BugCod3
7.26K subscribers
334 photos
6 videos
7 files
445 links
[ BugCod3 ] โ€” From Shadows To Shells โšก๏ธ

๐Ÿ•ถ Hacking | ๐Ÿž Bug Bounty | ๐Ÿ” Security Tools
โš”๏ธ Learn โ€ข Hunt โ€ข Dominate

๐Ÿ‘ฅ Group: T.me/BugCod3GP
๐Ÿ“‚ Topic: T.me/BugCod3Topic

๐ŸŒ Web: BugCod3.com
๐Ÿค– Contact: T.me/BugCod3BOT
๐Ÿ“ง Email: BugCod3@protonmail.com
Download Telegram
FinalRecon is an automatic web reconnaissance tool written in python. Goal of FinalRecon is to provide an overview of the target in a short amount of time while maintaining the accuracy of results. Instead of executing several tools one after another it can provide similar results keeping dependencies small and simple.

FinalRecon provides detailed information such as :

โšช๏ธ Header Information

โšช๏ธ Whois

โšช๏ธ SSL Certificate Information

โšช๏ธ Crawler
...

โšช๏ธ DNS Enumeration
...

โšช๏ธ Subdomain Enumeration
...

โšช๏ธ Directory Searching
...

โšช๏ธ Wayback Machine
...

โšช๏ธ Port Scan
...

โšช๏ธ Export
...

Github

#pentesting #web #Tools
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/MRvirusIRBOT
๐Ÿ“ข T.me/BugCod3
โšก3
๐ŸŒ https://www.ntbcl.com

๐Ÿ‘ค name: Admin
๐Ÿ“ง email: ntbcl_adminn@ntbcl.com
๐Ÿ”“ password: NewP30MAY@$#

๐Ÿšซ login page: N/A

#web #sql
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/MRvirusIRBOT
๐Ÿ“ข T.me/BugCod3
๐ŸŒ aeronsindia.com

๐Ÿ‘ค Name: Admin
๐Ÿ“ง Email: admin@aeronsindia.com
๐Ÿ”“ Password: admin12345


๐Ÿ“ง Email: anilverm404@gmail.com
๐Ÿ”“ Password: 123

๐Ÿ†š Version: 5.6.51
๐Ÿ—‚ Database: aeronsin_web

๐Ÿšซ login page: N/A

#web #sql
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/MRvirusIRBOT
๐Ÿ“ข T.me/BugCod3
๐ŸŒ http://www.simscollege.ac.in

๐Ÿ‘ค Username: admin
๐Ÿ”“ Password: simsxyz

๐Ÿ†š Version: 10.5.22-MariaDB
๐Ÿšซ Database: N/A

โœ… login page: /members.php

#web #sql
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/MRvirusIRBOT
๐Ÿ“ข T.me/BugCod3
๐ŸŒŸkiterunner๐ŸŒŸ

๐Ÿ“ Introduction

For the longest of times, content discovery has been focused on finding files and folders. While this approach is effective for legacy web servers that host static files or respond with 3xxโ€™s upon a partial path, it is no longer effective for modern web applications, specifically APIs.

Over time, we have seen a lot of time invested in making content discovery tools faster so that larger wordlists can be used, however the art of content discovery has not been innovated upon.

Kiterunner is a tool that is capable of not only performing traditional content discovery at lightning fast speeds, but also bruteforcing routes/endpoints in modern applications.

Modern application frameworks such as Flask, Rails, Express, Django and others follow the paradigm of explicitly defining routes which expect certain HTTP methods, headers, parameters and values.

When using traditional content discovery tooling, such routes are often missed and cannot easily be discovered.

By collating a dataset of Swagger specifications and condensing it into our own schema, Kiterunner can use this dataset to bruteforce API endpoints by sending the correct HTTP method, headers, path, parameters and values for each request it sends.

Swagger files were collected from a number of datasources, including an internet wide scan for the 40+ most common swagger paths. Other datasources included GitHub via BigQuery, and APIs.guru.

๐ŸŒ Github
โฌ‡๏ธ Download

#FUZZ
โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—
๐Ÿ‘ค T.me/MRvirusIRBOT
๐Ÿ“ข T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
๐ŸŒŸ Fast and customisable vulnerability scanner based on simple YAML based DSL. ๐ŸŒŸ

๐Ÿ“
Nuclei is used to send requests across targets based on a template, leading to zero false positives and providing fast scanning on a large number of hosts. Nuclei offers scanning for a variety of protocols, including TCP, DNS, HTTP, SSL, File, Whois, Websocket, Headless etc. With powerful and flexible templating, Nuclei can be used to model all kinds of security checks.

We have a dedicated repository that houses various type of vulnerability templates contributed by more than 300 security researchers and engineers.

