Skip to content
View h4x0rl33tx's full-sized avatar
🥷
Hunting
🥷
Hunting

Block or report h4x0rl33tx

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
62 results for source starred repositories
Clear filter

Tips and Tutorials for Bug Bounty and also Penetration Tests.

1,645 389 Updated Oct 7, 2025

Tools and methods that I personally use for Recon and Exploitations

46 19 Updated May 1, 2025

💀 Generate a bunch of malicious pdf files with phone-home functionality. Can be used with Burp Collaborator or Interact.sh

Python 3,596 465 Updated Nov 14, 2025
HTML 11 6 Updated Oct 25, 2021

An Automated Subdomain Enumeration Tool

Shell 290 64 Updated Oct 16, 2024

A security research tool designed to intercept and analyze OAuth requests.

Python 6 Updated Feb 20, 2025

Reflected XSS Payload List for Vue.js (2 & 3)

15 4 Updated Jan 12, 2023

Repositories, Links, Payloads, Blogs, Tools, etc.. which I think might be useful for pentesting and bug bounty

48 5 Updated Jan 6, 2026

jsleak is a tool to find secret , paths or links in the source code during the recon.

Go 572 62 Updated Sep 25, 2025

60k+ WordPress Nuclei templates, updated daily from Wordfence intel—filter by severity/tags/CVE and scan in one line. 🚀🔒

Python 1,191 150 Updated Feb 4, 2026

A list of interesting payloads, tips and tricks for bug bounty hunters.

6,371 1,613 Updated Sep 14, 2023

Pentesting and Bug Bounty Notes, Cheetsheets and Guide for Ethical Hacker, Whitehat Pentesters and CTF Players.

PHP 590 89 Updated Jan 31, 2026

HackerOne资产更新 | 每日更新HackerOne资产,对HackerOne的资产进行爬行和整理,SRC资产更新仅会增加,不会进行删除,每天更新的可以进行差异化对比来获取到新的项目资产范围

Python 312 229 Updated Feb 3, 2026

List of XSS Vectors/Payloads

1,358 269 Updated Jan 14, 2026

Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are already exploitable, so we can report them. We wis…

Go 5,183 952 Updated Jan 31, 2026

Nuclei POC,每2小时更新 | 自动整合全网Nuclei的漏洞POC,实时同步更新最新POC,保存已被删除的POC。通过批量克隆Github项目,获取Nuclei POC,并将POC按类别分类存放,使用Github Action实现。已有41w+POC,其中3.5w+高质量POC

1,910 532 Updated Feb 4, 2026

HackerOne "in scope" domains

Python 498 133 Updated Feb 4, 2026

Secrets Patterns DB: The largest open-source Database for detecting secrets, API keys, passwords, tokens, and more.

Python 1,321 164 Updated Aug 6, 2025

This repo contains hourly-updated data dumps of bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) that are eligible for reports

3,625 648 Updated Feb 4, 2026

Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥

Python 7,347 1,164 Updated Aug 28, 2025

A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnerability.

Go 409 83 Updated Dec 16, 2025

Generate HTML/SVG payloads for testing Server-Side Request Forgery vulnerabilities

Python 1 Updated Dec 5, 2025

JNDI注入测试工具(A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability,like Jackson,Fastjson,etc)

Java 2,780 738 Updated Mar 22, 2023

A small collection of File converter vulnerability

10 2 Updated Mar 22, 2022

Webshell && Backdoor Collection

PHP 1,985 1,036 Updated Apr 6, 2020

A collaborative hub for Nuclei templates. Contribute, share, and explore powerful vulnerability detection tools!

50 10 Updated Feb 1, 2025

针对SpringBoot的开源渗透框架,以及Spring相关高危漏洞利用工具

Python 2,208 180 Updated Nov 9, 2025

SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list

Java 6,113 1,322 Updated Mar 10, 2021
Next