Brut Security – Telegram
Brut Security
14.7K subscribers
919 photos
73 videos
287 files
974 links
Queries: @wtf_brut
🛃WhatsApp: wa.link/brutsecurity
🈴Training: brutsec.com
📨E-mail: info@brutsec.com
Download Telegram
Try something like "© [COMPANY]. All rights reserved." to find new root domains!
👍9
CVE-2024-33533, -33535, -33536: Multiple vulns in Zimbra, 5.4 - 7.5 rating❗️

The vulnerabilities could allow an attacker to perform path traversal or create XSS injection, which could compromise sensitive data.

Search at Netlas.io:
👉 Link: https://nt.ls/0aGwL
👉 Dork: http.favicon.hash_sha256:1afd891aacc433e75265e3ddc9cb4fc63b88259977811384426c535037711637 OR \*.banner:"Zimbra"

Vendor's advisory: https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.8#Security_Fixes
👍42
👍2
😐Hello Everyone 😐

🚬It's been a long time & I hope everyone is well. I have not posted anything from past few days. Let me know what you're looking for in the comments.

🗒If you're looking for course enrollments, do DM here- Whatsapp
Please open Telegram to view this post
VIEW IN TELEGRAM
☄️Use Burpsuite like Pro by @daffainfo

⚡️Match and Replace Feature which is not known by many hunters or doesn't use it at all.

🔗https://github.com/daffainfo/match-replace-burp
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥1261👍1
Please open Telegram to view this post
VIEW IN TELEGRAM
😍21🔥1
Brut Security pinned «💥A collection of awesome one-liner noscripts especially for bug bounty💥 🔗https://github.com/dwisiswant0/awesome-oneliner-bugbounty»
Please open Telegram to view this post
VIEW IN TELEGRAM
2
Brut Security pinned «🔈Exposed Pinata API Key Nuclei Template 📎https://raw.githubusercontent.com/karkis3c/bugbounty/main/nuclei-templates/info-disclosure/pinata-keys-exposed.yaml»
☄️Collection of Links, Write-ups, Blog posts and Papers related to Cybersecurity, Reverse engineering and Exploitation☄️

🔖https://github.com/0xor0ne/awesome-list/blob/main/topics/cybersec.md
Please open Telegram to view this post
VIEW IN TELEGRAM
3🗿2😱1
👍61
What makes you hacker?🤨
Please open Telegram to view this post
VIEW IN TELEGRAM
Add the folder 'home/000~ROOT~000/' to your wordlist, and you might discover some juicy data. Enjoy!"
😭7👍5🔥5🤣21
👍3👏1
☄️If you have access to jenkins dashboard, use below Script Console cmd for poc☄️
def passwdFile = new File("/etc/passwd")
println passwdFile.text
Please open Telegram to view this post
VIEW IN TELEGRAM
96🔥2👍1
prv8_nuclei_templates.zip
3.9 MB
6000+ Private Nuclei Templates
❤‍🔥28🤣5👌211🔥1🤝1
CVE-2024-8073: Command Injection in Hillstone Networks Firewalls, 9.8 rating 🔥

The freshest vulnerability in Hillstone WAFs allows an attacker to perform RCE due to incorrect input validation.

Search at Netlas.io:
👉 Link: https://nt.ls/YZWqU
👉 Dork: http.noscript:"Hillstone Networks"

Vendor's advisory: https://www.hillstonenet.com.cn/security-notification/2024/08/21/mlzrld-2/
🔥5👍2🤣1
Telegram CEO is arrested, so there is a probability that telegram will end the services or it's services will be blocked on different countries. So as a backup you can join our discord channel. Thanks!
https://discord.gg/NTU2q8gU5K
🤣1