brutecat Profile Banner
skull Profile
skull

@brutecat

Followers
3K
Following
319
Media
10
Statuses
193

hacker, security researcher. i run a blog @ https://t.co/cBW6gzTpV2

Singapore
Joined October 2024
Don't wanna be here? Send us removal request.
@brutecat
skull
6 days
TubeVault puts together the discoveries made by a niche but dedicated community who have worked hard to discover and document the early beginnings of YouTube, often relying on clever and unconventional methods as well as lots of investigative work.
0
0
5
@grok
Grok
3 days
Join millions who have switched to Grok.
162
191
1K
@brutecat
skull
6 days
"Me at the zoo" is widely known as the first video ever uploaded to YouTube. But did you know that Jawed has 17 other deleted videos?. You can see them here at
Tweet media one
3
4
26
@brutecat
skull
2 months
My channel has been restored! Thank you to everyone who supported me during this process, especially @GoogleVRP for the help in bring the channel back.
youtube.com
Security researcher
@brutecat
skull
2 months
Are you seriously kidding me? There's only 3 videos on this channel, all of which are @GoogleVRP PoCs. @TeamYouTube
Tweet media one
7
4
99
@brutecat
skull
2 months
Are you seriously kidding me? There's only 3 videos on this channel, all of which are @GoogleVRP PoCs. @TeamYouTube
Tweet media one
23
8
223
@brutecat
skull
2 months
RT @TechCrunch: Google fixes bug that could reveal users' private phone numbers | TechCrunch
Tweet card summary image
techcrunch.com
The bug allowed a researcher to uncover recovery phone numbers of nearly any Google account.
0
16
0
@brutecat
skull
2 months
RT @WIRED: Phone numbers are a goldmine for SIM swappers. A researcher found how to get this precious piece of information through a clever….
Tweet card summary image
wired.com
Phone numbers are a gold mine for SIM swappers. A researcher found how to get this precious piece of information through a clever brute-force attack.
0
16
0
@brutecat
skull
3 months
It used to be possible to leak the EXIF data of any Google user's profile picture by adding "=ip" to the end of the image URL, until recently when this got patched. No, Google does not strip EXIF when you upload a profile picture to your Google account. .
55
5
90
@brutecat
skull
3 months
This form, just like all their other jank forms, even let's you appeal bans for other people's channels you don't own lol.
1
1
22
@brutecat
skull
3 months
Not many people know this, but YouTube only lets you appeal a banned channel via YT Studio once, and that decision is "final". However, their old form ( lets you make a new appeal every 2 weeks. After enough appeals you will eventually be unbanned lol.
6
4
80
@brutecat
skull
6 months
The discovery document was removed from both as well as Thankfully, I do have both documents archived as I was tracking changes in them. I'll likely open source these along with my next YouTube exploit disclosure! :).
2
0
16
@brutecat
skull
6 months
Google just removed the staging InnerTube discovery documents. This is quite unfortunate as you could previously leak upcoming changes/updates to YouTube as well as new endpoints through this.
Tweet media one
4
2
59
@brutecat
skull
6 months
I've seen a lot of discussion about what the impact of an email address leak is. Here's my thoughts:.- Many valuable but inactive accounts are on expired domains or old yahoo emails. Attackers can claim these domains, set up forwarding, or recreate deleted emails - then use.
3
1
34
@brutecat
skull
6 months
i figured they didn't like the email address visible on the vid. reuploaded it but blurred it this time, let's see if it stays up lmao.
0
0
103
@brutecat
skull
6 months
??? @TeamYouTube . This is a video of a publicly disclosed Google VRP writeup.
Tweet media one
23
33
795
@brutecat
skull
7 months
Google just removed comments for over ~2219 objects from the staging-people-pa discovery document today. All removed comments:.
Tweet media one
1
1
11