hakluke / bug-bounty-standards
A list of edge cases that occur in bug bounty programs, conversations on how they should be handled. The goal is to standardise the way that specific situations are handled in bug bounties.
☆229Updated 3 years ago
Alternatives and similar repositories for bug-bounty-standards:
Users that are interested in bug-bounty-standards are comparing it to the libraries listed below
- Burp extension to create target specific and tailored wordlist from burp history.☆234Updated 3 years ago
- List of reporting templates I have used since I started doing BBH.☆248Updated 5 months ago
- ☆162Updated last week
- Repository to house markdown templates for researchers☆196Updated last week
- ☆152Updated last year
- ☆128Updated 3 years ago
- The Bug Bounty Reconnaissance Framework (BBRF) can help you coordinate your reconnaissance workflows across multiple devices☆304Updated 3 months ago
- Whitebox source code review cheatsheet (Based on AWAE syllabus)☆128Updated 3 years ago
- Prototype pollution scanner using headless chrome☆216Updated 2 years ago
- ☆162Updated 7 months ago
- Unofficial documentation for the great tool Param Miner☆176Updated 2 years ago
- IIS shortname scanner written in Go☆323Updated last year
- A script for installing private Burp Collaborator with free Let's Encrypt SSL-certificate☆206Updated 7 months ago
- Useful "Match and Replace" burpsuite rules☆342Updated last year
- ☆141Updated 2 years ago
- Secret and/or credential patterns used for gf.☆238Updated 2 years ago
- This is a python wrapper around the amazing KNOXSS API by Brute Logic☆238Updated last month
- De-clutter a list of URLs☆321Updated 3 months ago
- Recon MindMap (RMM)☆150Updated 8 months ago
- Top disclosed reports from HackerOne☆148Updated 3 years ago
- Burp Suite extension that offers a toolkit for testing GraphQL endpoints.☆189Updated 6 months ago
- All About Dependency Confusion Attack, (Detecting, Finding, Mitigating)☆283Updated 11 months ago
- Real world bug bounty wordlists☆112Updated last year
- A reverse whois tool based on Whoxy API.☆162Updated 10 months ago
- EvenBetter is a frontend Caido plugin that makes the Caido experience even better 😎☆140Updated 2 weeks ago
- ☆149Updated last year
- ☆97Updated 2 years ago
- PDF slides☆246Updated 3 years ago
- Javascript security analysis (JSA) is a program for javascript analysis during web application security assessment.☆486Updated last week
- Source Code Review resources for Bug Bounty Hunters & Developers. This Repo is updated consistently.☆64Updated 3 years ago