Lists (24)
Sort Name ascending (A-Z)
android pentest
api pentesting
burpsuite utilized
Bypass (4xx)
checklists, methodologies
code review, devsecops
general stuffs
ios pentest
node stuffs
payloads
pentest note taking apps
recon (application)
recon (assets)
recon (dorks, queries)
recon (javascripts)
vulnerable android apps
vulnerable ios apps
vulnerable [web] apps
vulns (open redirect)
vulns (sqli)
vulns (ssrf)
vulns (xss)
wlists
writeups & edu
Stars
Easily and securely send things from one computer to another 🐊 📦
Network-wide ads & trackers blocking DNS server
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
A self-hosted dashboard that puts all your feeds in one place
Find, verify, and analyze leaked credentials
The most customisable and low-latency cross platform/shell prompt renderer
Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are already exploitable, so we can report them. We wis…
🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.
A powerful browser crawler for web vulnerability scanners
Gospider - Fast web spider written in Go
Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.
40X/HTTP bypasser in Go. Features: Verb tampering, headers, #bugbountytips, User-Agents, extensions, default credentials...
CF-Hero is a reconnaissance tool that uses multiple data sources to discover the origin IP addresses of Cloudflare-protected web applications
Extract URLs, paths, secrets, and other interesting bits from JavaScript
MassDNS wrapper written in go to enumerate valid subdomains using active bruteforce as well as resolve subdomains with wildcard filtering and easy input-output support.
A fast tool to scan CRLF vulnerability written in Go
🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise. Effective.
Extract JavaScript source trees from Sourcemap files
fuzzuli is a url fuzzing tool that aims to find critical backup files by creating a dynamic wordlist based on the domain.
Fast and customizable subdomain wordlist generator using DSL
Accept URLs on stdin, replace all query string values with a user-supplied value