Termux + NetHunter on Android: Complete Guide + $7,500 SQLi Bug Bounty Story
Termux... What?
Yes, Termux is a terminal emulator that is designed to give you as much of a Linux terminal shell as possible. Thanks to the amazing world of Android devices, using SHELL is just as easy, but Termux makes it smoother and more powered for Linux-Based users.
Let's Get Started
In order to install Termux, we will follow the original Developer's Guide that you can also read here.
Now, at the time of writing this article, the latest version/release of Termux is v0.119.0-beta.3 - 2025-05-22 10:48. While there are a plethora of versions you can use, we will just need to download the "APK" File for the "Universal Build".
Once you have that downloaded, click on "Open". It will ask you how to download, and typically the suggested application installation tool is already selected and you can click confirm. Then, it will ask you to adjust your settings to allow installation. Click the button and toggle the switch, then use your three bars to go back to the installation process and proceed. A few pop-up windows will come up, just accept everything, and you are good to go.
Once this is done, we are not out of the woods yet. This was actually the easiest part.
Installing NetHunter
But Viking, what IS NetHunter? I am glade you asked! NetHunter is literally the Kali Linux operating system, that is packaged and designed to work on a vast range of Android Devices. And for those who are confused, Kali is literally a Debian based Linux distro that is packed full of all types of Hacking Tools, Software Programs, and scripts required to literally handle any hack you need.
How to get started? Easy as pie! We will use the default configurations found directly from Nethunter repository.
When you run the first command, it will pop-up a window, click on allow and then proceed with the rest of the instructions.
When you get to the last command, it will prompt you which Nethunter operation you want to install. I recommend using option 1 for "Full". However, if y ou do not have a lot of storage space, go with the "Minimal" operation for now. Personally, I use the first option and install everything. You never know what you will need.
Post Installation
Alright Viking, we have Termux + Nethunter successfully installed! Now what do we do!?!?!
The first thing I personally enjoy doing, is to ensure that all of the packages and programs are updated and up to date on their upgrades. So, I encourage you to run the following command:
This command will update and upgrade virtually everything on your latest NetHunter installation ensuring all of y our packages are working properly.
Now, you can take it for a test run! Investigate a potential end-point and attempt to use tools.
- Hydra ~ Perfect for brute forcing usernames and passwords.
- SQLMap ~ Ideal for handling SQLi vulnerabilities
- WPScan ~ Here we can use this tool for hacking into WordPress websites.
- Nikto ~ Great for scanning web applications for various information.
- NMap ~ Ideal to handle discovering open ports, service versions, and operating system information.
If you recall from my previous article, Getting Started in Bug Bounty Hunting, we discussed how I discovered an SQLi vulnerability earned $200+ and then purchased a new laptop. So, how did I do that?
I discovered this URL:
So, I ended up placing a very simple, but powerful, symbol at the very end. Right after the number 4, I placed this symbol;
That one symbol gave me this Error Message;
Now, inside of my Termux and NetHunter running, I just typed in the following command;
What the heck is that?!?!
sqlmap ~ Tells the terminal what program to run.
--risk ~ Tells the program how risky we want it to be. 3 is the max, 1 is the lowest. Basically, how quite do we want to be? 1 = quite | 3 = LOUD.
--level ~ We tell the program how aggressive we want to run. 5 is the maximum, and 1 is the lowest.
--random-agent ~ Here we can make it look like our program is coming from a real browser and not trying to hack them in a terminal.
--url ~ You guessed it! The exact Domain that we need to look at!
--dbs ~ We tell the program to display ALL of the database names that it can find on our target.
--batch ~ Here, we tell it to automatically answer questions for us.
And when I was completed, I was left with the following database names.
[*] information_schema
[*] mysql
[*] performance_schema
[*] users
[*] admins
So, I naturally went slightly deeper, was able to easily discover their entire user's database that including sensitive PII information like;
- Full Name
- Email Addresses
- Usernames
- Passwords ~ Had to decrypt these, but sqlmap did that!
- Addresses
- Credit/Debit Cards
- PayPal accounts
And, to show the severity of the impact, I stated that an unethical hacker would be able to pick a random user that had registered and purchased something, discovered their debit card. Then, I ran their card number on an online Card Detector site, discovered it belonged to a Bank of America. Then, I used that customers username and password and was instantly granted access into their bank account. Why is that even possible? 90% of individuals utilize the same email, username, and password for almost ALL of their entire online activities and they think they are safe. When all it takes is literally 1 data breach on a website like this and your entire online presence can be done with.
This was escalated to Critical and paid out $7,500 for this discovery. That is when I used 50% of the funds to pay off debt and my bills, then the other half went into purchasing a whole new computer.
And boy did my hacking journey REALLY take off then!