ArabianPanel SEARCHER
Black-hat web toolkit · 32 tools · one tap each
☢
GOD MODE
Full-spectrum auto audit
☠
MEGA NUKES
One-command attack chain
☁
SSRF Lab
Cloud metadata · internal net
💣
RCE Lab
Command injection · OOB
🐧
PARROT VM
Full Linux shell in your browser
🔐
JWT Attacker
Crack · alg:none · confusion
🔓
IDOR & BAC
Steal other users' data
🪣
S3 Hunter
Public cloud storage leaks
📂
LFI Lab
Path traversal · file read
🔑
Cred Brute
Credential stuffing
💀
Breach Hunter
GitHub · S3 · HIBP leaks
⌗
SQLi Lab
Injection playground
⚔
XSS Lab
Payload arsenal
🪞
Trust Fuzzer
CORS · open redirect theft
🧮
NoSQLi · LDAP
Auth bypass injection
🐞
Bug Finder
Sqli · xss · cors · cve
🎯
SNIKER
Parallel port scanner
📊
GraphQL Attacker
Introspection · depth · batch
💥
Server Nuke
Fingerprint + misconfigs
🗂
Leak Scan
Sensitive path hunter
🧂
Hash Cracker
Offline md5 / sha
🛡
Web Scan
Deep web app scan
🧪
Pentest Sweep
Auto misconfig audit
🌐
Host Recon
Host deep recon
◈
Bounty Kit
Recon + one-click scans
⚗
Reverse Lab
JS deobfuscate · secrets
✦
Subhunter
CT logs + DNS brute
◉
OSINT
Open-source intel sweep
⌕
Domain Search
DNS · WHOIS · reach
⚡
Service Check
Service + TLS audit
✉
Email Sec
SPF · DKIM · DMARC
📄
Bounty Report
All findings, one report
≡
Activity Log
Live activity stream
DOMAIN SEARCH
Live DNS records (DNS-over-HTTPS), WHOIS (RDAP), HTTP/HTTPS reachability + IP info for a domain.
DNS RECORDS
—
WHOIS (RDAP)
—
HTTP / HTTPS REACHABILITY
—
IP INFO
—
HOST RECON
DNS lookups: A, AAAA, MX, NS and reverse (PTR) records via DNS-over-HTTPS.
—
SERVICE CHECK
Browser-safe reachability probe of web ports. Browsers cannot open arbitrary TCP connections —
full port scanning and banner grabbing is available in the ArabianPanel SEARCHER desktop app.
—
🎯 SNIKER — PARALLEL PORT SCAN
High-speed parallel reachability scan across common service ports. Browsers can only probe
HTTP(S) sockets — SNIKER fires them all at once with a timeout, classifies each as OPEN / FILTERED, and
guesses the service. Only point it at hosts you are authorized to test.
READY
—
BOUNTY KIT
Advanced recon for the browser: certificate transparency, subdomain enumeration,
reachability, external one-click scanners. Only on targets you are authorized to test.
CERTIFICATE (transparency log)
—
SUBDOMAINS FOUND
—
REACHABILITY + IP
—
AUDIT SUMMARY + SCORE
—
☠ MEGA NUKES — ONE-COMMAND BLACK HAT CHAIN ULTIMATE
A single button runs the full attack pipeline against one target: subdomain discovery → data-leak scan → bug hunting → credential brute force → breach hunter → server nuke → hash cracking. Every detection lands in the BOUNTY REPORT.
0 CRITICAL
0 HIGH
0 CREDS FOUND
0 DATA LEAKS
0 SUBDOMAINS
☠ MEGA NUKES READY. Enter a target, choose the engines, then press LAUNCH ALL NUKES. Everything runs client-side through CORS proxies — no account, no trace on your machine.
🔑 CRED BRUTE — DEEP CREDENTIAL STUFFING BRUTEFORCE
Blaster-style credential stuffing against any login endpoint. Auto-detects the username/password field names from the login page, then hammers every username × password combination through CORS proxies and fingerprints successes (redirects, status flips, token patterns, body markers). Found creds are highlighted and pushed to the BOUNTY REPORT.
