🌐 https://www.ntbcl.com
👤 name: Admin
📧 email: ntbcl_adminn@ntbcl.com
🔓 password: NewP30MAY@$#
🚫 login page: N/A
#web #sql
➖➖➖➖➖➖➖➖➖➖
👤 T.me/MRvirusIRBOT
📢 T.me/BugCod3
👤 name: Admin
📧 email: ntbcl_adminn@ntbcl.com
🔓 password: NewP30MAY@$#
🚫 login page: N/A
#web #sql
➖➖➖➖➖➖➖➖➖➖
👤 T.me/MRvirusIRBOT
📢 T.me/BugCod3
🌐 aeronsindia.com
👤 Name: Admin
📧 Email: admin@aeronsindia.com
🔓 Password: admin12345
📧 Email: anilverm404@gmail.com
🔓 Password: 123
🆚 Version: 5.6.51
🗂 Database: aeronsin_web
🚫 login page: N/A
#web #sql
➖➖➖➖➖➖➖➖➖➖
👤 T.me/MRvirusIRBOT
📢 T.me/BugCod3
👤 Name: Admin
📧 Email: admin@aeronsindia.com
🔓 Password: admin12345
📧 Email: anilverm404@gmail.com
🔓 Password: 123
🆚 Version: 5.6.51
🗂 Database: aeronsin_web
🚫 login page: N/A
#web #sql
➖➖➖➖➖➖➖➖➖➖
👤 T.me/MRvirusIRBOT
📢 T.me/BugCod3
🌐 http://www.simscollege.ac.in
👤 Username: admin
🔓 Password: simsxyz
🆚 Version: 10.5.22-MariaDB
🚫 Database: N/A
✅ login page: /members.php
#web #sql
➖➖➖➖➖➖➖➖➖➖
👤 T.me/MRvirusIRBOT
📢 T.me/BugCod3
👤 Username: admin
🔓 Password: simsxyz
🆚 Version: 10.5.22-MariaDB
🚫 Database: N/A
✅ login page: /members.php
#web #sql
➖➖➖➖➖➖➖➖➖➖
👤 T.me/MRvirusIRBOT
📢 T.me/BugCod3
For the longest of times, content discovery has been focused on finding files and folders. While this approach is effective for legacy web servers that host static files or respond with 3xx’s upon a partial path, it is no longer effective for modern web applications, specifically APIs.
Over time, we have seen a lot of time invested in making content discovery tools faster so that larger wordlists can be used, however the art of content discovery has not been innovated upon.
Kiterunner is a tool that is capable of not only performing traditional content discovery at lightning fast speeds, but also bruteforcing routes/endpoints in modern applications.
Modern application frameworks such as Flask, Rails, Express, Django and others follow the paradigm of explicitly defining routes which expect certain HTTP methods, headers, parameters and values.
When using traditional content discovery tooling, such routes are often missed and cannot easily be discovered.
By collating a dataset of Swagger specifications and condensing it into our own schema, Kiterunner can use this dataset to bruteforce API endpoints by sending the correct HTTP method, headers, path, parameters and values for each request it sends.
Swagger files were collected from a number of datasources, including an internet wide scan for the 40+ most common swagger paths. Other datasources included GitHub via BigQuery, and APIs.guru.
#FUZZ
Please open Telegram to view this post
VIEW IN TELEGRAM
Nuclei is used to send requests across targets based on a template, leading to zero false positives and providing fast scanning on a large number of hosts. Nuclei offers scanning for a variety of protocols, including TCP, DNS, HTTP, SSL, File, Whois, Websocket, Headless etc. With powerful and flexible templating, Nuclei can be used to model all kinds of security checks.
We have a dedicated repository that houses various type of vulnerability templates contributed by more than 300 security researchers and engineers.
Install Nuclei
Nuclei requires go1.20 to install successfully. Run the following command to install the latest version -
➜ ~ go install -v github.com/projectdiscovery/nuclei/v2/cmd/nuclei@latest
#security #vulnerability_detection
Please open Telegram to view this post
VIEW IN TELEGRAM
Quasar is a fast and light-weight remote administration tool coded in C#. The usage ranges from user support through day-to-day administrative work to employee monitoring. Providing high stability and an easy-to-use user interface, Quasar is the perfect remote administration solution for you.
Please check out the Getting Started guide.
