Brut Security – Telegram
Brut Security
14.8K subscribers
919 photos
73 videos
287 files
974 links
Queries: @wtf_brut
🛃WhatsApp: wa.link/brutsecurity
🈴Training: brutsec.com
📨E-mail: info@brutsec.com
Download Telegram
☄️ Exciting News for Aspiring Bug Hunters! ☄️

💥 Starting at the end of September, our Bug Bounty Course is designed to transform you from a beginner to a professional bug hunter. Learn the ins and outs of bug bounty hunting, including XSS, SQL Injection, and more. With 40 hours of live, online training, you'll gain the skills needed to identify and ethically report security flaws.
Don't miss this opportunity to boost your cybersecurity career!
📱 https://wa.link/7j7p6g
Please open Telegram to view this post
VIEW IN TELEGRAM
If you're new to bug bounty, you should not learn recon.
👍122
Recently found a SAML vulnerability, any website that allows users to configure SAML also takes a x509 certificate as input there will be an implicit trust between IDP and SP. (You can easily perform an account takeover via using your own x509 cert, Signed saml response with the victim's email)
🔥5
Also SAML can be used for session hijacking/login csrf

- User is entering his credit card details while attacker's site is open
- Attacker swaps the session using SAML session hijacking and now card details will be saved in attacker's account
🔥41
Brut Security pinned «💥Join Our Bugbounty Discussion Group 💥 🔥https://news.1rj.ru/str/brutsec🔥 🤖https://discord.gg/GZBsQMY6🤖»
💥Join Our Discussion Group 💥
🔥 https://news.1rj.ru/str/brutsec 🔥
🤖 https://discord.gg/GZBsQMY6 🤖
Please open Telegram to view this post
VIEW IN TELEGRAM
2👍2
FFUF Web Parser is a web-based tool built using React and Node.js that allows users to upload FFUF JSON files, apply a variety of filters, and export the filtered results to an Excel file. The tool supports filtering based on status codes, response data, lines, length, and URLs (including regex filtering). It also provides the ability to view, manipulate, and extract valuable information from FFUF fuzzing results.

🔗
https://github.com/VikzSharma/ffufwebparser
👍62
CVE-2024-37288, -37285: RCE in Kibana, 9.9 rating 🔥🔥🔥

By improperly deserializing YAML, attackers can perform RCE. The attack is quite complex, but Elastic still recommends updating.

Search at Netlas.io:
👉 Link: https://nt.ls/cVF9O
👉 Dork: http.favicon.hash_sha256:30db4185530d8617e9f08858787a24b219ac5102321b48515baf5da7ac43b590

Read more: https://securityonline.info/critical-kibana-flaws-cve-2024-37288-cve-2024-37285-expose-systems-to-arbitrary-code-execution/
👍31
🗿13🔥4🐳31
Awesome Shodan Dorks
7👍1
CVE-2024-29847 and other: Multiple vulns in Ivanti EPM, 4.3 - 10.0 rating 🔥🔥🔥

Numerous vulnerabilities in Ivanti. Includes, but is not limited to, RCE with the highest severity score!

Search at Netlas.io:
👉 Link: https://nt.ls/pHqay
👉 Dork: http.headers.set_cookie:("JSESSIONID" "Path" "/mifs")

Vendor's advisory: https://forums.ivanti.com/s/article/Security-Advisory-EPM-September-2024-for-EPM-2024-and-EPM-2022?language=en_US
👍21
Add the file configurations.xml to your wordlist.
Credit- @NoRed0x

#bugbountytips #bugbountytip
🔥5
Add to your wordlist:

auth/jwt/register
auth-demo/register/classic
auth-demo/register/modern
🔥31
🚀 Shodan Search Dorks
👍41
☄️ Common Open Redirection Parameters ☄️
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥10👍1
🐳54
Forwarded from Netlas.io
Reminder: The update begins in one hour. Netlas will be temporarily offline. We apologize for any inconvenience caused.
Brut Security pinned Deleted message