🔑 CRED BRUTE READY. Set the login URL, pick your wordlists, press BLAST LOGIN. Success = response differs from the "known-bad" baseline AND matches your hints.
💀 BREACH HUNTER — DATA LEAKAGE ENGINE DEEP BREACH
Hunts real leaked data for a domain: exposed secrets in public GitHub code, leaked source (`.git`, `.env`, `.DS_Store`), AWS S3 bucket leaks, HIBP breach records, plus dork-style search links to dig deeper manually.
💀 BREACH HUNTER READY. Enter a domain/email, press HUNT BREACHES. Secrets are scored by type — AWS keys, private keys, JWTs and tokens are flagged CRITICAL.
🐞 BUG FINDER — AUTO VULN SWEEP BLACK HAT
One URL + one parameter → automatic sweep: SQL injection (error + boolean + time-based), reflected XSS, CORS misconfiguration, open redirects, missing security headers, IDOR-style endpoint probing, JSONP, and common CVE-prone endpoints (actuator, swagger, phpmyadmin, wp-json, graphql…). Each hit is severity-rated into the BOUNTY REPORT.
🐞 BUG FINDER READY. Point it at a URL with a query string (e.g. …?id=1). Detections are rated CRITICAL / HIGH / MED / LOW and stored in the BOUNTY REPORT.
💥 SERVER NUKE — FINGERPRINT + MISCONFIG DEEP-DIVE HOST
Full fingerprint of a host: HTTP/HTTPS reachability, server banner, TLS certificate, open web ports, directory listing, exposed admin panels, common dev/ops tooling (actuator, graphql, .well-known), and a deep misconfiguration sweep (HSTS, headers, CORS, robots.txt, default creds hints).
💥 SERVER NUKE READY. Enter a host and press NUKE. Fingerprint + misconfigs stream in below.
🧂 HASH CRACKER — OFFLINE DICT + BRUTE OFFLINE
Cracks MD5 / SHA-1 / SHA-256 / SHA-512 hashes fully offline in the browser (WebCrypto + native MD5). Two modes: dictionary attack against a wordlist, or a character-set brute force up to your length limit. Progress bar, attempts/sec, and instant match display.
Idle. Enter a hash, pick a type and mode, then press CRACK.
☢ GOD MODE — FULL ATTACK SURFACE AUDIT
One-click pipeline: subdomain discovery → DNS deep-dive → email security → web security headers →
TLS → sensitive-file leak scan. Every detection is captured as a severity-graded finding in the Bounty Report.
0CRITICAL
0HIGH
0MEDIUM
0LOW
0INFO
☢ GOD MODE READY. Enter a target domain you are authorized to test, then press ENGAGE GOD MODE. The pipeline runs every advanced tool and streams results here. Findings are automatically stored in the Bounty Report (survives page reload).
SUBHUNTER
Deep subdomain enumeration: Certificate Transparency logs + DNS brute-force, CNAME mapping,
IP clustering, subdomain-takeover watch and reachability.
SUBDOMAINS FOUND
—
TAKEOVER WATCH + CNAME MAPPING
—
IP CLUSTERING (shared infrastructure)
—
REACHABILITY
—
WEB SCAN — SECURITY HEADERS / TLS / HSTS
Full header audit via SecurityHeaders.org engine, HSTS preload status, live HTTPS/TLS posture
check, live certificate (CT logs) and CORS cross-origin probe. One-click link to the MDN HTTP Observatory grade.
SECURITY HEADERS AUDIT
—
HSTS PRELOAD + OBSERVATORY GRADE
—
TLS CERTIFICATE (live)
—
CORS PROBE + EXTERNAL LINKS
—
EMAIL SECURITY AUDIT
SPF / DMARC / DKIM / MTA-STS / TLS-RPT / CAA — the full email-spoofing & spoof-rate analysis
a bounty hunter needs for inbox takeover and business-email-compromise targets.
SPF + DMARC
—
DKIM SELECTOR PROBE
—
MTA-STS + TLS-RPT + CAA
—
SPOOFABILITY VERDICT
—
XSS LAB
Copy-paste payload arsenal + a sandboxed live execution tester that proves which payloads actually run.
