đ xLeet Shell Uploader v2.1
Disclaimer: For educational purposes only.
By: Who Knows (https://t.me/Moonlightcrow)
Download : LINK
Disclaimer: For educational purposes only.
By: Who Knows (https://t.me/Moonlightcrow)
Download : LINK
đ Lufix Items Uploader v1.91
Disclaimer: For educational purposes only.
By: Who Knows (https://t.me/Moonlightcrow)
Download : Here
Disclaimer: For educational purposes only.
By: Who Knows (https://t.me/Moonlightcrow)
Download : Here
â¤5
đ DA / PA checker
Disclaimer: For educational purposes only.
By: Who Knows (https://t.me/Moonlightcrow)
Download : Here
Disclaimer: For educational purposes only.
By: Who Knows (https://t.me/Moonlightcrow)
Download : Here
đĨ°4
Media is too big
VIEW IN TELEGRAM
WP-Shell3r v0.2 â WordPress Shell Uploader
â Plugin/Direct/File Manager upload
â WAF & verification bypass
â Auto admin creation
â Async GUI + retry system
Site format: site#user@pass | site|user|pass
Trial version : here
Price : $70 / blackscriptx
đŠ @Moonlightcrow
â ī¸ Authorized use only
â Plugin/Direct/File Manager upload
â WAF & verification bypass
â Auto admin creation
â Async GUI + retry system
Site format: site#user@pass | site|user|pass
Trial version : here
Price : $70 / blackscriptx
đŠ @Moonlightcrow
â ī¸ Authorized use only
đĨ3
âĄī¸ SMTP Sentinel â High-performance async SMTP tester with real-time WebSocket dashboard. Test thousands of credentials simultaneously, track live progress, visualize results with interactive charts & export to CSV. Built with FastAPI + aiosmtplib. Fast, sleek & powerful.
đĨ Features:
âĸ Async testing (up to 200 concurrent)
âĸ Real-time WebSocket updates
âĸ Beautiful dark-themed UI
âĸ CSV export with timestamps
âĸ Auto SSL/TLS detection
Perfect for security testing & bulk SMTP validation.
install modules:
Download Link : Here
đĨ Features:
âĸ Async testing (up to 200 concurrent)
âĸ Real-time WebSocket updates
âĸ Beautiful dark-themed UI
âĸ CSV export with timestamps
âĸ Auto SSL/TLS detection
Perfect for security testing & bulk SMTP validation.
install modules:
pip install fastapi aiosmtplib uvicornDownload Link : Here
â¤2
WP Bruter
ââââââ
Fast WordPress credential scanner.
FEATURES
âĸ Auto-detects XML-RPC & wp-login attack surface
âĸ Enumerates real usernames per site
âĸ Smart password expansion â [user], [domain] tokens
âĸ Built-in combos tried automatically (admin@admin, domain+user, etc.)
âĸ High concurrency â scan hundreds of sites simultaneously
âĸ Early exit on first hit â no wasted attempts
âĸ Clean result files â hits saved instantly
HOW TO USE
1. Prepare site.txt â one URL per line
2. Prepare pass.txt â one password per line
3. Run wp-bruter.exe
4. Enter your files and concurrency when prompted
5. Check result\ folder for hits
RESULT FILES
result\wp-brute.txt â XML-RPC hits
result\wp-login.txt â wp-login hits
result\wordpress.txt â confirmed WP sites
PASSWORD TOKENS
[user] â replaced with the site's real username
[domain] â replaced with domain parts (example, shop, âĻ)
Example: [domain]@[user] â shop@admin
Telegram: https://t.me/Moonlightcrow
Download : WP-BRUTER
ââââââ
Fast WordPress credential scanner.
FEATURES
âĸ Auto-detects XML-RPC & wp-login attack surface
âĸ Enumerates real usernames per site
âĸ Smart password expansion â [user], [domain] tokens
âĸ Built-in combos tried automatically (admin@admin, domain+user, etc.)
