Brut Security – Telegram
Brut Security
14.6K subscribers
904 photos
72 videos
287 files
958 links
Queries: @wtf_brut
🛃WhatsApp: wa.link/brutsecurity
🈴Training: brutsec.com
📨E-mail: info@brutsec.com
Download Telegram
CENT Tool

Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one place.

📱 CENT Tool 📱
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥64👍4
☄️Here’s a list of tools to streamline your work with Google Dorks and other search engines:
dorki.io
taksec.github.io/google-dorks-bug-bounty/
dorksearch.com
dorkme.comdorkgenius.com
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥3
Brut Security Website is now live- Visit- https://brutsec.com/
👍14🗿3
Did you know that you can smuggle payloads in your email & phone number if incorrect validation is done!
🔥9👍3
Payloads for LFR/LFD ⚔️
file:/etc/passwd%3F/ 
file:/etc%252Fpasswd/
file:/etc%252Fpasswd%3F/
file:///etc/%3F/../passwd
file:${br}/et${u}c%252Fpas${te}swd%3F/
file:$(br)/et$(u)c%252Fpas$(te)swd%3F/
4👍4
BLACKFRIDAY2024 SALE: Get all of our malware development and red teaming courses bundle for only $199.

$400
$199

Start your new year with developing malware and building offensive tools

redteamsorcery.teachable.com/p/learnthemall
🤨3👍21
CVE-2024-11274, -8233, other: Multiple vulnerabilities in GitLab, 7.5 - 8.7 rating

In a new release, GitLab talked about two important vulnerabilities. One of them allows attacker to carry out DoS, the second allows to steal session data and potentially gain unauthorized access to accounts. Several smaller vulnerabilities are also mentioned.

Search at Netlas.io:
👉 Link: https://nt.ls/xM1vs
👉 Dork: http.favicon.hash_sha256:72a2cad5025aa931d6ea56c3201d1f18e68a8cd39788c7c80d5b2b82aa5143ef OR http.headers.set_cookie:"gitlab" OR http.headers.location:"gitlab"

Vendor's advisory: https://about.gitlab.com/releases/2024/12/11/patch-release-gitlab-17-6-2-released/
👍4🤨2
🗿13🔥74👍4
🐳6👍3
In the world of cybersecurity, there is no mercy—only the relentless pursuit of vulnerabilities. Hunt with precision, adapt with resilience, and remember: it’s hunt or be hunted. For those of us climbing to the top of the food chain, there can be no mercy—only one rule: hunt or be hunted.
Please open Telegram to view this post
VIEW IN TELEGRAM
10🔥4👍1
🔖 Dnsbruter - A powerful tool for active subdomain enumeration and discovery.

Features:
Dnsbruter uses DNS resolution to bruteforce and identify subdomains efficiently. Its multithreading capability allows users to control concurrency for faster and more effective results. Perfect for researchers and pen testers targeting domain reconnaissance.

🔗 https://github.com/RevoltSecurities/Dnsbruter/
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥12👍4
CRLF Injection Tips
Please open Telegram to view this post
VIEW IN TELEGRAM
👍113
CVE-2024-38819: Path Traversal in Spring Framework, 7.5 rating❗️

Another Path Traversal vulnerability in the Spring framework. This time there is even a PoC!

Search at Netlas.io:
👉 Link: https://nt.ls/AzCtg
👉 Dork: tag.name:"spring"

Vendor's advisory: https://spring.io/security/cve-2024-38819
👍63
⚡️SSRFUtility - SSRF Exploitation Tool
🔗 https://ssrf.cvssadvisor.com/
15
🤡🤡
Please open Telegram to view this post
VIEW IN TELEGRAM
🐳13🗿8👍3🤨2