Install Nuclei
Nuclei requires go1.20 to install successfully. Run the following command to install the latest version -

โฌ‡๏ธ
โžœ ~ go install -v github.com/projectdiscovery/nuclei/v2/cmd/nuclei@latest

๐ŸŒ Github

#security #vulnerability_detection
โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—
๐Ÿ‘ค T.me/MRvirusIRBOT
๐Ÿ“ข T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
๐ŸŒŸQuasar๐ŸŒŸ

๐Ÿ”ตFree, Open-Source Remote Administration Tool for Windows

๐Ÿ“
Quasar is a fast and light-weight remote administration tool coded in C#. The usage ranges from user support through day-to-day administrative work to employee monitoring. Providing high stability and an easy-to-use user interface, Quasar is the perfect remote administration solution for you.

Please check out the Getting Started guide.

โž• Features
โšช๏ธTCP network stream (IPv4 & IPv6 support)
โšช๏ธFast network serialization (Protocol Buffers)
โšช๏ธEncrypted communication (TLS)
โšช๏ธUPnP Support (automatic port forwarding)
โšช๏ธTask Manager
โšช๏ธFile Manager
โšช๏ธStartup Manager
โšช๏ธRemote Desktop
โšช๏ธRemote Shell
โšช๏ธRemote Execution
โšช๏ธSystem Information
โšช๏ธRegistry Editor
โšช๏ธSystem Power Commands (Restart, Shutdown, Standby)
โšช๏ธKeylogger (Unicode Support)
โšช๏ธReverse Proxy (SOCKS5)
โšช๏ธPassword Recovery (Common Browsers and FTP Clients)
โšช๏ธ... and many more!

โฌ‡๏ธ Download
Latest stable release (recommended)

๐ŸŒ Github

#windows #administration #remote #desktop
โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—
๐Ÿ‘ค T.me/MRvirusIRBOT
๐Ÿ“ข T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก3โค1
๐ŸŒŸ UnamBinder 1.3.0 - A free silent native file binder ๐ŸŒŸ

๐Ÿ”ต A free silent (hidden) open-source native file binder.

๐Ÿ“
Main Features
โšช๏ธ Native or Managed - Builds the final executable as a native (C) or a managed (.NET C#) 32-bit file depending on choice

โšช๏ธ Silent - Drops and executes (if enabled) files without any visible output unless the bound program has one

โšช๏ธ Multiple files - Supports binding any amount of files

โšช๏ธ Compatible - Supports all tested Windows version (Windows 7 to Windows 11) and all file types

โšช๏ธ Windows Defender exclusions - Can add exclusions into Windows Defender to ignore any detections from the bound files

โšช๏ธ Icon/Assembly - Supports adding an Icon and/or Assembly Data to the built file

โšช๏ธ Fake Error - Supports displaying a fake error message when file is originally started

โฌ‡๏ธ Downloads
Pre-Compiled
Github

#c #windows #binder #open_source
โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—
๐Ÿ‘ค T.me/MRvirusIRBOT
๐Ÿ“ข T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ†3
๐ŸŒŸ REMCOS RAT๐ŸŒŸ

โฌ‡๏ธ Download

#rat #windows #malware
โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—
๐Ÿ‘ค T.me/MRvirusIRBOT
๐Ÿ“ข T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
๐ŸŒŸ A Python tool for DDos via proxy ๐ŸŒŸ

โฌ‡๏ธ Download

#DDos #Proxy #L7 #L4
โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—
๐Ÿ‘ค T.me/MRvirusIRBOT
๐Ÿ“ข T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โค5
๐ŸŒŸ Welcome to HackTools ๐Ÿ›  ๐ŸŒŸ

๐Ÿ“
The all-in-one Red Team browser extension for Web Pentesters

HackTools, is a web extension facilitating your web application penetration tests, it includes cheat sheets as well as all the tools used during a test such as XSS payloads, Reverse shells and much more.

With the extension you no longer need to search for payloads in different websites or in your local storage space, most of the tools are accessible in one click. HackTools is accessible either in pop up mode or in a whole tab in the Devtools part of the browser with F12.

