Brut Security – Telegram
Brut Security
14.6K subscribers
909 photos
73 videos
287 files
966 links
Queries: @wtf_brut
🛃WhatsApp: wa.link/brutsecurity
🈴Training: brutsec.com
📨E-mail: info@brutsec.com
Download Telegram
🌟 FREE Exam Voucher ISC2 CC 🌟

Exam Voucher: CC1M12312024

Link https://www.isc2.org/landing/1mcc
5
🚨Subprober🚨

👉Subprober is a powerful and efficient subdomain scanning tool👈

📥 https://github.com/sanjai-AK47/Subprober
👍7🔥2
🌟Dons Js Scanner🌟

👉Dons Js Scanner is a Python tool designed by Ali Essam to scan websites and uncover potential sensitive information within JavaScript files. It utilizes asynchronous programming for efficient web crawling and in-depth analysis.Dons Js Scanner is a Python tool designed by Ali Essam to scan websites and uncover potential sensitive information within JavaScript files. It utilizes asynchronous programming for efficient web crawling and in-depth analysis.

👉https://github.com/dragonked2/Dons
7👏3👍1🔥1😁1
This media is not supported in your browser
VIEW IN TELEGRAM
𝐄𝐱𝐩𝐥𝐨𝐢𝐭𝐢𝐧𝐠 𝐑𝐚𝐜𝐞 𝐂𝐨𝐧𝐝𝐢𝐭𝐢𝐨𝐧𝐬 𝐮𝐬𝐢𝐧𝐠 𝐁𝐮𝐫𝐩 𝐑𝐞𝐩𝐞𝐚𝐭𝐞𝐫 𝐆𝐫𝐨𝐮𝐩𝐬 👇

Race condition vulnerabilities abuse the server's (improper) way of handling concurrent requests.

These vulnerabilities can be used to perform limit-overrun attacks such as:
- using the same gift card multiple times
- redeeming the same coupon code
- bypassing a shop's quantity limits (nvidia video cards 😉)

How to check for race condition vulns

1. Find the request that triggers the server-side check
2. Create a new tab group in Repeater
3. Add the same request multiple times to the group (CTRL+R)
4. Select "Send group in parallel"
5. Run the attack
6. Check if more than one response is valid

*
Credit- Andrei Agape

Lab: https://portswigger.net/web-security/race-conditions/lab-race-conditions-limit-overrun

Article: https://portswigger.net/research/smashing-the-state-machine
8👍6🔥4
🤑Bug Bounty Tips for SSRF🤑

Step 1: Subdomain Enumeration

•DNS Dumpster
•Sublist3r
•Amass
•Google Dorking
•Certificate Transparency Logs
•subdomainer

Step 2: Find Live Domains

cat all-domains.txt | httpx > all-live.txt

Step 3: Identify All URLs

cat all-live.txt | gauplus -subs -b png,jpg,gif,jpeg,swf,woff,gif,noscript -o allUrls.txt

Step 4: Injection Burp Collaborator URL in Parameters

cat /home/casperino/tools/nuclei/httpx.txt | grep "=" | ./qsreplace 40ga7gynfy6pcg06ov.oastify.com > ssrf.txt

Step 5: Test for SSRF Vulnerabilities

cat ssrf.txt | httpx -fr

Step 6: How to check which URL is vulnerable

split -l 10 ssrf.txt output_file_
27👍10🔥7
🔴Easy Open Redirect in 10 min🔴
17🔥2👍1