PAYLOAD ARSENAL (click ⊘ to copy)
—
SANDBOX EXECUTION TESTER
Paste a JavaScript payload or HTML snippet and press “Run in Sandbox”. The payload executes inside an isolated sandboxed frame (no access to this page). The tester detects: console output, title changes, DOM writes and timers.
SQL INJECTION LAB
Error-based + time-based blind detection against a parameterized URL, with a payload arsenal and
WAF-fingerprint heuristics. Only on parameters you are authorized to test.
TEST RESULTS
—
PAYLOAD ARSENAL
—
LEAK SCAN — SENSITIVE FILE / ENDPOINT DISCOVERY
Browser-safe content probing of classic leak paths (.git, .env, .bak, .svn, backups, admin panels,
debug endpoints, API discovery). Browsers cannot read cross-origin status codes, so the scanner reports
reachable vs blocked paths and flags well-known leak signatures when the target allows cross-origin reads.
LEAK CANDIDATES
—
FULL PROBE LOG
—
BOUNTY REPORT — FINDINGS
Structured findings from every tool, severity-graded, stored locally. Export as a submission-ready text report.
0CRITICAL
0HIGH
0MEDIUM
0LOW
0INFO
No findings yet. Run GOD MODE or any tool — detections land here automatically.
OSINT
Open-source intelligence: search links, dorks, code & paste search, archive + live IP lookups.
—
ACTIVITY LOG
REVERSE LAB — JS DEOBFUSCATOR & SECRET HUNTER
Paste a minified/obfuscated bundle or give a target URL — the lab fetches its scripts and runs reverse-engineering
analysis offline: secret & credential patterns (AWS, GitHub, JWT, Stripe, private keys, DB URLs), obfuscation fingerprints
(eval/atob/\x-hex/obfuscator.io), base64 + charCode decoding, and API endpoint mining. No data leaves the browser.
SECRETS & CREDENTIAL PATTERNS
—
OBFUSCATION FINGERPRINT + SCORE
—
DECODED STRINGS (base64 / \x / fromCharCode)
—
MINED ENDPOINTS & API PATHS
—
PENTEST SWEEP — AUTO MISCONFIGURATION AUDIT
One click, full misconfiguration sweep: 28 sensitive-path probes (.env, .git, backups, actuator, phpMyAdmin…),
robots.txt + sitemap mining for hidden assets, CORS misconfig probe, cookie-flag and clickjacking review, and server fingerprinting.
Findings land in the Bounty Report automatically.
EXPOSURE FINDINGS (paths / files)
—
CORS · CLICKJACKING · COOKIES
—
SERVER FINGERPRINT + HEADERS
—
ROBOTS / SITEMAP MINED ASSETS
—
📖 TUTORIAL — HOW EVERY TOOL WORKS FIELD MANUAL
One entry per tool: what it does, then the black-hat play in red. Read it before you go live — the warning screen said you are responsible.
دليل كل الأدوات: ما تفعله كل أداة ثم الطريقة "غير الشرعية" للاستخدام باللون الأحمر.
دليل كل الأدوات: ما تفعله كل أداة ثم الطريقة "غير الشرعية" للاستخدام باللون الأحمر.
🐧PARROT VMDANGER 10/10
Legit: a sandboxed Parrot-Linux-style console for your own lab — run nmap, dig, curl, neofetch against hosts you own, crack your own hashes offline, browse your own pages. Zero install, 100% client-side, nothing leaves your machine except the requests you fire.
HOW TO USE IT ILLEGALLY
A full attack console on the victim's turf: nmap live-probes every port in the top-30 set and flags the dangerous ones (MySQL, Redis, RDP, Docker…), dirb/gobuster crawls the 100+ leak paths (.git, .env, backups, admin panels, actuator), hydra fires the built-in 120×180 wordlists at their login, john/hashcat crack any md5/sha hash you stole, dig/whois pull the DNS + registration record, curl grabs raw pages — and the one-shot run <target> chains it all in seconds. Every hit lands in the BOUNTY REPORT with severity. The victim's firewall only sees traffic from the panel's CORS-proxy IPs — your home IP never shows up.🔑CRED BRUTEDANGER 9/10
Legit: test your own login page against a wordlist to find weak passwords before your users do.
