Skip to content
View muhammadfaizan92's full-sized avatar

Block or report muhammadfaizan92

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
24 stars written in Python
Clear filter

A curated list of bugbounty writeups (Bug type wise) , inspired from https://github.com/ngalongc/bug-bounty-reference

Python 5,394 1,103 Updated Aug 6, 2023

Top disclosed reports from HackerOne

Python 4,974 901 Updated Oct 12, 2025

Email OSINT & Password breach hunting tool, locally or using premium services. Supports chasing down related email

Python 4,711 561 Updated Aug 15, 2023

Server-Side Template Injection and Code Injection Detection and Exploitation Tool

Python 4,063 687 Updated Apr 21, 2024

Reverse proxies cheatsheet

Python 1,854 217 Updated Nov 4, 2023

Burp Plugin to Bypass WAFs through the insertion of Junk Data

Python 1,342 133 Updated Jul 14, 2025

[ Admin panel finder / Admin Login Page Finder ] ¢σ∂є∂ ву 👻 (❤-❤) 👻

Python 646 133 Updated Jan 19, 2025

Check subdomains for subdomain takeovers and other DNS tomfoolery

Python 427 44 Updated Nov 6, 2025
Python 411 79 Updated Oct 29, 2025

Version 0.2 - Exploit Time-based blind-SQL injection in HTTP-Headers (MySQL/MariaDB).

Python 395 108 Updated Mar 24, 2019

A smarter web fuzzing tool that combines local LLM models and ffuf to optimize directory and file discovery

Python 367 50 Updated Nov 26, 2024

Advanced Time-based Blind SQL Injection fuzzer for HTTP Headers

Python 306 53 Updated Mar 31, 2024

Automated Tool for Testing Header Based Blind SQL Injection

Python 289 68 Updated Jul 23, 2023

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Python 287 28 Updated Apr 9, 2024

A hacking tool for bug bounties. Sharing and modifying is encouraged!

Python 244 51 Updated Dec 5, 2022

Self-hosted passive subdomain continous monitoring tool.

Python 168 20 Updated Jan 30, 2024

POC for CVE-2024-36991: This exploit will attempt to read Splunk /etc/passwd file.

Python 126 21 Updated Jul 12, 2024

Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)

Python 91 14 Updated Mar 25, 2024

This script Crawl the website and find the urls that contains html forms.

Python 72 23 Updated Jun 15, 2024

Advanced CORS Header Checker Tool with Vulnerability Detection and Bypass Attempts

Python 66 16 Updated Jun 6, 2025

This script can be used to find html forms in the list of endpoints/urls.

Python 49 12 Updated Mar 24, 2024

All About My Recon

Python 5 Updated Sep 19, 2025
Python 3 Updated Jan 2, 2025

Burp Plugin to Bypass WAFs through the insertion of Junk Data

Python 1 Updated May 26, 2024