Latest stable release (recommended)
🌐 Github
#windows #administration #remote #desktop
Please open Telegram to view this post
VIEW IN TELEGRAM
⚡3❤1
Main Features
Pre-Compiled
Github
#c #windows #binder #open_source
Please open Telegram to view this post
VIEW IN TELEGRAM
🏆3
Please open Telegram to view this post
VIEW IN TELEGRAM
#DDos #Proxy #L7 #L4
Please open Telegram to view this post
VIEW IN TELEGRAM
❤5
The all-in-one Red Team browser extension for Web Pentesters
HackTools, is a web extension facilitating your web application penetration tests, it includes cheat sheets as well as all the tools used during a test such as XSS payloads, Reverse shells and much more.
With the extension you no longer need to search for payloads in different websites or in your local storage space, most of the tools are accessible in one click. HackTools is accessible either in pop up mode or in a whole tab in the Devtools part of the browser with F12.
➜ ~
git clone https://github.com/LasCC/Hack-Tools.git
➜ ~ cd Hack-Tools
➜ ~ npm install && npm run build
#Bug_bounty #Payloads #Addons #ToolsPlease open Telegram to view this post
VIEW IN TELEGRAM
👍3🔥3
A discord nitro generator and checker for all your nitro needs
It generates and checks discord nitro codes at the same time for maximum efficiency
To get a local copy up and running follow these simple steps.
You need to install Python, that can be done here
➜ ~
python3.8 -m pip install -r requirements.txt
Run the
main.py file using py -3 main.py The code will show you two prompts:1. How many codes to generate
2. If you want to use a discord webhook, if you dont know how to get a discord webhook url it is located at
channel settings » intergrations » webhooks » create webhookIf you dont want to use a webhook simply leave this blank
The code will start generating and checking after that step
#Python #Generator #Checker #Discord #Nitro
Please open Telegram to view this post
VIEW IN TELEGRAM
❤🔥4
HTML Form Parser For Humans
It's very easy to make HTTP requests in python, thanks to urllib and requests. However, there was no way to submit HTML forms on the go, well now there is.
from zetanize import zetanize
forms = zetanize(html)
Well that's it! Just feed zetanize a HTML document and it will give you a dict of actionable form data.Let's parse
https://google.com for getting familiar:from requests import get
from zetanize import zetanize
html = get('https://google.com').text
forms = zetanize(html)
{
"0": {
"action": "/search",
"inputs": [
{
"type": "hidden",
"name": "ie",
"value": "ISO-8859-1"
},
{
"type": "hidden",
"name": "hl",
"value": "en-IN"
},
{
"type": "hidden",
"name": "source",
"value": "hp"
},
{
"type": "hidden",
"name": "biw",
"value": ""
},
{
"type": "hidden",
"name": "bih",
"value": ""
},
{
"type": "",
"name": "q",
"value": ""
},
{
"type": "submit",
"name": "btnG",
"value": "Google Search"
},
{
"type": "submit",
"name": "btnI",
"value": "I"
},
{
"type": "hidden",
"name": "gbv",
"value": "1"
}
],
"method": "get"
}
}
#Mechanize #Html #Parser
Please open Telegram to view this post
VIEW IN TELEGRAM
❤4
Incredibly fast crawler designed for OSINT
Photon can extract the following data while crawling:
example.com/gallery.php?id=2)#Python #Crawler #Osint #Spider
Please open Telegram to view this post
VIEW IN TELEGRAM
👍2😱2
Xss Payload
#Xss #Payload➗ ➗ ➗ ➗ ➗ ➗ ➗ ➗ ➗ ➗ ➗ ➗
👤 T.me/BugCod3BOT
📢 T.me/BugCod3
<input/onmouseover="javaSCRIPT:confirm(1)”
#Xss #Payload
Please open Telegram to view this post
VIEW IN TELEGRAM
🌟 Any to Icon 🌟
3.59 converts BMP, JPEG, GIF, PNG, PCX, PSD, TGA, TIFF, WMF, WBMP, XPM, XBM and CUR formats into Windows icons. You can add files and folders from Windows Explorer or other file shells using drag and drop. You also can paste bitmaps from the clipboard and change color resolution and size to create customized icons. It's possible to convert 256-color icons into True Color icons and vice versa.
