Payload Delivery Server for Web Exploits
-
Updated
Mar 30, 2025 - Java
A bug bounty program is a deal offered by many websites, organizations and software developers by which individuals can receive recognition and compensation for reporting bugs, especially those pertaining to security exploits and vulnerabilities.
Payload Delivery Server for Web Exploits
Vulnerable Android application for developers and security researchers to learn about Android penetration testing/ bug bounty hunting. Updated to run with Python 3.
🔍 Discover and exploit web vulnerabilities with WebPwn, your go-to tool for enhancing web security testing and vulnerability assessments.
PwnFox is an extension for Burp Suite
PoC of Android deep link abuse for app impersonation
BSMAPREC is a Burp Suite extension that automatically detects and extracts source maps from JavaScript files. It helps security researchers and developers identify and analyze the original source code of minified JavaScript files.
Sitemap Exporter is an extension for Burp Suite that lets you export items from the Site Map to files on your disk.
Add a local REST API to Burp Suite Pro for instant, scriptable control of proxy, scanning, and scope.
extract social media accounts and check if possible to hijacking
🔍 Discover and analyze historical URLs from the Wayback Machine in Burp Suite to enhance your bug bounty and penetration testing efforts.
Some useful files for upload features pentesting
Buggyapp is an vulnerable android application. This app can be used by pentesters, security researchers to practice Android application pentesting. This is build for beginners to learn basics about Android application pentesting
A handy plugin for copying requests/responses directly from Burp, some extra magic included.
Lightweight BApp that seamlessly integrates powerful LLM-scanning capabilities into Burp's built-in Scanner with improved accuracy. Supports the latest LLMs from OpenAI (gpt-4o, o1), Anthropic (Claude 3.5, Claude 3), and Google (Gemini 1.5). Requires valid API key(s) and an active Burp Suite Pro or Enterprise license.
Burp Extension for BFAC (Advanced Backup-File Artifacts Testing for Web-Applications)
SALSA 💃⚡ - SALesforce Scanner for Aura (and beyond). Enumeration of vulnerabilities and misconfigurations against Salesforce endpoint.