BugCod3
7.27K subscribers
333 photos
6 videos
7 files
442 links
[ BugCod3 ] β€” From Shadows To Shells ⚑️

πŸ•Ά Hacking | 🐞 Bug Bounty | πŸ” Security Tools
βš”οΈ Learn β€’ Hunt β€’ Dominate

πŸ‘₯ Group: T.me/BugCod3GP
πŸ“‚ Topic: T.me/BugCod3Topic

🌐 Web: BugCod3.com
πŸ€– Contact: T.me/BugCod3BOT
πŸ“§ Email: BugCod3@protonmail.com
Download Telegram
Mirai DDoS source with botnet and all tools and peripherals for sale, urgent sale

To Buy: T.me/BugCod3BOT
πŸ”₯7
RFC-compliant payloads for email and phone number fields

#RFC #Payload
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
❀4πŸ”₯4⚑2
Burp Suite MCP Server Extension with scan and crawl features

πŸ’¬
This an extended MCP Server Extension for BurpSuite proxy with scan and crawl based on the original.
For Building instructions follow below the original README as provided from PortSwigger, for direct use, load the extension provided on your Burp proxy.

πŸ“Š Features:
βšͺ️ Connect Burp Suite to AI clients through MCP
βšͺ️ Automatic installation for Claude Desktop
βšͺ️ Comes with packaged Stdio MCP proxy server

πŸ’» Usage:
βšͺ️ Install the extension in Burp Suite
βšͺ️ Configure your Burp MCP server in the extension settings
βšͺ️ Configure your MCP client to use the Burp SSE MCP server or stdio proxy
βšͺ️ Interact with Burp through your client!

πŸ”Ό Installation:
Prerequisites
βšͺ️ Java
βšͺ️ Jar Command
cd burp-mcp
./gradlew embedProxyJar
#Open Burp Suite
#Access the Extensions Tab
#Add the Extension

Github

⬇️ Download
πŸ”’ BugCod3

#Burp #Suite #Extension
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
❀6⚑4πŸ”₯1🀣1
Revelar – Origin Reveal PRO

πŸ‘β€πŸ—¨ Overview:
Revelar (Origin Reveal PRO) is a professional Go-based CLI tool for uncovering real/origin IP addresses of websites behind CDNs such as Cloudflare, Akamai, Fastly, Imperva, and AWS CloudFront.

πŸ“Š Features:
βšͺ️ Detects CDN providers automatically.
βšͺ️ Collects DNS records (A, AAAA, MX, Reverse DNS).
βšͺ️ Extracts SSL Subject Alternative Names (SANs).
βšͺ️ Integrates with optional external tools (subfinder, amass, dnsx, httpx, nuclei).
βšͺ️ Filters CDN IP ranges to isolate real origin candidates.
βšͺ️ Active verification engine

πŸ”Ό Installation:
Install via go install:
go install github.com/MRvirusIR/Revelar@latest

or
cd Revelar
./Revelar -d example.com #For Run


πŸ’» Usage:
./Revelar -h


😸 Github

⬇️ Download
πŸ”’ BugCod3

#Revelar #CDN #Finder #RealIP #Discovery #Tool
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ“£ T.me/BugCod3
πŸ“£ T.me/RootAccessClub
Please open Telegram to view this post
VIEW IN TELEGRAM
10❀7⚑3πŸ”₯3πŸ†1
If this post gets support and a lot of reactions, we will prepare and create many more cool tools for you to use and enjoy. πŸ”₯
πŸ”₯13❀2
Laravel RCE Exploitation Toolkit πŸ€•

Purpose: Exploits Laravel RCE vulnerability by using a known APP_KEY to generate a malicious payload that leads to remote code execution. If successful, it writes a backdoor to the server and logs the URL ⭐

πŸ’» Github

#Exploit #laravel #Rce #Rcr_Exploit

Join Exploit Forge ✈️
Join Exploit Forge Forum ✈️
Join BugCod3✈️
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯5⚑4❀1
CVE-2025-24893 πŸ€”

is a critical unauthenticated remote code execution (RCE) vulnerability affecting the XWiki Platform 🩷

Summary ❗

Affected Versions ❓

XWiki πŸ€” 5.3-milestone-2 up to < 15.10.11 🦠

XWiki πŸ€” 16.0.0-rc-1 up to < 16.4.1 🦠

CVSS v3.1 Score : 9.8 (Critical) πŸ”«

Github 🌐

#Rce #Exploit

Join Exploit Forge πŸ’Ž
Join Exploit Forge Forum πŸ’Ž
Join BugCod3 πŸ’Ž
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯6⚑4❀1πŸ‘1πŸ’‹1
πŸ”₯ [remote] Ivanti Endpoint Manager Mobile 12.5.0.0 - Authentication Bypass
Ivanti Endpoint Manager Mobile 12.5.0.0 - Authentication Bypass

