Curated collection of bug bounty notes and tutorials in one place. Visit the link below to view the docs.
-
Updated
Apr 19, 2025 - JavaScript
A bug bounty program is a deal offered by many websites, organizations and software developers by which individuals can receive recognition and compensation for reporting bugs, especially those pertaining to security exploits and vulnerabilities.
Curated collection of bug bounty notes and tutorials in one place. Visit the link below to view the docs.
Chrome extension to scrape Shodan host & domain pages and export IPs, ports, subdomains, and DNS records.
Sistema de notas propositalmente vulnerável para educação em segurança cibernética e testes de penetração - contém 12+ vulnerabilidades web intencionais (SQL Injection, XSS, Path Traversal, Command Injection, etc.)
The official DSC-RIT Bug Bounty 2020 codes.
small and simple tool for generating a list and searching for Google Dork to identify leaked files and save the scan result. Useful tools for Bug Bounty
BeyondSub is a powerful subdomain enumeration tool that uses over 25 techniques to discover, analyze, and assess subdomains' security. Its modular design lets users customize scans for different purposes—ideal for security researchers, bug bounty hunters, and system administrators.
Contains security vulnerabilities payloads and exploits that I come across or use
Active Recon Framework Web Management
Blog for computer stuffs and whatnot.
The "Hacksmith Shop" Vulnerable Web Application
A powerful and flexible web crawler built with Node.js. This tool allows you to crawl websites, extract links, and filter results based on various criteria.
Social Network for hackers, pentesters, and bug hunters
Lab to understand and test SSRF attacks
npm PoC packages
🔍 Customize your new tab with Hacker Search, a modern Chrome extension featuring a matrix-inspired design and powerful search widgets.
The Internet Observatory (Obsrva) is a vulnerability research project founded by independent security researcher Tyler Butler. Obsrva engages product vendors in coordinated disclosures, publishes vulnerability advisories, and creates proof of concept exploits.
⚡ JavaScript-aware crawler for security researchers and bug bounty hunters. Extract hidden endpoints and internal subdomains through static and semantic analysis of JS files. Lightweight. Fast. Sneaky.