Brut Security – Telegram
Brut Security
14.6K subscribers
903 photos
72 videos
287 files
956 links
Queries: @wtf_brut
🛃WhatsApp: wa.link/brutsecurity
🈴Training: brutsec.com
📨E-mail: info@brutsec.com
Download Telegram
https://x.com/wtf_brut/status/1863893133379150234
Do Follow Me On
🐣
Have Shared Almost 2000+ Bug Bounty Tips.
😱🇷🇺🇺🇸
Please open Telegram to view this post
VIEW IN TELEGRAM
👍72
🎉 Unlock That 20% Pro Labs Discount! 🎉

Alright, hackers, here’s the deal: Hack The Box Pro Labs just got REAL! 💥 If you’re ready to leave the beginner stuff in the dust and dive into legit red team missions, I’ve got an exclusive 20% off waiting for you. But here’s the catch – only 100 of you can snag this deal. 👀

💥 Use code:
brutsecurityprolabs20

at checkout for 20% off the annual Pro Labs subnoscription! It’s high-level hacking in real enterprise environments. Ready to go pro? 🕶️

🔗Checkout Here - https://hackthebox.com/hacker/pro-labs

Jump on this quick – or you might miss the boat. 🚤💨 #HackTheBox #LevelUp #ProLabs
👍51
Get HoF & Thanks by reporting issues: https://cyfare.net/apps/vdp/
1
This media is not supported in your browser
VIEW IN TELEGRAM
🔍 gitlab-subdomains - A Go-based tool to uncover subdomains via GitLab searches.

🔗https://github.com/gwen001/gitlab-subdomains
7👍2
⚡️Zzl - A powerful reconnaissance tool for subdomain discovery through SSL certificates.

Key Feature:
Zzl scans IP ranges and extracts subdomains from SSL certificates, making it an essential tool for thorough reconnaissance and security research.

☄️https://github.com/DEMON1A/zzl
Please open Telegram to view this post
VIEW IN TELEGRAM
113
Find open redirect vulnerabilities with gf
By @ofjaaah

🚫Here’s a cool one-liner to help find open redirect vulnerabilities. All you need is to provide the target domain name:

echo "tesla.com" | waybackurls | httpx -silent -timeout 2 -threads 100 | gf redirect | anew


🔵This is what the command does in detail:
1. Collect all URLs of the target domain from the Wayback Machine
2. Attempt to download all the URLs quickly in 100 parallel threads in order to identify working URLs
3. For all working URLs, match any potentially vulnerable parameters to open redirect
4. Print out only unique, potentially vulnerable URLs
Please open Telegram to view this post
VIEW IN TELEGRAM
13👍4🔥2
It's a request to everyone, do give reaction on the post, it helped me to stay motivated and to post content like this.🥸

For queries do reach me out from channel bio. Thanks Everyone!
🚫
Please open Telegram to view this post
VIEW IN TELEGRAM
👍3611🔥8
🚫Add the file appsettings.jsont to your wordlist, and you might discover some juicy data. Enjoy! @NoRed0x
Please open Telegram to view this post
VIEW IN TELEGRAM
👍13
🔖 JShunter - A command-line tool for analyzing JavaScript files and extracting valuable endpoints.

Key Features:
JShunter specializes in uncovering sensitive data like API endpoints and spotting potential security vulnerabilities, making it indispensable for developers and security researchers.

🔗 https://github.com/cc1a2b/jshunter
👍121🔥1
🚨CVE-2024-35286 & CVE-2024-41713:Critical Mitel MiCollab Flaw Exposes Systems to Unauthorized File and Admin Access

🔥PoC: https://github.com/watchtowrlabs/Mitel-MiCollab-Auth-Bypass_CVE-2024-41713

👇Dorks
HUNTER:/product.name="Mitel MiCollab"
SHODAN: http.favicon.hash:-1922044295
FOFA: app="Mitel-Network-Products"
👍15
🚨Free Bug Bounty Complete Course!

Learn Bug Bounty to identify and report System vulnerabilities.

🔗https://drive.google.com/drive/mobile/folders/1t-hTqg0-02t0cnc5SypHnb8t3CfE3bXU
22👍6🔥5🗿4
🤨5🗿3👍21
All Dorks.txt
5.1 KB
Dorks List
8🔥3👍2
🔖Subhunter - A fast subdomain takeover tool


📱Github: https://github.com/umutcamliyurt/Subhunter
Please open Telegram to view this post
VIEW IN TELEGRAM
17👍3🔥2
CVE-2024-55579, -55580: RCE and Broken Access Control in Qlik Sense, 7.5 - 8.8 rating❗️

Vulnerabilities discovered in Qlik Sense allow attackers to run EXE files on the server, as well as remotely execute commands, potentially affecting confidentiality and integrity.

Search at Netlas.io:
👉 Link: https://nt.ls/9ok2E
👉 Dork: http.noscript:"Qlik Sense"

Vendor's advisory: https://community.qlik.com/t5/Official-Support-Articles/High-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows-CVEs/tac-p/2496004
👍8
CENT Tool

Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one place.

📱 CENT Tool 📱
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥64👍4