πŸ”— Read / Download

#BugCod3 #security #bugbounty #infosec
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
❀2⚑2πŸ”₯2
Google Dork - High % keywords πŸš€

inurl:conf | inurl:env | inurl:cgi | inurl:bin | inurl:etc | inurl:root | inurl:sql | inurl:backup | inurl:admin | inurl:php site:example[.]com

#BugCod3 #Google #Dork
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
⚑2❀2πŸ”₯2πŸ‘1πŸ‘Ž1
How this seasoned bug bounty hunter combines Burp Suite and HackerOne to uncover high-impact vulnerabilities
Arman S., a full-time independent security researcher and bug bounty hunter, talked us through how he uses Burp Suite Professional and HackerOne in tandem to find and report high-value security vulner

πŸ”— Read more

#BugCod3 #security #bugbounty #infosec #portswigger
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
⚑1❀1πŸ”₯1
[webapps] Birth Chart Compatibility WordPress Plugin 2.0 - Full Path Disclosure
Birth Chart Compatibility WordPress Plugin 2.0 - Full Path Disclosure

πŸ”— Read more

#BugCod3 #security #bugbounty #infosec #exploitdb #exploit #poc
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
πŸ”₯3❀‍πŸ”₯1❀1
Researchers discovered a critical Redis vulnerability called RediShell πŸ—‘

(CVE-2025-49844) a CVSS 10 remote code execution flaw affecting all Redis versions. It allows attackers to send a malicious Lua script, escape the sandbox, and execute code on the host. Around 330,000 Redis instances are exposed online, 60,000 of them without authentication, and over 75% of cloud environments use Redis⚑️

CVE-2025-49844 (RediShell) POC πŸ›‘

Github

#cve #poc #exploit #redishell #redis

Join Exploit Forge πŸ”
Join Exploit Forge Forum πŸ‘‘
Join BugCod3 🀝
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯7❀‍πŸ”₯3❀2⚑1
πŸ‘ Burpsuite Pro πŸ‘

πŸ”₯ v2025.10.4

πŸ”” BurpBountyPro_v2025.10.4 βž•

πŸ“‚ README (en+ru) included, plz read it before run BS.

πŸ”Ό Run this version With Java SE JDK 22

⬇️ Download
πŸ”’ 311138

#Burpsuite #Pro #Tools
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
❀8⚑3πŸ”₯3
Burp AI Agent ⚑️

πŸ“‚ Github

#Burpsuite #burp #ai #tools

βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯4⚑2❀2
Scanners Box πŸ”₯

A powerful and open source toolkit for hackers and security automation
⭐️

Github β›“

#Tools #open_source #automation

Join RootAccessClub πŸ”₯
Join BugCod3 πŸ”₯
Please open Telegram to view this post
VIEW IN TELEGRAM
⚑3πŸ”₯3❀‍πŸ”₯2❀1
When nationwide internet blackouts silence millions in Iran, Meshtastic offers a way to stay connected without relying on the web πŸ™ˆ

Mesh networks don’t go dark when the internet does 🌐

Build yours, Now βš™οΈ

Read here πŸ“–

#internet #iran #censorship

Join RootAccessClub ⭐
Join BugCod3 πŸ’Ž
Please open Telegram to view this post
VIEW IN TELEGRAM
❀4⚑3
🚨 2 new vulnerability scripts created for the n8n vulnerabilities disclosed today:

⬇️ Download (CVE-2026-1470)

⬇️ Download (CVE-2026-0863)

πŸ”’ BugCod3

#BugBounty #CVE #n8n
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
❀7πŸ”₯3⚑2
Forwarded from Root Access Club
𝝣.𝗩.𝝠 πŸ”₯Exploit Vector Agent

Autonomous offensive security AI for guiding pentest processes 🧠

πŸ“± Github

#ai #pentesting #pentest #security

Join RootAccessClub πŸ“±
Join BugCod3 πŸ“±
Please open Telegram to view this post
VIEW IN TELEGRAM
❀3❀‍πŸ”₯2⚑2πŸ”₯2
Krawl πŸ•Έ

modern, customizable web honeypot server designed to detect and track malicious activity from attackers and web crawlers through deceptive web pages, fake credentials, and canary tokens

Github πŸ–₯

#Honeypot #tools

Join RootAccessClub πŸ₯Έ
Join BugCod3 ❀
Please open Telegram to view this post
VIEW IN TELEGRAM
❀7⚑2πŸ”₯2