- Dhaka, Bangladesh
- https://sites.google.com/view/tasfiul441/home
- @tasfiul_hedayet
Lists (2)
Sort Name ascending (A-Z)
Starred repositories
π RuView turns commodity WiFi signals into real-time spatial intelligence, vital sign monitoring, and presence detection — all without a single pixel of video.
Use Garry Tan's exact Claude Code setup: 23 opinionated tools that serve as CEO, Designer, Eng Manager, Release Manager, Doc Engineer, and QA
A Bash script for automated nuclei dast scanning by using passive urls
Source control for agents. Use multiple coding agents, track their changes and query them in one place
Supports RSC fingerprinting and exploitation of the React component vulnerability CVE-2025-55182.
176 vulnerabilities in Samsung preinstalled Android apps
A powerful and lightweight tool for bug bounty hunters and security researchers to identify hardcoded secrets, API keys, tokens, credentials, and other sensitive data in code repositories, web appl…
A community-powered collection of all known bug bounty platforms, vulnerability disclosure platforms, and crowdsourced security platforms currently active on the Internet.
⚔️ Community maintained directory, MCP and API of 3,000+ active bug bounty programs and VDPs
Legitimate bug bounty programs value ethical practices and provide clear rewards to researchers for identifying security flaws
SelfHosted - Bug Bounty Programs | Discover new and fresh bug bounty programs across platforms. Updated frequently to always display the newest public programs.
A ruby gem for defending against Server Side Request Forgery (SSRF) attacks
This project crawls bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) hourly and dumps them into the bounty-targets-data repo
Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh
Master Thick Client Penetration Testing: Explore practical methodologies, uncover vulnerabilities, and enhance security.
Turbo Intruder is a Burp Suite extension for sending large numbers of HTTP requests and analyzing the results.
A simple Python tool for performing Google Dorking on a target domain to gather information and discover potential vulnerabilities. This script automates the process of running multiple dork querie…
Swift SDK for fetching and filtering Forex Factory's weekly financial events with ease.
Automatic SQL injection and database takeover tool
Open-source Claude Code skills, agents, and slash commands for AI-powered penetration testing, bug bounty hunting, and security research
The Template Injection Table is intended to help during the testing of an application for template injection vulnerabilities.
🎯 Chrome Extension - Passive scanner for Dependency Confusion vulnerabilities in npm/PyPI packages
c0dejump / iis_tilde_enum
Forked from esabear/iis_tilde_enumTakes a URL and checks the system for the tilde enum vuln and then find the files.
GimmeYourPassword (GYP) is a tool designed to perform tests on reset password features on websites and analyze the results to identify vulnerabilities and interesting behaviors