en
Feedback
Termux All Command [Telegram Group]

Termux All Command [Telegram Group]

Open in Telegram

Hello This Is Termux All Command Official Telegram Group. Here Share All Kind of Resourses. It is Also backup of Facebook Page Telegram Channel >> https://t.me/termuxcommandfull Facebook Page >> https://www.facebook.com/termux.command.full

Show more
1 184
Subscribers
No data24 hours
+147 days
+4730 days
Posts Archive
๐Ÿ“ขUse This Extensions, it will help you to Extract all domains From any website. ๐Ÿ”ธLink Extractor: https://lnkd.in/gmPdCynZ ๐Ÿ”ธLink Gopher: https://lnkd.in/gbC6ePcb .

security-study-plan-main.zip7.79 KB

๐ŸšจCVE-2024-27348: Unauthenticated users can execute OS commands via Groovy injection in Apache HugeGraph-Server. Upgrade to v
๐ŸšจCVE-2024-27348: Unauthenticated users can execute OS commands via Groovy injection in Apache HugeGraph-Server. Upgrade to version 1.3.0 to mitigate. ๐Ÿ’ฅPOC: https://lnkd.in/g_v4h7Cg ๐Ÿ‘‰Dorks: Hunter: /product.name="Apache HugeGraph" FOFA: app="HugeGraph-Studio" SHODAN: http.title:"HugeGraph"

IDOR TIPS~ Always try to find hidden parameters for this endpoints using Arjun, Parameth, etc. Endpoints:- /settings/profile /user/profile /user/settings /account/settings /username /profile And any similar endpoints.

BREAKING!!! OpenAl confirms GPT-5 is coming. With training already underway, this model promises to take artificial intellige
+1
BREAKING!!! OpenAl confirms GPT-5 is coming. With training already underway, this model promises to take artificial intelligence to a new level. Additionally, OpenAl has formed a new Safety and Security Team, led by Sam Altman

Recently I have found a critical bug in world's top organization - CVE-2024-24919 :- its path traversal allows information di
Recently I have found a critical bug in world's top organization - CVE-2024-24919 :- its path traversal allows information disclosure vulnerability affecting Check Point Security Gateways. allows attackers to access sensitive information on affected devices.โฃ๏ธโฃ๏ธ