โž• Current functions
โšช๏ธ Dynamic Reverse Shell generator (PHP, Bash, Ruby, Python, Perl, Netcat)
โšช๏ธ Shell Spawning (TTY Shell Spawning)
โšช๏ธ MSF Venom Builder
โšช๏ธ XSS Payloads
โšช๏ธ Basic SQLi payloads
โšช๏ธ Local file inclusion payloads (LFI)
โšช๏ธ Data Encoding
โšช๏ธ Obfuscated Files or Information
โšช๏ธ Hash Generator (MD5, SHA1, SHA256, SHA512, SM3)
โšช๏ธ Useful Linux commands (Port Forwarding, SUID)
โšช๏ธ RSS Feed (Exploit DB, Cisco Security Advisories, CXSECURITY)
โšช๏ธ CVE Search Engine
โšช๏ธ Various method of data exfiltration and download from a remote machine

โฌ‡๏ธ Download
๐ŸŒ Chromium based browser
๐Ÿ” Mozilla Firefox
๐ŸŒ Instructions to build for Safari

๐Ÿ˜ธ Github

โ—€๏ธ Build from source code
โžœ ~ git clone https://github.com/LasCC/Hack-Tools.git
โžœ ~ cd Hack-Tools
โžœ ~ npm install && npm run build

#Bug_bounty #Payloads #Addons #Tools
โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—
๐Ÿ‘ค T.me/MRvirusIRBOT
๐Ÿ“ข T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘3๐Ÿ”ฅ3
๐ŸŒŸ Discord Nitro Generator and Checker ๐ŸŒŸ

A discord nitro generator and checker for all your nitro needs

It generates and checks discord nitro codes at the same time for maximum efficiency

๐Ÿ“ Getting Started
To get a local copy up and running follow these simple steps.

โž• Prerequisites
You need to install Python, that can be done here

โฌ‡๏ธ Download OR Clone the repo github

โ—€๏ธ Install Python packages
โžœ ~ python3.8 -m pip install -r requirements.txt

โžก๏ธ Usage
Run the main.py file using py -3 main.py The code will show you two prompts:

1. How many codes to generate
2. If you want to use a discord webhook, if you dont know how to get a discord webhook url it is located at
channel settings ยป intergrations ยป webhooks ยป create webhook
If you dont want to use a webhook simply leave this blank

The code will start generating and checking after that step

๐Ÿ˜ธ Github

โš ๏ธ This program has not been tested by our team โš ๏ธ

#Python #Generator #Checker #Discord #Nitro
โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—
๐Ÿ‘ค T.me/MRvirusIRBOT
๐Ÿ“ข T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โคโ€๐Ÿ”ฅ4
๐ŸŒŸ zetanize ๐ŸŒŸ

HTML Form Parser For Humans

๐Ÿ“ Introduction
It's very easy to make HTTP requests in python, thanks to urllib and requests. However, there was no way to submit HTML forms on the go, well now there is.

๐Ÿ”ฐ Documentation
from zetanize import zetanize
forms = zetanize(html)

Well that's it! Just feed zetanize a HTML document and it will give you a dict of actionable form data.
Let's parse https://google.com for getting familiar:
from requests import get
from zetanize import zetanize

html = get('https://google.com').text
forms = zetanize(html)

๐Ÿ‘ Here's the output:
{
"0": {
"action": "/search",
"inputs": [
{
"type": "hidden",
"name": "ie",
"value": "ISO-8859-1"
},
{
"type": "hidden",
"name": "hl",
"value": "en-IN"
},
{
"type": "hidden",
"name": "source",
"value": "hp"
},
{
"type": "hidden",
"name": "biw",
"value": ""
},
{
"type": "hidden",
"name": "bih",
"value": ""
},
{
"type": "",
"name": "q",
"value": ""
},
{
"type": "submit",
"name": "btnG",
"value": "Google Search"
},
{
"type": "submit",
"name": "btnI",
"value": "I"
},
{
"type": "hidden",
"name": "gbv",
"value": "1"
}
],
"method": "get"
}
}


โฌ‡๏ธ Download
๐Ÿ˜ธ Github

#Mechanize #Html #Parser
โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—
๐Ÿ‘ค T.me/MRvirusIRBOT
๐Ÿ“ข T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โค4
๐ŸŒŸ Photon ๐ŸŒŸ

Incredibly fast crawler designed for OSINT

Photon can extract the following data while crawling:
โšช๏ธURLs (in-scope & out-of-scope)
โšช๏ธURLs with parameters (example.com/gallery.php?id=2)
โšช๏ธIntel (emails, social media accounts, amazon buckets etc.)
โšช๏ธFiles (pdf, png, xml etc.)
โšช๏ธSecret keys (auth/API keys & hashes)
โšช๏ธJavaScript files & Endpoints present in them
โšช๏ธStrings matching custom regex pattern
โšช๏ธSubdomains & DNS related data


โฌ‡๏ธ Download
๐Ÿ˜ธ Github

#Python #Crawler #Osint #Spider
โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—
๐Ÿ‘ค T.me/MRvirusIRBOT
๐Ÿ“ข T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘2๐Ÿ˜ฑ2โค1
Xss Payload

<input/onmouseover="javaSCRIPT&colon;confirm&lpar;1&rpar;โ€


#Xss #Payload
โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ข T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
๐ŸŒŸ Any to Icon ๐ŸŒŸ
3.59 converts BMP, JPEG, GIF, PNG, PCX, PSD, TGA, TIFF, WMF, WBMP, XPM, XBM and CUR formats into Windows icons. You can add files and folders from Windows Explorer or other file shells using drag and drop. You also can paste bitmaps from the clipboard and change color resolution and size to create customized icons. It's possible to convert 256-color icons into True Color icons and vice versa.

