BLACKFRIDAY2024 SALE: Get all of our malware development and red teaming courses bundle for only $199.
❌$400
✅$199
Start your new year with developing malware and building offensive tools
redteamsorcery.teachable.com/p/learnthemall
❌$400
✅$199
Start your new year with developing malware and building offensive tools
redteamsorcery.teachable.com/p/learnthemall
🤨3👍2❤1
CVE-2024-11274, -8233, other: Multiple vulnerabilities in GitLab, 7.5 - 8.7 rating❗
In a new release, GitLab talked about two important vulnerabilities. One of them allows attacker to carry out DoS, the second allows to steal session data and potentially gain unauthorized access to accounts. Several smaller vulnerabilities are also mentioned.
Search at Netlas.io:
👉 Link: https://nt.ls/xM1vs
👉 Dork: http.favicon.hash_sha256:72a2cad5025aa931d6ea56c3201d1f18e68a8cd39788c7c80d5b2b82aa5143ef OR http.headers.set_cookie:"gitlab" OR http.headers.location:"gitlab"
Vendor's advisory: https://about.gitlab.com/releases/2024/12/11/patch-release-gitlab-17-6-2-released/
In a new release, GitLab talked about two important vulnerabilities. One of them allows attacker to carry out DoS, the second allows to steal session data and potentially gain unauthorized access to accounts. Several smaller vulnerabilities are also mentioned.
Search at Netlas.io:
👉 Link: https://nt.ls/xM1vs
👉 Dork: http.favicon.hash_sha256:72a2cad5025aa931d6ea56c3201d1f18e68a8cd39788c7c80d5b2b82aa5143ef OR http.headers.set_cookie:"gitlab" OR http.headers.location:"gitlab"
Vendor's advisory: https://about.gitlab.com/releases/2024/12/11/patch-release-gitlab-17-6-2-released/
👍4🤨2
Please open Telegram to view this post
VIEW IN TELEGRAM
GitHub
GitHub - mrmtwoj/apache-vulnerability-testing: Apache HTTP Server Vulnerability Testing Tool | PoC for CVE-2024-38472 , CVE-2024…
Apache HTTP Server Vulnerability Testing Tool | PoC for CVE-2024-38472 , CVE-2024-39573 , CVE-2024-38477 , CVE-2024-38476 , CVE-2024-38475 , CVE-2024-38474 , CVE-2024-38473 , CVE-2023-38709 - mrmt...
❤10👍2
Please open Telegram to view this post
VIEW IN TELEGRAM
❤10🔥4👍1
🔖 Dnsbruter - A powerful tool for active subdomain enumeration and discovery.
✨ Features:
Dnsbruter uses DNS resolution to bruteforce and identify subdomains efficiently. Its multithreading capability allows users to control concurrency for faster and more effective results. Perfect for researchers and pen testers targeting domain reconnaissance.
🔗 https://github.com/RevoltSecurities/Dnsbruter/
✨ Features:
Dnsbruter uses DNS resolution to bruteforce and identify subdomains efficiently. Its multithreading capability allows users to control concurrency for faster and more effective results. Perfect for researchers and pen testers targeting domain reconnaissance.
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥12👍4
Please open Telegram to view this post
VIEW IN TELEGRAM
👍11❤3
CVE-2024-38819: Path Traversal in Spring Framework, 7.5 rating❗️
Another Path Traversal vulnerability in the Spring framework. This time there is even a PoC!
Search at Netlas.io:
👉 Link: https://nt.ls/AzCtg
👉 Dork: tag.name:"spring"
Vendor's advisory: https://spring.io/security/cve-2024-38819
Another Path Traversal vulnerability in the Spring framework. This time there is even a PoC!
Search at Netlas.io:
👉 Link: https://nt.ls/AzCtg
👉 Dork: tag.name:"spring"
Vendor's advisory: https://spring.io/security/cve-2024-38819
👍6❤3
Please open Telegram to view this post
VIEW IN TELEGRAM
🐳13🗿8👍3🤨2
🔖 IVRE - The Ultimate Network Reconnaissance Framework
✨ Key Features:
IVRE allows you to build your self-hosted, fully controlled alternatives to tools like Shodan, ZoomEye, Censys, and GreyNoise.
- Run your Passive DNS service
- Create tailor-made EASM tools
- Collect and analyze network intelligence using Nmap, Masscan, Zeek, p0f, ProjectDiscovery tools, and more!
Perfect for security researchers and network analysts.
🔗 Get the tool here: https://github.com/ivre/ivre
✨ Key Features:
IVRE allows you to build your self-hosted, fully controlled alternatives to tools like Shodan, ZoomEye, Censys, and GreyNoise.
- Run your Passive DNS service
- Create tailor-made EASM tools
- Collect and analyze network intelligence using Nmap, Masscan, Zeek, p0f, ProjectDiscovery tools, and more!
Perfect for security researchers and network analysts.
🔗 Get the tool here: https://github.com/ivre/ivre
GitHub
GitHub - ivre/ivre: Network recon framework. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye…
Network recon framework. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye / Censys and GreyNoise, run your Passive DNS service, build your taylor-made EASM tool, co...
👍4
🎄 Wrapping Up an Amazing Year Together! 🎄
Hey Brut Fam! 🚀As 2024 comes to a close, I want to thank each and every one of you for being part of this amazing journey. This year, we’ve shared 1,500+ resources, learned, grown, and built an incredible community of 8,000+ members. Your support and engagement have made Brut Security what it is today. 💪
If you’ve found value in the resources I’ve shared and want to support me in continuing this journey, you can now buy me a coffee ☕ here:
☄️ https://buymeacoffee.com/saumadip
It’s not mandatory—just a small way to show appreciation if you feel like it.
Wishing you all a early very Merry Christmas 🎅 and a Happy New Year 🎉 filled with learning, growth, and success! Here’s to an even bigger and better 2025! 🚀
Stay curious, stay secure. 🔐
Hey Brut Fam! 🚀As 2024 comes to a close, I want to thank each and every one of you for being part of this amazing journey. This year, we’ve shared 1,500+ resources, learned, grown, and built an incredible community of 8,000+ members. Your support and engagement have made Brut Security what it is today. 💪
If you’ve found value in the resources I’ve shared and want to support me in continuing this journey, you can now buy me a coffee ☕ here:
It’s not mandatory—just a small way to show appreciation if you feel like it.
Wishing you all a early very Merry Christmas 🎅 and a Happy New Year 🎉 filled with learning, growth, and success! Here’s to an even bigger and better 2025! 🚀
Stay curious, stay secure. 🔐
Please open Telegram to view this post
VIEW IN TELEGRAM
❤3👍3👨💻2🔥1🐳1
Brut Security pinned «🎄 Wrapping Up an Amazing Year Together! 🎄 Hey Brut Fam! 🚀As 2024 comes to a close, I want to thank each and every one of you for being part of this amazing journey. This year, we’ve shared 1,500+ resources, learned, grown, and built an incredible community…»