯🀯🀯🀯🀯🀯🀯🀯🀯🀯🀯
Drop Your Suggestions for Resources
Please open Telegram to view this post
VIEW IN TELEGRAM
🀣6😁2πŸ™1
🀣10
This media is not supported in your browser
VIEW IN TELEGRAM
BBRF-Client: The Bug Bounty Reconnaissance Framework (BBRF) can help you coordinate your reconnaissance workflows across multiple devices.

😚 https://github.com/honoki/bbrf-client/
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘2πŸ‘1
πŸ‘3
IDOR in Reset Password

When the user reset his password the application make an API request to make sure that username exists. If exist, it will come back with Personal Identifying Information (PII) in the response [Full name,Email,Phone number].

By:
@Maakthon

#bugbountytips
❀11πŸ‘4
🚨 CVE-2024-40348 🚨

πŸ‘‰ This is a bulk scanning and exploitation tool for CVE-2024-40348: Bazaar v1.4.3 allows unauthenticated attackers to execute a directory traversal. This vulnerability was discovered by 4rdr.

πŸ”— Download :
https://github.com/bigb0x/CVE-2024-40348
πŸ”₯2❀1
Advanced SQL Injection Techniques by nav1n0x.pdf
1 MB
Advanced SQL Injection Techniques
❀7πŸ”₯1
🀩Hey everyone, thanks for being part of this awesome community!
🐸If you enjoy my content and want to support me, you can buy me a coffee on Ko-fi: https://ko-fi.com/brutxninja β˜•οΈ !
Please open Telegram to view this post
VIEW IN TELEGRAM
❀2🀝1
Brut Security pinned «🀩Hey everyone, thanks for being part of this awesome community! 🐸If you enjoy my content and want to support me, you can buy me a coffee on Ko-fi: https://ko-fi.com/brutxninja β˜•οΈ !Β»
πŸš€A Practical Guide to Starting Your Cybersecurity Career in IndiaπŸš€

✈️Link- https://ko-fi.com/post/A-Practical-Guide-to-Starting-Your-Cybersecurity-C-L4L410XGKI
Please open Telegram to view this post
VIEW IN TELEGRAM
❀1
😎Add this to your wordlist:
actuator/env
actuator/auditevents
actuator/beans
actuator/caches
actuator/configprops
actuator/health
actuator/heapdump
actuator/info
actuator/integrationgraph
actuator/configprops
actuator/jolokia/exec/
com.sun.management:type=DiagnosticCommand/compilerDirectivesAdd/!/etc!/hosts

#bugbountytip #bugbountytips #bugbounty
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘3
πŸ₯°SQLi Tip by @0xTib3rius
If your input causes a server error (e.g. 500) when you inject a ' (for eg) but you don't get reliable results using boolean inferential injections, try these payloads which should trigger the 500 when the red condition is true.
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯2
Permission Model Issues: $3,000,000 methodology

https://forums.cybershieldctf.com/showthread.php?tid=87
πŸ”₯1
✈️Bug Type - Improper Authentication – Generic CWE-287

πŸš€Summary:
While testing the site I found the registration OTP bypass error which lead to create new accounts
without verifying them and can generate different account from different number unlimited times.

πŸ‘Ύhttps://youtu.be/5LdtitF3ovE
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘2❀1😍1
bbtip.jpg
180.5 KB
Bug Bounty Tips !
πŸ‘2
Easy Account Take Over

1.Go to
http://web.archive.org
2. Put the domain and search for urls
3. Type in the filter ( %40 ) and search
4. Get a lot of urls that have a parameter leaks the email and password of the users

By:
@Sayed_v2

#BugBounty #bugbountytips
πŸ”₯11πŸ‘3