๐Ÿšจ Excited to share that I made a nuclei template for mass hunting CVE 2024-24919 in a ๐๐ข๐Ÿ๐Ÿ๐ž๐ซ๐ž๐ง๐ญ ๐ฐ๐š๐ฒ ๐Ÿšจ ๐Ÿ” Key Fe
๐Ÿšจ Excited to share that I made a nuclei template for mass hunting CVE 2024-24919 in a ๐๐ข๐Ÿ๐Ÿ๐ž๐ซ๐ž๐ง๐ญ ๐ฐ๐š๐ฒ ๐Ÿšจ ๐Ÿ” Key Features + ๐„๐ฑ๐ฉ๐š๐ง๐๐ž๐ ๐๐š๐ญ๐ก๐ฌ: ๐“๐ก๐จ๐ซ๐จ๐ฎ๐ ๐ก ๐œ๐จ๐ฏ๐ž๐ซ๐š๐ ๐ž ๐ญ๐จ ๐ž๐ง๐ฌ๐ฎ๐ซ๐ž ๐ง๐จ ๐ฌ๐ญ๐จ๐ง๐ž ๐ข๐ฌ ๐ฅ๐ž๐Ÿ๐ญ ๐ฎ๐ง๐ญ๐ฎ๐ซ๐ง๐ž๐. + ๐€๐œ๐œ๐ฎ๐ซ๐š๐ญ๐ž ๐‘๐ž๐ ๐ž๐ฑ: ๐”๐ญ๐ข๐ฅ๐ข๐ณ๐ข๐ง๐  ๐ฉ๐ซ๐ž๐œ๐ข๐ฌ๐ž ๐ฉ๐š๐ญ๐ญ๐ž๐ซ๐ง๐ฌ ๐ฅ๐ข๐ค๐ž ๐œ๐ฉ_๐ฉ๐จ๐ฌ๐ญ๐ ๐ซ๐ž๐ฌ:.*:.*:.*:.*:.*:.*:.*: ๐ญ๐จ ๐ฌ๐ข๐ ๐ง๐ข๐Ÿ๐ข๐œ๐š๐ง๐ญ๐ฅ๐ฒ ๐ซ๐ž๐๐ฎ๐œ๐ž ๐Ÿ๐š๐ฅ๐ฌ๐ž ๐ฉ๐จ๐ฌ๐ข๐ญ๐ข๐ฏ๐ž๐ฌ. + ๐’๐ญ๐š๐ญ๐ฎ๐ฌ ๐‚๐จ๐๐ž ๐…๐ฅ๐ž๐ฑ๐ข๐›๐ข๐ฅ๐ข๐ญ๐ฒ: ๐๐จ๐ญ ๐๐ž๐ฉ๐ž๐ง๐๐ž๐ง๐ญ ๐ฌ๐จ๐ฅ๐ž๐ฅ๐ฒ ๐จ๐ง ๐Ÿ๐ŸŽ๐ŸŽ ๐Ž๐Š ๐ซ๐ž๐ฌ๐ฉ๐จ๐ง๐ฌ๐ž๐ฌ, ๐š๐œ๐œ๐จ๐ฆ๐ฆ๐จ๐๐š๐ญ๐ข๐ง๐  ๐ฏ๐š๐ซ๐ข๐จ๐ฎ๐ฌ ๐ฌ๐ž๐ซ๐ฏ๐ž๐ซ ๐›๐ž๐ก๐š๐ฏ๐ข๐จ๐ซ๐ฌ (๐Ÿ’๐ŸŽ๐ŸŽ, ๐Ÿ“๐ŸŽ๐ŸŽ, ๐ž๐ญ๐œ.). ๐ŸŽฏ This template is designed to enhance precision and capture those elusive vulnerabilities effectively. Let's elevate our Bug Hunting game! ๐Ÿ•ต๏ธโ€โ™‚๏ธ๐Ÿ’ป ๐Ÿ”—Link: https://lnkd.in/gUHtwQYi

FREE Advance web Hacking course ๐Ÿ”ฅ https://lnkd.in/dWT2GSXh

HACKTHEBOX ROADMAP TO CLEAR OSCP Disclaimer: The boxes that are contained in this list should be used as a way to get started, to build your practical skills, or brush up on any weak points that you may have in your pentesting methodology. This list is not a substitute to the actual lab environment that is in the PWK/OSCP course. When you are taking the course, It is encouraged that you try to go through every system that is in the PWK/OSCP lab environment, as they will provide better insight for when you attempt to the exam itself. [LINUX MACHINES] - lame - brainfuck - shocker - bashed - nibbles - beep - cronos - nineveh - sense - solidstate - node - valentine - poison - sunday - tartarsauce - Irked - Friendzone - Swagshop - Networked - jarvis - Mirai - Popcorn - Haircut - Blocky - Frolic - Postman - Mango - Traverxec - OpenAdmin - Magic - Admirer - Blunder - Tabby - Doctor - SneakyMailer - Passage - Luanne - Time - Ready - Delivery - Ophiuchi - ScriptKiddie - Armageddon - Knife - Seal - Previse - Forge - Horizontall - Shibboleth - Writer - Precise - Pandora - Meta - Paper - Talkative - Seventeen WINDOWS MACHINES] - legacy - Blue - Devel - Optimum - Bastard - granny - Arctic - grandpa - silo - bounty - jerry - conceal - chatterbox - Forest - BankRobber - secnotes - Bastion - Buff - Servmon - Active - Remote - Fuse - Omni - Worker - Love - Intelligence - APT - Object - Support - Acute - Timelapse - StreamIO - Scrambled More challenging than OSCP, but good practice] - Jeeves [Windows] - Bart [Windows] - Tally [Windows] - Kotarak [Linux] - falafel [Linux] - Devops [Linux] - Hawk [Linux] - Netmon [Windows] - Lightweight [Linux] - La Casa De Papel [Linux] - Jail [Linux] - Safe [Linux] - Bitlab [Linux] - Sizzle [Windows] - Sniper [Windows] - Control [Windows] - October [Linux] - Mango [Linux] - Nest [Windows] - Book [Linux] - Sauna [Windows] - Cascade [Windows] - Querier [Windows] - Quick [Linux] - BlackField [Windows] - APT [Windows] - Atom [Windows] - BreadCrumbs [Windows] - Monitors [Linux] - Dynstr [Linux] - PivotAPI [Windows] - Pikaboo [Linux] - Monteverde [Windows] - Writer [Linux] - Forge [Linux] - Stacked [Linux] - Backdoor[Linux] - Search [Windows] - Undetected[Linux] (More like an IR box)