HOW TO USE IT ILLEGALLY
Point it at the victim's login (/wp-login.php, /admin, /cpanel). Leave the lists blank → the built-in black-hat wordlists fire: 150 usernames × 300+ passwords, all the leaked classics (admin/admin123, P@ssw0rd, root2026…). Set DELAY MS to 300+ so the WAF doesn't ban you, and put the site's success markers in SUCCESS HINTS (a 302 to the dashboard, "Welcome back"). One match = full account takeover. The site only sees requests coming from the CORS-proxy IPs — not yours.☠MEGA NUKESDANGER 10/10
Legit: one-click full self-audit of your own domain before a release or after an incident.
HOW TO USE IT ILLEGALLY
The full recon strike in one button: subdomain discovery → leak scan → bug sweep → credential brute → breach hunter → server nuke → hash crack, chained automatically, everything logged into the Bounty Report. Run it at 3 AM on the victim's domain, keep the report, and you have their complete attack surface mapped before they notice a single extra request in their logs.☢GOD MODEDANGER 8/10
Legit: map the complete attack surface of a host you own before you ship it.
HOW TO USE IT ILLEGALLY
Full-spectrum audit of a foreign host in under a minute: which server they run, which framework, every exposed endpoint, weak TLS, missing headers. That's the attacker's attack map — the exact same pass a pentester runs before day one of an engagement. Read the SERVER FINGERPRINT section and you know exactly which exploits to pull out next.💀BREACH HUNTERDANGER 7/10
Legit: check your own GitHub org and domain for leaked secrets before they find you.
HOW TO USE IT ILLEGALLY
Hunt the victim's GitHub for committed .env files (AWS keys, DB passwords), public S3 buckets, and check breach databases for their domain's leaked credentials. Most companies push secrets to public repos and never look back — one hit and you can hit their infrastructure directly, often without touching their website at all.🐞BUG FINDERDANGER 8/10
Legit: sweep your own app for SQLi / XSS / CORS / redirect bugs before the bounty hunters do.
HOW TO USE IT ILLEGALLY
Point it at the victim's search box: boolean + time-based SQLi, reflected XSS, CORS misconfig, open redirects, CVE-prone endpoints (actuator, swagger, phpMyAdmin) and IDOR-style probes in one pass. Then chain the hits: open redirect → the victim's OAuth login URL → their auth code lands in your inbox. That's a full session theft with zero code execution on their side.⌗SQLi LABDANGER 9/10
Legit: test your own endpoints for injection with safe payloads on staging.
HOW TO USE IT ILLEGALLY
If a search returns records for 1=1 but "no results" for 1=2, the field is boolean-blind SQLi. Fire the time payload (SLEEP(3)): if the page visibly waits ~3s, you can extract the database password character by character — no error messages needed. Then the UNION payload dumps the users table: username, email, and the password hashes straight into your response. Hand the hashes to the Hash Cracker and the victim's own account is yours.⚔XSS LABDANGER 9/10
Legit: find reflected/stored XSS in your own app with the payload arsenal on a test account.
HOW TO USE IT ILLEGALLY
Drop a stored-XSS payload into the victim's comment box, profile name, or support ticket. It sits there invisible. Next time an admin opens that page, the payload runs inside the admin's session and exfiltrates their session cookie to your server. One stored payload = admin panel takeover, and the victim's whole platform runs under your badge.💥SERVER NUKEDANGER 7/10
Legit: fingerprint your own server and catch misconfigurations (headers, exposed endpoints) before customers do.
HOW TO USE IT ILLEGALLY
Most Java/Spring apps ship with /actuator/env open — that endpoint literally prints the DB password and API keys from their config. /swagger.json hands you every hidden admin API. Probe both on the victim's host and you often skip straight past authentication entirely.🎯SNIKERDANGER 7/10
Legit: parallel-scan your own infrastructure for forgotten open ports.
