Brut Security
15.2K subscribers
967 photos
76 videos
292 files
1.01K links
βœ…DM: @wtf_brut
πŸ›ƒWhatsApp: https://wa.link/brutsecurity
🈴Training: https://brutsecurity.com
πŸ“¨Mail: info@brutsec.com
Download Telegram
you have a big js file ? no time to analyze it all

search for these :
URLSearchParams
window.location
window.location.search
URL.searchParams
fetch()
XMLHttpRequest
FormData
window.location.hash
window.location.href
URL.hash

#bugbountytips
πŸ‘14❀1
Do you want to receive this gift with just one report and one bug?

The GC3 Vulnerability program is one of the best programs after the DOD program for reputation collection as well as gift collection

This program is similar to the large DOD and has more than 10,000 subdomains you can work on it works in two ways

The first only gives you a reputation. You can report it on the HACKERONE platform

LINK:
https://vulnerability-reporting.service.security.gov.uk/

Secondly, it gives you a reputation and gifts as shown above

LINK:
https://www.gov.uk/guidance/report-a-vulnerability-on-an-mod-system

#bugbounty #bugbountytips
πŸ‘3
add this file to your wordlist `.gitlab-ci.yml` , enjoy
its contain a database username and password

By:
@NoRed0x

#bugbounty #bugbountytips
❀5πŸ‘1
chrome_2PdqXXPfb9.png
128.7 KB
⚠️How Can I Earn $1000 Per Day [Santiago Lopez] Methods⚠️
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘3❀2
3 million dollars Methodology Santiago Lopez.pdf
469.9 KB
$3 million dollars Methodology! [Santiago Lopez]
❀4😭3πŸ‘1
LucasFaudman_apkscan_Scan_for_secrets,_endpoints,_and_other_sensitive.mov
3.7 MB
🫑APKscan - Scan for secrets, endpoints, and other sensitive data after decompiling and deobfuscating Android files. (.apk, .xapk, .dex, .jar, .class, .smali, .zip, .aar, .arsc, .aab, .jadx.kts).

πŸš€Download - https://github.com/LucasFaudman/apkscan

#bugbounty #bugbountytips
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯8
🚨 Depix πŸ‘‰ It is a free and open-source tool used for image steganography, specifically for extracting hidden data from images.

πŸ”—Download :
https://github.com/spipm/Depix

#bugbounty #bugbountytips
❀2πŸ”₯2
Discover more subdomains during your recon by extracting subdomains from TLS certificates. Integrate Cero into your recon automation for better results.

https://github.com/glebarez/cero
πŸ”₯5πŸ‘2
PostgreSQL Injection via CAST:

'=(SELECT CAST(user AS int) FROM users)='

πŸ’‘ DB errors w/o useful info? Try this payload ☝️
πŸ₯°5
Mastering Online Cameras Searching πŸ“Ή

Intrigued by global events? Live cameras offer a solution. Millions of Internet-connected devices worldwide provide real-time views of live events, like public gatherings and conflictsπŸ’₯

IoT search engines, Google dorking, and niche websites: learn how to search online cameras around the world πŸ”Ž

πŸ‘‰ Read now:
https://netlas.io/blog/find_online_cameras/

βœ… Sign Up Now on @netlas- https://app.netlas.io/ref/9cc61538/
Please open Telegram to view this post
VIEW IN TELEGRAM
❀2πŸ‘2
πŸš€CRLFsuite - CRLF injection scanner πŸš€
πŸ‘‰ The most powerful CRLF injection (HTTP Response Splitting) scanner.
πŸ”— Download :
https://github.com/Raghavd3v/CRLFsuite
πŸ”₯6
This media is not supported in your browser
VIEW IN TELEGRAM
πŸ’―Success in bug bounty isn't about luckβ€”it's about persistence. Every failure is a lesson, and every attempt brings you closer to the win.
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘14❀7
Brut Security pinned Deleted message
πŸš€Found a subdomain running on Symfony debug mode.
πŸ‘ΎTip: Use EOS (https://github.com/synacktiv/eos) to get PHP variables and a lot more.

#BugBounty #bugbountytips #vulnerability
Please open Telegram to view this post
VIEW IN TELEGRAM
❀1
πŸ₯·WebLogic Server Unauthenticated RCE | CVE 2020-14882
πŸ“žhttps://www.youtube.com/watch?v=WJn3-DHK1bk
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘5
Advanced XSS.pdf
370.6 KB
SQLi Techniques.zip
5.6 MB
πŸ‘6❀3
πŸ”₯22😁5πŸ‘4❀1πŸ—Ώ1
Add 'app/config/config.local.neon' to the wordlist, and maybe you will get juicy data.

By:
@NoRed0x

#bugbountytips #bugbountytip
πŸ‘Œ5❀2πŸ‘1