New reports accepted in Coca-Cola. A hint: If you canยดt bypass the firewall (in case of XSS), doe a brute-force with all events of the javascript (with Intruder in the Burpsuite), and search a payload with the events allowed by the Firewall. Payload used: "<zzz><style>@keyframes+x+{}</style><xss+style="animation-Name:+x"+onwebkitanimationstart="print()"></xss>

๐Ÿž Learn SSRF ๐Ÿœ [+] https://portswigger.net/web-security/ssrf [X] https://book.hacktricks.xyz/pentesting-web/ssrf-server-side-request-forgery [*] https://gowthams.gitbook.io/bughunter-handbook/list-of-vulnerabilities-bugs/ssrf [-] https://www.youtube.com/watch?v=1pyoYa79ejs โœ…Tryhackme Lab:- ๐Ÿ‘‰ 1. https://tryhackme.com/r/room/ssrfqi 2. https://tryhackme.com/r/room/ssrfhr โœ…A New Era Of SSRF - Exploiting Url Parsers:- ๐Ÿ‘‰ https://www.youtube.com/watch?v=D1S-G8rJrEk โœ… Hackerone report :- ๐Ÿ‘‰ 1. https://github.com/reddelexc/hackerone-reports/blob/master/tops_by_bug_type/TOPSSRF.md โœ… Medium report :-๐Ÿ‘‰ 1. https://medium.com/techfenix/ssrf-server-side-request-forgery-worth-4913-my-highest-bounty-ever-7d733bb368cb 2. https://raymondlind.medium.com/ssrf-lfi-in-uploads-feature-a134aa467abf 3. Read And Add More โœ… 6-7 year old ssrf poc video :- ๐Ÿ‘‰ poc :- https://www.youtube.com/playlist?list=PL9VLN4DOjAsjjAZiPf_vbGp9eGufX7lKY โœ… Automate :-๐Ÿ‘‰ https://medium.com/@a1bi/ssrf-get-notified-on-discord-whenever-you-have-an-ssrf-5162a6daf8a3 โœ… All SSRF In One :- ๐Ÿ‘‰ 1. https://github.com/jdonsec/AllThingsSSRF 2. https://gowthams.gitbook.io/bughunter-handbook/list-of-vulnerabilities-bugs/ssrf โœ… Tools :- ๐Ÿ‘‰ 1. https://github.com/zmap/zgrab 2. Collaborator Everywhere 3. SSRFmap โœ… SSRF EndPoint:- ๐Ÿ‘‰ dest= path= window= next= site= reference= data= load= html= validate= page= return= callback= domain= feed= view= dir= request-baskets= dict= pdf= file= imageuri= url= key= .json oauth redirect= api= dashboard = config.= โœ… Bypass :- ๐Ÿ‘‰ 1. https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Server%20Side%20Request%20Forgery 2. Collect All bypass Techniques from twitter, medium or others sources and note down 3. https://www.bugbountyhunting.com/ #bugbounty #ssrf #bugbountytips

