maurosoria / bugbounty-tools
Random tools I've written for bug bounties
☆72Updated 10 months ago
Related projects ⓘ
Alternatives and complementary repositories for bugbounty-tools
- All known and unknown public POC's for wordpress themes and plugins☆78Updated 3 years ago
- Nuubi Tools (Information-ghatering|Scanner|Recon.)☆86Updated 4 years ago
- SecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript files☆36Updated 3 years ago
- SQLi Query Tampering extends and adds custom Payload Generator/Processor in Burp Suite's Intruder. This extension gives you the flexibil…☆150Updated 4 years ago
- Host Header Injection Scanner☆44Updated 4 years ago
- Generates target specific word lists for Fuzzing with fuff☆106Updated 4 years ago
- A very (very) FAST and simple subdomain finder based on online & free services. Without any configuration requirements.☆104Updated 2 weeks ago
- ☆57Updated last year
- A Python based scanner to find potential SSRF parameters in a web application.☆71Updated 3 years ago
- ☆72Updated 3 years ago
- 0x0p1n3r is set of combination of other tools and one line scripts to find subdomains easily and to check subdomain takeover☆56Updated 3 years ago
- Host Header Injection Checker☆79Updated 2 years ago
- A Payload Injector for bugbounties written in go☆71Updated 4 years ago
- 📚 An ultimate collection wordlists of the best-known CMS☆84Updated 5 months ago
- golang tool to scan domains or single domains with know security issues against xmlrpc☆59Updated last year
- A collection of over 5.1 million sub-domains and assets belonging to public bug bounty programs, compiled into a repo, for performing bul…☆95Updated 3 years ago
- Sometimes we want to fuzz a set of sub-domain URLs with a common wordlist. Fuzzing them one by one is a tedious task, not to mention the …☆51Updated 3 years ago
- A simple Swagger-ui scanner that can detect old versions vulnerable to various XSS attacks☆55Updated 5 years ago
- A combined wordlists for files and directory discovery☆116Updated 3 years ago
- A simple reconnaissance framework for bug bounty hunting☆35Updated 4 years ago
- A docker image which will enumerate, sort, unique and resolve the results of various subdomains enumeration tools.☆69Updated 4 months ago
- A simple Bash one liner with aim to automate CRLF vulnerability scanning.☆68Updated 4 years ago
- SubzzZ to find possible subdomains using passive recon. Tool also support Permutations, Mutations, Alterations.☆38Updated 3 years ago
- My Tools For Bug Bounty☆63Updated last month
- Quick script to install all the required tools over a VPS (tested on DEBIAN)☆77Updated 3 years ago
- A Proof of Concept for Clickjacking Attacks☆52Updated 3 years ago
- Messy BurpSuite plugin for SQL Truncation vulnerabilities.☆61Updated 4 years ago
- A tool for append URLs, skipping duplicates/paths & combine parameters.☆118Updated 2 years ago