HOW TO USE IT ILLEGALLY
Hammer 1,000 ports in parallel on the victim's IP and look for the classics: RDP 3389, VNC 5900, and the forgotten Redis on 6379. An unauthenticated Redis instance is remote code execution in most cases — set a key, write a cron, own the box.🗂LEAK SCANDANGER 7/10
Legit: sweep your own site for exposed .env / .git / backup files.
HOW TO USE IT ILLEGALLY
If the victim's /.env exists, their DB password and secret signing keys are sitting there in plain text. A leaked /.git is worse: you can reconstruct the entire source-code history, including secrets they deleted "last week". One directory listing and the site is effectively open source.🧂HASH CRACKERDANGER 6/10
Legit: verify your own password storage — can your hashes be cracked offline?
HOW TO USE IT ILLEGALLY
Grab a leaked password hash (from an SQLi dump, an .env, a breach DB), paste it here, and the offline dictionary + brute engine cracks MD5/SHA in seconds. The victim never sees you — this happens entirely on your machine. Cracked hash → login as them anywhere that password is reused.⚗REVERSE LABDANGER 7/10
Legit: audit your own SPA's JavaScript bundle for accidentally bundled secrets.
HOW TO USE IT ILLEGALLY
Pull the victim's app.js (or paste it directly), deobfuscate it, and let the secret hunter comb out API keys, AWS credentials, Firebase configs, JWT signing secrets, and hidden admin routes. Teams ship their backend secrets inside the frontend bundle every single week — and nobody reads their own bundle.🛡WEB SCANDANGER 5/10
Legit: check your own site's security headers, TLS, and HSTS config.
HOW TO USE IT ILLEGALLY
Missing Strict-Transport-Security means you can force the victim onto HTTP and run a classic MITM at their coffee shop. No Content-Security-Policy means your XSS payloads face no resistance. Two missing headers and the victim's session is fair game.🌐HOST RECONDANGER 5/10
Legit: deep recon on your own host to see exactly what the internet can see.
HOW TO USE IT ILLEGALLY
Banner grabbing, cert inspection, open web ports, exposed admin panels and dev tooling (graphql, .well-known, actuator) — the complete "what can I touch" pass on a foreign host. Pair it with SNIKER and you have the full perimeter in minutes.◈BOUNTY KITDANGER 5/10
Legit: start your own bug-bounty hunting on a target you're allowed to test.
HOW TO USE IT ILLEGALLY
Recon + one-click vulnerability scans against a company that hasn't announced a program yet: find the bug, log it in their issue tracker as a "user report", and wait for the reply. Same bug, friendlier cover story.✦SUBHUNTERDANGER 5/10
Legit: enumerate your own subdomains to find forgotten assets in your own org.
HOW TO USE IT ILLEGALLY
Certificate-transparency logs + DNS brute-force against the victim's zone: staging.test, old-admin, internal-api, backup-2019. Old subdomains are where weak passwords and outdated software live — and they're the ones nobody renews or watches.⌕DOMAIN SEARCHDANGER 4/10
Legit: check DNS / WHOIS / reachability of domains you manage.
HOW TO USE IT ILLEGALLY
WHOIS on the victim's domain exposes the registrar, admin contacts, and expiry date. Expiry + no auto-renew = you can squat the domain the day it drops. MX records tell you where their mail flows — the next tool to test is always mail.◉OSINTDANGER 4/10
Legit: see what's already public about your own brand and team.
HOW TO USE IT ILLEGALLY
Open-source intelligence sweep: what the victim's team posts, shares, and forgets — cloud storage links, pastebin dumps, social posts with internal screenshots. Zero packets sent to the victim. By the time they notice, you already know their architecture, their codenames, and who works on the security team.⚡SERVICE CHECKDANGER 4/10
Legit: verify your own services and TLS config stay healthy.
HOW TO USE IT ILLEGALLY
Service banners and TLS audit on a foreign host: which service, which version, which ciphers. An old OpenSSL version with a known CVE and you can skip straight to the exploit — no login page required.✉EMAIL SECDANGER 4/10
Legit: audit your own SPF / DKIM / DMARC so your mail isn't spoofed.