โฌ‡๏ธ Download

#Anytoicon
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ข T.me/BugCod3
๐Ÿ‘2
๐ŸŒŸ TheFatRat ๐ŸŒŸ

๐Ÿ”ฅ A Massive Exploiting Tool

๐Ÿ“ TheFatRat is an exploiting tool which compiles a malware with famous payload, and then the compiled maware can be executed on Linux , Windows , Mac and Android. TheFatRat Provides An Easy way to create Backdoors and Payload which can bypass most anti-virus.

๐Ÿ‘ Features !

๐Ÿ”ปFully Automating MSFvenom & Metasploit.
๐Ÿ”ปLocal or remote listener Generation.
๐Ÿ”ปEasily Make Backdoor by category Operating System.
๐Ÿ”ปGenerate payloads in Various formats.
๐Ÿ”ปBypass anti-virus backdoors.
๐Ÿ”ปFile pumper that you can use for increasing the size of your files.
๐Ÿ”ปThe ability to detect external IP & Interface address .
๐Ÿ”ปAutomatically creates AutoRun files for USB / CDROM exploitation

โ–ถ๏ธ Installation
Instructions on how to install TheFatRat
git clone https://github.com/Screetsec/TheFatRat.git
cd TheFatRat
chmod +x setup.sh && ./setup.sh


๐Ÿ˜ธ Github

#Trojan #Rat #Tools
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ข T.me/BugCod3
โค2๐Ÿ‘Ž2
๐‡๐จ๐ฐ ๐ญ๐จ ๐Ÿ๐ข๐ง๐ ๐š ๐ญ๐š๐ซ๐ ๐ž๐ญ
๐š๐ฎ๐ญ๐จ๐ฆ๐š๐ญ๐ข๐œ๐š๐ฅ๐ฅ๐ฒ?

โœจSQLMAPโœจ
๐Ÿ“SQLmap is an open-source tool used in penetration testing to detect and exploit SQL injection flaws. SQLmap automates the process of detecting and exploiting SQL injection. SQL Injection attacks can take control of databases that utilize SQL.

Installation
Github ๐Ÿ‘พ

๐ŸŽฏ ๐˜๐˜ฐ๐˜ธ ๐˜ต๐˜ฐ ๐˜ถ๐˜ด๐˜ฆ

To find the target automatically, you must use this command:
If you installed on sudo:sqlmap -g โ€œinurl:โ€.php?id=โ€intext:โ€Exampleโ€
if you installed on path:
sqlmap.py -g โ€œinurl:โ€.php?id=โ€intext:โ€Exampleโ€

โœ๏ธNote:you can add any dork in โ€œ

#Tools #dork
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ข T.me/BugCod3
๐Ÿ”ฅ2
MH Ddos-Dos TOOL

mh ddos-dos tool is one of the best and powerful ddos tools๐ŸŽƒ
with 56 methods one of the most powerful ddos tools
if you want do down any web site We suggest you to do it with several systems at the same time.

Installation๐Ÿ“
git clone https://github.com/MatrixTM/MHDDoS.git
cd MHDDoS
pip install -r requirements.txt


#ddos #dos
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ข T.me/BugCod3
๐Ÿ‘4๐ŸŽ‰2
๐ŸŒŸ Wifiphisher ๐ŸŒŸ

๐Ÿ“
Wifiphisher is a rogue Access Point framework for conducting red team engagements or Wi-Fi security testing.

โฌ‡๏ธ Download
๐Ÿˆโ€โฌ› Github

#WifiPhisher #RedTeam #Tools
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ข T.me/BugCod3
โคโ€๐Ÿ”ฅ4
5 important Tools that can use for Bug Hunting Journey or pen-testing process.

Information Gathering or Reconnisence is the most important part of penetration testing.

1:Nmap:Nmap is a free and open-source network mapping tool that can use for network discovery and security auditing
2: Amass:The OWASP Amass tool suite obtains subdomain names by scraping data sources, recursive brute forcing, crawling web archives, permuting/altering names, and reverse DNS sweeping.
3:Dirb:Dirb is a powerful web content scanner tool that can use to find hidden and existing files on the web application
4: Sublist3r:Sublist3r is a python tool designed to enumerate subdomains of websites using OSINT.
5:DNS Recon:DNS Recon is a tool that can use for Domain Name System (DNS) enumeration.


#recon #osint
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ข T.me/BugCod3
โคโ€๐Ÿ”ฅ4๐ŸŽ‰2