Skip to content
View muhammadfaizan92's full-sized avatar

Block or report muhammadfaizan92

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

1337 Wordlists for Bug Bounty Hunting

903 176 Updated Sep 6, 2025

The only GraphQL wordlist you'll ever need. Operations, field names, type names... Collected on more than 60k distinct GraphQL schemas.

TypeScript 436 44 Updated Oct 3, 2023

These are my checklists which I use during my hunting.

HTML 743 94 Updated Nov 30, 2023

Subdomain Enumerator and Simple Crawler

Rust 154 48 Updated Aug 24, 2025
Python 410 79 Updated Oct 29, 2025

Check subdomains for subdomain takeovers and other DNS tomfoolery

Python 427 44 Updated Nov 5, 2025

This repo contains different variants of Bug Bounty & Security & Pentest & Tech related Articles

49 8 Updated Jan 7, 2025
1 Updated May 6, 2025

Mind-Maps of Several Things

2,602 548 Updated Jun 29, 2023
Python 3 Updated Jan 2, 2025

A smarter web fuzzing tool that combines local LLM models and ffuf to optimize directory and file discovery

Python 365 49 Updated Nov 26, 2024

Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port scanning; Fuzz, HW, awesome BugBounty( ͡° ͜ʖ ͡°)...

Go 5,896 706 Updated Jul 12, 2024

An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability

921 119 Updated Dec 31, 2021

A Bash script to monitor the status of hosts. It allows you to add, remove, display, clean duplicate entries, and count unique IP addresses. Use long (--add, --clean) or short (a, c) command option…

Shell 8 2 Updated Oct 12, 2024

Version 0.2 - Exploit Time-based blind-SQL injection in HTTP-Headers (MySQL/MariaDB).

Python 395 108 Updated Mar 24, 2019
126 20 Updated Aug 19, 2025

Advanced CORS Header Checker Tool with Vulnerability Detection and Bypass Attempts

Python 66 16 Updated Jun 6, 2025

PDF Files for Pentesting

657 101 Updated Oct 4, 2024

This Repositories contains list of One Liners with Descriptions and Installation requirements

496 82 Updated Jun 28, 2025

Scrape domain names from SSL certificates of arbitrary hosts

Go 686 91 Updated Mar 31, 2024

A browser extension that allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.

JavaScript 714 73 Updated Oct 28, 2025

🕵️‍♂️ All-in-one OSINT tool for analysing any website

TypeScript 26,804 2,150 Updated Aug 3, 2025

A really fast http prober.

Rust 41 8 Updated Feb 1, 2024

Reverse proxies cheatsheet

Python 1,854 217 Updated Nov 4, 2023

POC for CVE-2024-36991: This exploit will attempt to read Splunk /etc/passwd file.

Python 126 21 Updated Jul 12, 2024

[ Admin panel finder / Admin Login Page Finder ] ¢σ∂є∂ ву 👻 (❤-❤) 👻

Python 646 133 Updated Jan 19, 2025

Scope aggregation tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!

Go 1,209 167 Updated Oct 17, 2025

GH-Takeover — GitHub Pages Sub-domain Takeover Automation!

Shell 29 5 Updated Apr 17, 2021
Next