HOW TO USE IT ILLEGALLY
If the victim's domain has no DMARC (or a soft one), you can send mail that looks like it came from ceo@victim.com to their own employees. "Urgent: invoice attached" → the whole chain clicks. Email is still the #1 breach vector, and most companies have zero DMARC.🧪PENTEST SWEEPDANGER 5/10
Legit: automated misconfiguration audit of your own app before a release.
HOW TO USE IT ILLEGALLY
One click on a foreign target: 28 sensitive-path probes, robots/sitemap mining for hidden assets, CORS misconfig probe, cookie-flag and clickjacking review, server fingerprint — the whole "what did they leave open" pass, reported and severity-rated. Read-only, fast, and it leaves almost nothing in their logs.📄BOUNTY REPORTDANGER 2/10
Legit: collect every finding from every tool into one exportable report.
HOW TO USE IT ILLEGALLY
Your case file. Every hit from every tool — SQLi, XSS, CORS, exposed endpoints, leaked creds — lands here automatically with severity ratings. Print it, timestamp it, attach it to your "polite email" to the victim. In a dispute, the report is the proof you were watching.≡ACTIVITY LOGDANGER 2/10
Legit: a live stream of everything the toolkit has done this session.
HOW TO USE IT ILLEGALLY
Your alibi trail — or your mistake trail. It records every probe, every hit, every tool run. Review it before you send the report; a careless entry ("BRUTE FORCE: 12,400 combos against admin@victim.com") is the kind of line defenders screenshot first.☁SSRF LABDANGER 10/10
Legit: verify your own image-preview / URL-import feature only fetches allowed hosts before it goes live.
HOW TO USE IT ILLEGALLY
Find any field where the victim's server fetches your URL (preview, import, webhook, "load image from URL"). Feed it the cloud metadata address: if the response leaks ami-id or IAM role names, you can fetch temporary AWS keys for that machine — full cloud access without one password. Then the loopback and RFC1918 vectors reach internal panels nobody can see from the internet. This is how "one form field" becomes "their whole cloud".💣RCE LABDANGER 10/10
Legit: time-based blind checks on your own debug / ping / lookup endpoints in staging.
HOW TO USE IT ILLEGALLY
Any parameter that reaches a shell (ping tools, hostname lookups, "notify by URL") is a candidate. The sleep vectors answer the only question that matters: did my command run? A 5-second delay = your code is executing on their machine. The OOB DNS callback confirms it even when the response shows nothing — point the callback at your interactsh/OAST box, read the hit, and you have remote command execution to chain into a shell, a keygen, or a backdoor.🔐JWT ATTACKERDANGER 10/10
Legit: audit your own token secrets and catch alg:none / key-confusion bugs before auth0-style reviews do.
HOW TO USE IT ILLEGALLY
Steal one token from anywhere — leaked localStorage, a breach dump, a logged-in victim's cookie. The tool decodes the claims (you now know their user ID, role, expiry) and cracks the HMAC secret offline at dictionary + brute speed. Weak secret (and most are) = you sign a token as any user, including admin, and the server accepts it like it's their own. The alg:none and HS↔RS confusion forgeries are handed to you ready-to-send.🔓IDOR & BACDANGER 9/10
Legit: verify your own object endpoints check ownership and authorization on every route.
HOW TO USE IT ILLEGALLY
Log in as a low-value account, copy your own invoice/profile/order URL, and run the matrix: sibling IDs, /admin twins, case tricks, encoding, parameter duplication. Any variant that returns 200 with different content is someone else's data — read the invoices, the private profiles, the API records. A 403→200 flip means the access-control check was bypassed entirely. This is the most common "real data stolen" bug in modern web apps.🪣S3 HUNTERDANGER 9/10
Legit: discover your own company's stray public buckets before someone else does.
