osamahamad / Sensitive-Data-Exposures-with-GithubLinks
Techniques / Tips and tricks for finding sensitive data exposures in Github for Penetration Testers / Bug Bounty Hunters
☆17Updated 5 years ago
Alternatives and similar repositories for Sensitive-Data-Exposures-with-Github
Users that are interested in Sensitive-Data-Exposures-with-Github are comparing it to the libraries listed below
Sorting:
- JsValidator is a tool created for validating the JS files after crawlling it from waybackurls☆19Updated 2 years ago
- ☆10Updated 2 years ago
- ☆21Updated 4 years ago
- Some simple scripts that I use during bug bounty hunting in Android Apps☆28Updated 7 months ago
- SubzzZ to find possible subdomains using passive recon. Tool also support Permutations, Mutations, Alterations.☆38Updated 4 years ago
- An SSRF detector tool written in golang. I have fixed some errors and added some more payloads to it. But the tool credits go to z0idsec.☆45Updated 4 years ago
- Enhanced 403 bypass header☆21Updated 3 years ago
- Framework to automate Bug Bounty Reconnaissance☆45Updated 4 years ago
- Cool HackerOne Reports☆22Updated 2 years ago
- Oneliners curated from my experience and from the internet☆23Updated 4 years ago
- ☆21Updated 2 years ago
- A repo for tools, utils, and wrappers that are to small to put in their own repo.☆23Updated 2 years ago
- Blind spot is a python tool for blind injection vulnerabilities , SQLi time based , Command injection , code injection , SSTI☆26Updated 4 years ago
- RegexFinder - Burp Suite extension to passively scan responses for occurrence of regular expression patterns.☆22Updated 4 years ago
- collection of various grep patterns collected from tomnomnom/gf and other places☆23Updated 4 years ago
- Some of the gf patterns which i use☆44Updated 3 years ago
- Magic Header Blind Xss tool (deliver blind xss payloads in request headers).☆26Updated 4 years ago
- Basic Recon For Bug Bounty Hunter - "HuntTheBug" is Basic Scripts For Sub Domain Enumeration> Live Domain Enumeration > Sub Domain Hijack…☆55Updated 3 years ago
- KARMA is a simple bash script automation that can hit Shodan Premium API and find active IPs, ASN, Common Vulnerabilities, CVEs & Open Po…☆59Updated 4 years ago
- XSS Finder Via SSTI☆56Updated 2 years ago
- A Tool to find subdomains from hackerone reports.☆17Updated 4 years ago
- Credax - Fuzzing Tool with Slack Notifications. Also removes false positive responses.☆10Updated 3 years ago
- ☆12Updated 3 years ago
- A solid recon tool I use personally.☆30Updated 2 years ago
- It grep subdomains, email/username, build custom wordlist etc from gau results☆48Updated 2 years ago
- ☆43Updated 4 years ago
- gup aka Get All Urls parameters to create wordlists for brute forcing parameters.☆18Updated 3 years ago
- ☆13Updated 4 years ago
- Some Tutorials and Things to Help Bug Hunter☆30Updated 4 years ago
- ☆33Updated 4 years ago