Brut Security – Telegram
Brut Security
14.6K subscribers
904 photos
72 videos
287 files
958 links
Queries: @wtf_brut
🛃WhatsApp: wa.link/brutsecurity
🈴Training: brutsec.com
📨E-mail: info@brutsec.com
Download Telegram
👻uro 1.0.2 is now out

https://github.com/s0md3v/uro
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥10👍5
Need an extensive SQL injection cheat sheet for bug bounty hunting and pentesting in general? 🧐

Check out @0xTib3rius' SQL Injection cheat sheet, it provides payloads for the 5 most popular databases such as MySQL, PostgreSQL, Oracle, etc.! 😎

🔗 buff.ly/3WeSO5X
👏13👍6
This media is not supported in your browser
VIEW IN TELEGRAM
urlhunter: A recon tool that allows searching on URLs that are exposed via shortener services

Link:
https://github.com/utkusen/urlhunter
🔥18👍32🤝2
CVE-2025-26794: SQL Injection in Exim 4.98, 7.5 rating❗️

A vulnerability in the Exim mail transfer agent could allow a remote attacker to perform SQL injection.

Search at Netlas.io:
👉 Link: https://nt.ls/ge4Iy
👉 Dork: smtp.banner:"Exim 4.98"

Vendor's advisory: https://www.exim.org/static/doc/security/CVE-2025-26794.txt
🔥35👍10🐳1
Don't forget to react guys 😢
🔥45👍7🗿4😁3🤣3
👻👻URL's Manipulation 4 Reconnaissance

🔥30 ways to gather information about the target domain just by adding different words to URL.

🛡https://osintteam.blog/urls-osint-bf5c9b087455
Please open Telegram to view this post
VIEW IN TELEGRAM
👍14🔥3🐳1🗿1
CVE-2025-1128: RCE in Everest Forms WordPress Plugin, 9.8 rating 🔥

The vulnerability allows an unauthenticated attacker to perform a wide range of actions with the site: upload arbitrary files, RCE, delete config files.

Search at Netlas.io:
👉 Link: https://nt.ls/q6pgJ
👉 Dork: http.body:"plugins/everest-forms"

Read more: https://www.wordfence.com/blog/2025/02/100000-wordpress-sites-affected-by-arbitrary-file-upload-read-and-deletion-vulnerability-in-everest-forms-wordpress-plugin/
🔥11👍1
👻👻👻Lenovo XSS via Unrestricted File Upload PoC---> https://news.1rj.ru/str/brutsecurity_poc/42
Please open Telegram to view this post
VIEW IN TELEGRAM
🗿3
👻👻 A search engine for CTF writeups
🛡https://ctfsearch.hackmap.win/
Please open Telegram to view this post
VIEW IN TELEGRAM
1028👍6
𝗚𝗮𝗺𝗲 𝗼𝗳 𝗔𝗰𝘁𝗶𝘃𝗲 𝗗𝗶𝗿𝗲𝗰𝘁𝗼𝗿𝘆

👻👻GOAD is a pentest active directory LAB project. This lab aims to give pentesters a vulnerable AD environment ready to use to practice usual attack techniques.

🔥https://github.com/Orange-Cyberdefense/GOAD
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥17👍72
👻👻SpoofProof helps security professionals detect email domain spoofing vulnerabilities and validate DMARC, SPF, and DKIM configurations, making email security assessments seamless and efficient.

Extension Name: SpoofProof - Domain Spoofing Validation

🔗 BApp Store:
https://portswigger.net/bappstore/a321360c6e114b3dab6f2c67d68c241a
💻 Source Code:
https://github.com/portswigger/spoofproof
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥206👍4🤨2
Don't forget to react guys 😔
Please open Telegram to view this post
VIEW IN TELEGRAM
🗿21🔥10👍6👏4🐳2🤣1🫡1
🤣86🐳81😁1👨‍💻1
CVE-2025-20029: Command Injection in F5 BIG-IP, 8.8 rating❗️

The vulnerability allows an attacker to escalate privileges, execute arbitrary commands, and manipulate system files. Not the latest vulnerability, but the PoC was published just recently!

Search at Netlas.io:
👉 Link: https://nt.ls/e17gN
👉 Dork: http.headers.server:"BigIP"

Vendor's advisory: https://my.f5.com/manage/s/article/K000148587
👍73😱2
CVE-2025-24752: XSS in Elementor Page Builder, 7.1 rating❗️

Reflected XSS in a large number of sites. Thanks to our friend Chirag Artani for suggesting the query!

Search at Netlas.io:
👉 Link: https://nt.ls/8wpei
👉 Dork: http.body:"plugins/elementor" AND host_type:domain

Read more: https://patchstack.com/articles/reflected-xss-patched-in-essential-addons-for-elementor-affecting-2-million-sites/
4👍3