HOW TO USE IT ILLEGALLY
Enter the victim's company name — the tool builds ~200 bucket candidates (backup, staging, tmp, db, 2024…2026 variants) and probes AWS + GCS. Public buckets expose full listings: old site backups with wp-config.php, database dumps, .env files, internal images, user uploads. Teams create "temporary" buckets and never delete them. One open bucket is usually the whole company's data, world-readable, with no auth at all.📂LFI LABDANGER 9/10
Legit: test your own template / file / page parameters for traversal on staging with safe payloads.
HOW TO USE IT ILLEGALLY
Any "page=", "file=", "template=" parameter is a target. The tool fires Linux, Windows, double-encoded, null-byte and php://filter sequences. Seeing "root:x:0:0" means you just read /etc/passwd; the php filter hands you the source code base64-encoded, where DB passwords and API keys sit in plain text. Log files (auth.log, nginx access) leak sessions and cookies — the classic LFI→RCE chain starts here.🪞TRUST FUZZERDANGER 8/10
Legit: verify your own API's CORS policy and redirect parameters before a feature release.
HOW TO USE IT ILLEGALLY
Two trust-confusion chains. One: if the API reflects an attacker Origin with credentials allowed, a single line of JS on your own site reads the victim's authenticated API responses — cookies, data, everything — silently. The null-origin iframe test proves it live. Two: open redirects in login/oauth/redirect parameters let you send the victim's auth code or session to your domain — full account takeover with zero code execution on their side. Both are one-click chains here.🧮NOSQLI · LDAPDANGER 8/10
Legit: test your own Mongo-based login and directory integrations with the same payloads.
HOW TO USE IT ILLEGALLY
Modern apps talk to Mongo and LDAP and still glue user input straight into the query. The tool fires blind boolean NoSQL vectors ($gt, $ne, array bypass) and LDAP wildcard patterns at the login endpoint. If a nonsense username + truthy payload behaves like a real login, authentication is gone — walk in as admin without a single password. On LDAP, the objectClass wildcard is the same trick against the directory service itself.📊GRAPHQL ATTACKERDANGER 7/10
Legit: check your own /graphql endpoint for open introspection, batching and depth limits.
HOW TO USE IT ILLEGALLY
GraphQL is a self-describing API. One introspection query dumps the entire schema — every type, field and mutation — a complete map of what data exists and how to pull it. Batching floods rate limits, alias flooding melts slow backends, and verbose errors leak field names when the query is wrong. The tool runs all of it and hands you the type inventory to build your real data-extraction queries.☁ SSRF LAB — CLOUD METADATA & INTERNAL NET PIERCER CRITICAL
Feeds the target its own fetching parameter so the server requests what you choose: cloud instance metadata (AWS IAM temp keys, GCP/Azure tokens), loopback & RFC1918 internal services, and protocol smuggling (file/dict/gopher). Any signature hit = a foothold inside the victim's infrastructure.
☁ SSRF LAB READY. Paste a URL where the server fetches a user-supplied link (preview, import, webhook, image proxy). A metadata hit means the cloud's temporary keys for that machine are one more request away.
💣 RCE LAB — REMOTE CODE EXECUTION HUNTER CRITICAL
Fires blind command-injection vectors (shell, PHP, Windows, time-based sleep) against a parameter, then confirms execution out-of-band through a DNS callback domain you control. One confirmed OOB = your command ran on their host.
💣 RCE LAB READY. Time-blind vectors wait 5 seconds — if the target's answer takes 5s longer than baseline, your command executed. The OOB DNS callback confirms execution on fully blind targets (point it at your interactsh / OAST box).
🔐 JWT ATTACKER — TOKEN CRACKER & FORGER SESSION THEFT
Decodes any JWT's claims, cracks its HMAC secret fully offline (dictionary + brute force via WebCrypto), forges the unsigned alg:none variant, and flags key-confusion and kid-injection vectors. A cracked secret = you sign tokens as any user, forever.
🔐 JWT ATTACKER READY. Paste a stolen/leaked token (victim's localStorage, a breach dump, a GitHub leak). Weak secret found → the FORGED TOKEN below is a valid session as the same user.