âĸ High concurrency â scan hundreds of sites simultaneously
âĸ Early exit on first hit â no wasted attempts
âĸ Clean result files â hits saved instantly
HOW TO USE
1. Prepare site.txt â one URL per line
2. Prepare pass.txt â one password per line
3. Run wp-bruter.exe
4. Enter your files and concurrency when prompted
5. Check result\ folder for hits
RESULT FILES
result\wp-brute.txt â XML-RPC hits
result\wp-login.txt â wp-login hits
result\wordpress.txt â confirmed WP sites
PASSWORD TOKENS
[user] â replaced with the site's real username
[domain] â replaced with domain parts (example, shop, âĻ)
Example: [domain]@[user] â shop@admin
Telegram: https://t.me/Moonlightcrow
Download : WP-BRUTER
â¤3đĨ1đĨ°1đ1
WP-Shell3r v0.3 â WordPress Shell Uploader
â Plugin / Direct / File Manager / Plugin Editor upload
â WAF & email verification bypass
â Auto admin creation
â Async GUI + retry system
â Multi-format site list support
ââââââââââââââââââââ
đ Site List Formats
ââââââââââââââââââââ
site|user|pass
site:user:pass
site;user;pass
site/wp-login.php:user:pass
site/wp-login.php#user@pass
âĸ http:// optional â auto-added
âĸ Duplicates removed automatically
âĸ Encodings: UTF-8 / Latin-1 / CP1252
Trial version : here
ââââââââââââââââââââ
đ° Price: DM
đ @blackscriptx
đŠ Contact: @Moonlightcrow
ââââââââââââââââââââ
â ī¸ For authorized penetration testing only
â Plugin / Direct / File Manager / Plugin Editor upload
â WAF & email verification bypass
â Auto admin creation
â Async GUI + retry system
â Multi-format site list support
ââââââââââââââââââââ
đ Site List Formats
ââââââââââââââââââââ
site|user|pass
site:user:pass
site;user;pass
site/wp-login.php:user:pass
site/wp-login.php#user@pass
âĸ http:// optional â auto-added
âĸ Duplicates removed automatically
âĸ Encodings: UTF-8 / Latin-1 / CP1252
Trial version : here
ââââââââââââââââââââ
đ° Price: DM
đ @blackscriptx
đŠ Contact: @Moonlightcrow
ââââââââââââââââââââ
â ī¸ For authorized penetration testing only
â đŦ Mailer Tester â by Who Knows
Mass-test your Leaf PHPMailer panels in seconds.
â Paste 100s of mailer URLs â tested concurrently
đ Live stats: Done / Left / OK / Failed in real time
âĄī¸ Progress bar updates as each result comes in
âšī¸ Stop anytime with one click
đ Clean web UI â runs locally on your machine
Built with Python (FastAPI) + Chrome TLS impersonation
so servers can't fingerprint-block the requests.
How to run:
python main.py
â open http://localhost:8765
Link : here
đ https://t.me/Moonlightcrow
Mass-test your Leaf PHPMailer panels in seconds.
â Paste 100s of mailer URLs â tested concurrently
đ Live stats: Done / Left / OK / Failed in real time
âĄī¸ Progress bar updates as each result comes in
âšī¸ Stop anytime with one click
đ Clean web UI â runs locally on your machine
Built with Python (FastAPI) + Chrome TLS impersonation
so servers can't fingerprint-block the requests.
How to run:
pip install -r requirements.txtpython main.py
â open http://localhost:8765
Link : here
đ https://t.me/Moonlightcrow
đĨ1
xleet-main.py
34.2 KB
đ xLeet Shell Uploader v3.0
GUI tool for mass-uploading shells to xLeet
Features:
âĸ đĒ JSON Cookie Loader â paste exported browser cookies, tokens auto-extracted
âĸ âĄī¸ Multi-threaded uploads â configurable worker count (1â20)
âĸ đ° Price control â set min/max range or randomize per shell
âĸ đ Auto-retry â exponential backoff, skips 4xx auth errors instantly
âĸ âī¸ Persistent settings â URL, tokens, performance saved between sessions
âĸ đ Clean stop â non-blocking cancel, saves progress
âĸ đ Live stats â success / failed / remaining counters
âĸ đ§ Configurable domain â change target URL without editing code
@Moonlightcrow
GUI tool for mass-uploading shells to xLeet
Features:
âĸ đĒ JSON Cookie Loader â paste exported browser cookies, tokens auto-extracted
âĸ âĄī¸ Multi-threaded uploads â configurable worker count (1â20)
âĸ đ° Price control â set min/max range or randomize per shell
âĸ đ Auto-retry â exponential backoff, skips 4xx auth errors instantly
âĸ âī¸ Persistent settings â URL, tokens, performance saved between sessions
âĸ đ Clean stop â non-blocking cancel, saves progress
âĸ đ Live stats â success / failed / remaining counters
âĸ đ§ Configurable domain â change target URL without editing code
pip install PySide6 requests brotli@Moonlightcrow
â¤1
CVE-2026-48907.py
15.1 KB
đĨ CVE-2026-48907 â JCE Joomla Unauthenticated RCE Scanner
Exploit for the JCE (JoomlaContentEditor) plugin remote code execution vulnerability.
âī¸ Features:
âĸ Async engine (aiohttp) â high concurrency, low overhead
âĸ Auto CSRF token extraction
âĸ Multi-payload strategy (direct .php + GIF rename bypass)
âĸ Only saves CONFIRMED shells (PHP code actually executes)
âĸ Results saved to: joom-shell.txt
đ Usage:
python CVE-2026-48907.py
â Enter targets file & concurrency
=> Who Knows
đĸ Channel : https://t.me/Moonlightcrow
For educational and authorized testing only.
Exploit for the JCE (JoomlaContentEditor) plugin remote code execution vulnerability.
âī¸ Features:
âĸ Async engine (aiohttp) â high concurrency, low overhead
âĸ Auto CSRF token extraction
âĸ Multi-payload strategy (direct .php + GIF rename bypass)
âĸ Only saves CONFIRMED shells (PHP code actually executes)
âĸ Results saved to: joom-shell.txt
đ Usage:
pip install aiohttp aiofiles coloramapython CVE-2026-48907.py
â Enter targets file & concurrency
=> Who Knows
đĸ Channel : https://t.me/Moonlightcrow
For educational and authorized testing only.
â¤2