⬇️ Download
#Anytoicon
➖➖➖➖➖➖➖➖➖➖
👤 T.me/BugCod3BOT
📢 T.me/BugCod3
3.59 converts BMP, JPEG, GIF, PNG, PCX, PSD, TGA, TIFF, WMF, WBMP, XPM, XBM and CUR formats into Windows icons. You can add files and folders from Windows Explorer or other file shells using drag and drop. You also can paste bitmaps from the clipboard and change color resolution and size to create customized icons. It's possible to convert 256-color icons into True Color icons and vice versa.
⬇️ Download
#Anytoicon
➖➖➖➖➖➖➖➖➖➖
👤 T.me/BugCod3BOT
📢 T.me/BugCod3
👍2
🌟 TheFatRat 🌟
🔥 A Massive Exploiting Tool
📝 TheFatRat is an exploiting tool which compiles a malware with famous payload, and then the compiled maware can be executed on Linux , Windows , Mac and Android. TheFatRat Provides An Easy way to create Backdoors and Payload which can bypass most anti-virus.
👁 Features !
🔻Fully Automating MSFvenom & Metasploit.
🔻Local or remote listener Generation.
🔻Easily Make Backdoor by category Operating System.
🔻Generate payloads in Various formats.
🔻Bypass anti-virus backdoors.
🔻File pumper that you can use for increasing the size of your files.
🔻The ability to detect external IP & Interface address .
🔻Automatically creates AutoRun files for USB / CDROM exploitation
▶️ Installation
Instructions on how to install TheFatRat
😸 Github
#Trojan #Rat #Tools
➖➖➖➖➖➖➖➖➖➖
👤 T.me/BugCod3BOT
📢 T.me/BugCod3
🔥 A Massive Exploiting Tool
📝 TheFatRat is an exploiting tool which compiles a malware with famous payload, and then the compiled maware can be executed on Linux , Windows , Mac and Android. TheFatRat Provides An Easy way to create Backdoors and Payload which can bypass most anti-virus.
👁 Features !
🔻Fully Automating MSFvenom & Metasploit.
🔻Local or remote listener Generation.
🔻Easily Make Backdoor by category Operating System.
🔻Generate payloads in Various formats.
🔻Bypass anti-virus backdoors.
🔻File pumper that you can use for increasing the size of your files.
🔻The ability to detect external IP & Interface address .
🔻Automatically creates AutoRun files for USB / CDROM exploitation
▶️ Installation
Instructions on how to install TheFatRat
git clone https://github.com/Screetsec/TheFatRat.git
cd TheFatRat
chmod +x setup.sh && ./setup.sh
😸 Github
#Trojan #Rat #Tools
➖➖➖➖➖➖➖➖➖➖
👤 T.me/BugCod3BOT
📢 T.me/BugCod3
❤2👎2
𝐇𝐨𝐰 𝐭𝐨 𝐟𝐢𝐧𝐝 𝐚 𝐭𝐚𝐫𝐠𝐞𝐭
𝐚𝐮𝐭𝐨𝐦𝐚𝐭𝐢𝐜𝐚𝐥𝐥𝐲?
✨SQLMAP✨
📝SQLmap is an open-source tool used in penetration testing to detect and exploit SQL injection flaws. SQLmap automates the process of detecting and exploiting SQL injection. SQL Injection attacks can take control of databases that utilize SQL.
Installation
Github 👾
🎯 𝘏𝘰𝘸 𝘵𝘰 𝘶𝘴𝘦
To find the target automatically, you must use this command:
If you installed on sudo:sqlmap -g “inurl:”.php?id=”intext:”Example”
if you installed on path:
sqlmap.py -g “inurl:”.php?id=”intext:”Example”
✍️Note:you can add any dork in “
#Tools #dork
➖➖➖➖➖➖➖➖➖➖
👤 T.me/BugCod3BOT
📢 T.me/BugCod3
𝐚𝐮𝐭𝐨𝐦𝐚𝐭𝐢𝐜𝐚𝐥𝐥𝐲?
✨SQLMAP✨
📝SQLmap is an open-source tool used in penetration testing to detect and exploit SQL injection flaws. SQLmap automates the process of detecting and exploiting SQL injection. SQL Injection attacks can take control of databases that utilize SQL.