========>โœ… Learn IDOR โœ…<======== Insecure Direct Object Reference (IDOR) is a very common type of weakness in the application authorization logic. The potential damage from IDOR exploitation can be either minimal or critical. Letโ€™s consider some cases when the presence of IDOR allowed to perform an attack with a high impact level โ€“ account takeover or project takeover. IDOR Enumeration Exploiting IDOR vulnerabilities is easy in some instances but can be very challenging in others. Once we identify a potential IDOR, we can start testing it with basic techniques to see whether it would expose any other data. As for advanced IDOR attacks, we need to better understand how the web application works, how it calculates its object references, and how its access control system works to be able to perform advanced attacks that may not be exploitable with basic techniques. => Chech JavaScript AJAX Calls For IDOR => Understand Hashing/Encoding and try to find idor => Change request method [DELETE, PUT, PATCH, POST] => Change privileges mode [user to admin, employee to admin] => As Ecommerce site :- focus on Order status, Order history, Account details, PDF download => [+] Let's Action 1. %20, %09, %0b, %0c, %1c, %1d, %1e, %1f, %00, %ff [ add after id for bypass ] [+] Tool or Extension :- 1. Autorize 2. AuthMatrix [+] Hackerone : 1. https://corneacristian.medium.com/top-25-idor-bug-bounty-reports-ba8cd59ad331 [+] Medium 1. https://medium.com/@pratikkaran/idor-to-delete-hall-of-fame-page-273724bd03ed 2. https://16521092.medium.com/some-ways-to-find-more-idor-da16c93954e5 3. https://adipsharif.medium.com/unveiling-all-techniques-to-find-idors-in-web-applications-578d2b8aa28a 4. https://bxmbn.medium.com/i-received-a-bank-offer-in-my-mailbox-and-discovered-an-idor-vulnerability-5-000-bounty-bxmbn-5209cab1fba8 5. https://cysky0x1.medium.com/my-first-p2-idor-insecure-direct-object-references-22d780e59a0d 6. https://hackergandhi.medium.com/my-first-idor-hunting-story-42c71fbe06dc 7. https://imwaiting18.medium.com/2-00-am-idor-leads-to-some-adrenaline-rush-996f710bd55a 8. https://medium.com/@pratyush1337/the-art-of-idor-7-idors-in-edm0d0-b86d683c8de9 9. https://bishal0x01.medium.com/idor-to-massive-government-data-leak-e8ad510d7e5 10. https://amineaboud.medium.com/idor-vulnerability-allowing-any-contact-point-to-be-removed-from-facebook-messenger-instagram-f878b0ab7e71 [+] Linkdin :- 1. https://www.linkedin.com/pulse/csrf-bypass-combined-idor-complete-account-takeover-omar-alzughaibi-my46e/?trackingId=lEV53ShyQwiNuHkQTNz%2Fzw%3D%3D 2. [+] Bunddle :- 1. https://www.bugbountyhunting.com/ 2. https://github.com/reddelexc/hackerone-reports/blob/master/tops_by_bug_type/TOPIDOR.md Specializes in IDOR Vulnerabilit :- 1. Pratyush Anjan Sarangi => https://medium.com/@pratyush1337/about 2. Imran Huda => https://x.com/imranHudaA #bugbountytips #IDOR #authentication #LogicError

๐—Ÿ๐—™๐—œ ๐—”๐˜‚๐˜๐—ผ๐—บ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐——๐—ฒ๐˜๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป + ๐—˜๐˜…๐—ฝ๐—น๐—ผ๐—ถ๐˜๐—ฎ๐˜๐—ถ๐—ผ๐—ป #STEP-1 waymore -i TARGET.COM -mode U --no-subs #STEP-2 cat ~/.config/waymore/results/target.com/waymore.txt | uro | sed 's/=.*/=/' | gf lfi | nuclei -tags lfi

Termux All Command [Telegram Group] - Statistics & analytics of Telegram channel @termuxcommandfull