Brut Security – Telegram
Brut Security
14.6K subscribers
904 photos
72 videos
287 files
958 links
Queries: @wtf_brut
🛃WhatsApp: wa.link/brutsecurity
🈴Training: brutsec.com
📨E-mail: info@brutsec.com
Download Telegram
Dropping Soon
🔥135
BrutDroid 2.0 is a powerful, Windows-optimized toolkit designed specifically for Android Studio, streamlining the setup of a mobile penetration testing lab. Built to make Android pentesting effortless, it automates emulator creation, rooting, Frida server setup, and Burp Suite certificate installation. With a vibrant new UI and support for custom Frida noscripts, BrutDroid empowers security researchers to focus on testing, not setup. Linux support is coming soon!

https://github.com/Brut-Security/BrutDroid

Don't forget to leave a star :)
31🔥2
Brut Security pinned «Full Walkthrough - https://youtu.be/bDxgilaYcE8»
Forwarded from Bug Bounty POC's
Asset inventory of over 800 public bug bounty programs.
https://github.com/trickest/inventory
8👍6
Another one made it. You still watching reels?
27🗿8🤔4🤝1
CVE-2025-53770: Deserialization of Untrusted Data in Microsoft SharePoint, 9.8 rating 🔥

The most high-profile recent vulnerability allows an attacker to perform RCE on a Microsoft SharePoint server. Hackers are already exploiting it, so be careful!

Search at Netlas.io:
👉 Link: https://nt.ls/Ix8gb
👉 Dork: http.headers.microsoftsharepointteamservices:*

Vendor's advisory: https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/
🔥113
2 Seats Left! Enroll Now 😎
Forwarded from Brut Security
🚨 New Batch Starting – August 2025 🚨
Brut Practical Web Penetration Testing (bPWP)

We’re back with a fresh batch of our most in-demand training – Brut Practical Web Penetration Testing – starting this August!

🔍 Learn the art of Web Hacking with:
100% Practical Sessions
Bug Bounty Approach
Real-World Lab Scenarios
Lifetime Community Access
Beginner-Friendly with Advanced Techniques

💻 Ideal for aspiring bug bounty hunters, cybersecurity students, and VAPT professionals.

📆 Limited Seats – Enroll Now
🌐
https://brutsec.com/bPWP

📩 For Queries:
Telegram:
@wtf_brut
WhatsApp:
https://wa.link/brutsecurity | +918945971332
Email:
info@brutsec.com
5
Chrome and Firefox extension that lists Amazon S3 Buckets while browsing

🚨Features:
Filters S3Buckets
Extract ACL permissions
Download recorded buckets
Manage recorded buckets
Tab-specific bucket recording

https://github.com/AlecBlance/S3BucketList
🔥164
PACU - The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

https://github.com/RhinoSecurityLabs/pacu
13🔥8
CYFARE-Reconner - Advanced Link Reconnaissance Extension For Firefox

Features
Deep Discovery
Secret Detection
URL Analysis

https://github.com/CYFARE/CYFARE-Reconner
12👍2
Akamai CloudTest - XXE Injection

Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection through the /concerto/services/RepositoryService SOAP endpoint.

Get: https://github.com/MuhammadWaseem29/CVE-2025-49493-Poc

References:
1. https://xbow.com/blog/xbow-akamai-cloudtest-xxe/
2. https://techdocs.akamai.com/cloudtest/changelog/june-2-2025-enhancements-and-bug-fixes
🔥54
😥
🗿20😁10🔥6👍3😱3🫡3🐳2
Looking for a freelancer, familiar with FB, Instagram and Whatsapp marketing.

Send your resume to info@ncybersecurity.com
🚨CVE-2025-0133 : Payload + Template

Payload: %3Cnoscript%20xmlns%3D%22http%3A%2F%http://2Fwww.w3.org%2F2000%2Fnoscript%22%3E%3Cnoscript%3Eprompt%28%22XSS%22%29%3C%2Fnoscript%3E%3C%2Fnoscript%3E

Write-up: https://codewithvamp.medium.com/cve-2025-0133-reflected-xss-vulnerability-in-palo-alto-globalprotect-gateway-portal-028128f2f5b9

Template: https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-0133.yaml
7👍4
Bug Bounty Tip: HTTP Parameter Pollution (HPP)

Some apps mishandle duplicate parameters. You can bypass logic or elevate privileges by injecting multiple values:

GET /transfer?amount=100&admin=true&amount=1

⚠️ Always test:
•param=value1&param=value2
•Encoded (%26,)
20