Installation
Github 👾
🎯 𝘏𝘰𝘸 𝘵𝘰 𝘶𝘴𝘦
To find the target automatically, you must use this command:
If you installed on sudo:sqlmap -g “inurl:”.php?id=”intext:”Example”
if you installed on path:
sqlmap.py -g “inurl:”.php?id=”intext:”Example”
✍️Note:you can add any dork in “
#Tools #dork
➖➖➖➖➖➖➖➖➖➖
👤 T.me/BugCod3BOT
📢 T.me/BugCod3
🔥2
MH Ddos-Dos TOOL
mh ddos-dos tool is one of the best and powerful ddos tools🎃
with 56 methods one of the most powerful ddos tools
if you want do down any web site We suggest you to do it with several systems at the same time.
Installation📝
#ddos #dos
➖➖➖➖➖➖➖➖➖➖
👤 T.me/BugCod3BOT
📢 T.me/BugCod3
mh ddos-dos tool is one of the best and powerful ddos tools🎃
with 56 methods one of the most powerful ddos tools
if you want do down any web site We suggest you to do it with several systems at the same time.
Installation📝
git clone https://github.com/MatrixTM/MHDDoS.git
cd MHDDoS
pip install -r requirements.txt
#ddos #dos
➖➖➖➖➖➖➖➖➖➖
👤 T.me/BugCod3BOT
📢 T.me/BugCod3
👏4🎉2
🌟 Wifiphisher 🌟
📝
Wifiphisher is a rogue Access Point framework for conducting red team engagements or Wi-Fi security testing.
⬇️ Download
🐈⬛ Github
#WifiPhisher #RedTeam #Tools
➖➖➖➖➖➖➖➖➖➖
👤 T.me/BugCod3BOT
📢 T.me/BugCod3
📝
Wifiphisher is a rogue Access Point framework for conducting red team engagements or Wi-Fi security testing.
⬇️ Download
🐈⬛ Github
#WifiPhisher #RedTeam #Tools
➖➖➖➖➖➖➖➖➖➖
👤 T.me/BugCod3BOT
📢 T.me/BugCod3
❤🔥4
5 important Tools that can use for Bug Hunting Journey or pen-testing process.
Information Gathering or Reconnisence is the most important part of penetration testing.
#recon #osint
➖➖➖➖➖➖➖➖➖➖
👤 T.me/BugCod3BOT
📢 T.me/BugCod3
Information Gathering or Reconnisence is the most important part of penetration testing.
1:Nmap:Nmap is a free and open-source network mapping tool that can use for network discovery and security auditing
2: Amass:The OWASP Amass tool suite obtains subdomain names by scraping data sources, recursive brute forcing, crawling web archives, permuting/altering names, and reverse DNS sweeping.
3:Dirb:Dirb is a powerful web content scanner tool that can use to find hidden and existing files on the web application
4: Sublist3r:Sublist3r is a python tool designed to enumerate subdomains of websites using OSINT.
5:DNS Recon:DNS Recon is a tool that can use for Domain Name System (DNS) enumeration.
#recon #osint
➖➖➖➖➖➖➖➖➖➖
👤 T.me/BugCod3BOT
📢 T.me/BugCod3
❤🔥4🎉2
🌟 njRAT 🌟
📝
NjRAT is a Remote Administration Tool. This repository contains a Njrat Editions.
Use it on virtual machine
⬇️ Download (NjRat 0.7D Danger Edition)
⬇️ Download (NjRat 0.7D Golden Edition)
⬇️ Download (NjRat 0.7D Green Edition)
⬇️ Download (NjRat 0.7D)
⬇️ Download (njRAT Lime Edition )
⬇️ Download (ALL Version)
🐈⬛ Github
#njRAT #Tools
➖➖➖➖➖➖➖➖➖➖
👤 T.me/BugCod3BOT
📢 T.me/BugCod3
📝
NjRAT is a Remote Administration Tool. This repository contains a Njrat Editions.
Use it on virtual machine
⬇️ Download (NjRat 0.7D Danger Edition)
⬇️ Download (NjRat 0.7D Golden Edition)
⬇️ Download (NjRat 0.7D Green Edition)
⬇️ Download (NjRat 0.7D)
⬇️ Download (njRAT Lime Edition )
⬇️ Download (ALL Version)
🐈⬛ Github
#njRAT #Tools
➖➖➖➖➖➖➖➖➖➖
👤 T.me/BugCod3BOT
📢 T.me/BugCod3
👍3⚡1