🔓 IDOR & BAC — INSECURE OBJECT DATA THEFT DATA THEFT
Takes one authenticated object URL (profile, invoice, order, API record) and auto-generates the full variant matrix: sibling IDs, /admin twins, case & encoding tricks, traversal, parameter duplication. Status and content flips expose other users' data and broken access control.
🔓 IDOR & BAC READY. Paste the URL of your own object, run the matrix, and watch for 200s with different content — that's someone else's data. A 403→200 flip means the access-control check itself was bypassed.
🪣 S3 HUNTER — PUBLIC CLOUD STORAGE LEAKS DATA LEAK
Brute-forces candidate S3 / GCS bucket names derived from the victim (company, backup, staging, db, 2024–2026 variants) and probes each for public listing and known sensitive keys. Companies leave full data dumps in "temporary" buckets they never delete.
🪣 S3 HUNTER READY. Enter the company name or domain — the tool builds ~200 bucket candidates and probes the live ones on AWS + GCS.
📂 LFI LAB — LOCAL FILE INCLUSION & TRAVERSAL FILE READ
Fires Linux, Windows, URL/double-encoded, null-byte and php://filter traversal sequences at a file parameter and flags the classic signatures: root:x:0:0 (/etc/passwd), [fonts] (win.ini), base64 source dumps and private keys. Source-code read = secrets in plain sight.
📂 LFI LAB READY. A response containing "root:x:0:0" means the server read /etc/passwd for you. php://filter hits hand you the source code — DB passwords and API keys included.
🪞 TRUST FUZZER — CORS & OPEN REDIRECT THEFT TRUST CONFUSION
Live-tests the target's CORS policy with a real Origin: null iframe request plus the panel-origin probe, then hammers redirect parameters with open-redirect vectors (//evil, \@evil, lookalike domains) to chain OAuth token capture and silent cookie theft.
🪞 TRUST FUZZER READY. ACAO reflecting an attacker origin + credentials = any site reads the victim's API with their cookies. Open redirect in login/oauth/redirect params = the victim's auth code lands on your domain.
🧮 NOSQLi · LDAP — MODERN INJECTION & AUTH BYPASS AUTH BYPASS
Blind boolean NoSQL vectors ($gt, $ne, array bypass, regex) against Mongo-backed login/search APIs, plus LDAP wildcard patterns for directory services. Classic 1=1 bypasses on modern stacks are still everywhere — one hit drops authentication entirely.
🧮 NOSQLi · LDAP READY. If a nonsense user + truthy NoSQL payload behaves like a real login, the stack is gluing your JSON straight into the query — authentication is gone.
📊 GRAPHQL ATTACKER — SCHEMA DUMP & QUERY ABUSE API
Dumps the full schema via introspection when open, then tests query batching, alias flooding, depth limits, persisted-query oracles and error verbosity. An open introspection endpoint is the victim's complete API map in a single response.
📊 GRAPHQL ATTACKER READY. Enter the /graphql endpoint — the tool maps the schema, then probes the abuse vectors.
🐧 PARROT WEB VM — LIVE IN-BROWSER PENETRATION OS FULL SHELL
A Parrot-Linux-style desktop that boots inside your browser. Open the terminal and run nmap · dirb · sqlmap · hydra · john · dig · whois · curl · msfconsole · neofetch — each one is wired to the panel's live engines and pushes hits straight into the BOUNTY REPORT. Browse the virtual file system, crack hashes offline, and render any target in the built-in web view. 100% client-side. Point it only at targets you are authorized to test.
Activities
🐧 Parrot Sec · Web VM
📶 up
--:--:--
🔋 100%
root@parrot: ~ TERMINAL
,-----. Parrot Web VM v5.0 — a full penetration console in your browser.
| ,*^ Every command below runs LIVE through the ArabianPanel engines (no fakes).
| (*) Type help to list every tool, or run <target> for the one-shot attack chain.
`-(*,-' Only attack targets you are authorized to test.
root@parrot:~#
Files /
Web view BROWSER
Enter a URL and press GO — the page is fetched through the panel's CORS engine and rendered here (sandboxed). This is your "web screen".
Editor payload.sh