bugbounty
Here are 371 public repositories matching this topic...
Updates to this repository will continue to arrive until the number of links reaches 10000 links & 10000 pdf files .Learn Ethical Hacking and penetration testing .hundreds of ethical hacking & penetration testing & red team & cyber security & computer science resources.
-
Updated
Jun 16, 2020
Automated pentest framework for offensive security experts
-
Updated
Jun 11, 2020 - Shell
Fully automated offensive security framework for reconnaissance and vulnerability scanning
-
Updated
Jun 11, 2020 - Python
A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.
-
Updated
Jun 10, 2020 - BitBake
OneForAll是一款功能强大的子域收集工具
-
Updated
Jun 16, 2020 - Python
Is subdomains hosted at discourse is vulnerable to takeover or not?
Automated NoSQL database enumeration and web application exploitation tool.
-
Updated
May 20, 2020 - Python
Merge /Testing_for_Vertical_Bypassing_Authorization_Schema_WSTG-AUTHZ-00X.md into 4-Web_Application_Security_Testing/05-Authorization_Testing/03-Testing_for_Privilege_Escalation.md
An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners. I'm just maintaining it.
-
Updated
Jun 11, 2020
Cleanup & Comment
- (Choose a consistent docstring format and lint (with pylint, probably)
- Try to organize files into directories:
- tests/
- models/
-
Updated
Apr 9, 2020
Penetration tests guide based on OWASP including test cases, resources and examples.
-
Updated
May 8, 2020
Security Tool to Look For Interesting Files in S3 Buckets
-
Updated
Dec 23, 2019 - Python
Subdomain Takeover tool written in Go
-
Updated
May 13, 2020 - Go
gitGraber: monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github, Mailgun, Facebook, Twitter, Heroku, Stripe...
-
Updated
Jun 5, 2020 - Python
ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.
-
Updated
Mar 19, 2020 - PHP
This challenge is Inon Shkedy's 31 days API Security Tips.
-
Updated
Apr 12, 2020
Automatically brute force all services running on a target.
-
Updated
Feb 20, 2020 - Shell
Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the active and passive scanner by means of personalized rules through a very intuitive graphical interface.
-
Updated
Jun 16, 2020 - Java
A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages.
-
Updated
Apr 28, 2020 - Python
StaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.
-
Updated
May 23, 2019 - JavaScript
A curated list of bugbounty writeups (Bug type wise) , inspired from https://github.com/ngalongc/bug-bounty-reference
-
Updated
May 16, 2020 - Python
A fast port scanner written in go with focus on reliability and simplicity. Designed to be used in combination with other tools for attack surface discovery in bug bounties and pentests
-
Updated
Jun 10, 2020 - Go
Firewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that domain. Handy for bugbounty hunters.
-
Updated
Feb 10, 2020 - Shell
Multi Tool Subdomain Enumeration
-
Updated
Apr 22, 2020 - Python
Improve this page
Add a description, image, and links to the bugbounty topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the bugbounty topic, visit your repo's landing page and select "manage topics."


It would be great if we add solution to each section that protects your code/server.
For example a PHP script that sanitises request strings against all attacks