osamahamad / Sensitive-Data-Exposures-with-Github
Techniques / Tips and tricks for finding sensitive data exposures in Github for Penetration Testers / Bug Bounty Hunters
☆16Updated 4 years ago
Alternatives and similar repositories for Sensitive-Data-Exposures-with-Github:
Users that are interested in Sensitive-Data-Exposures-with-Github are comparing it to the libraries listed below
- offy is a tool for bugbounty hunters to save money in their EC2 instances☆13Updated last year
- collection of various grep patterns collected from tomnomnom/gf and other places☆21Updated 4 years ago
- Find CVEs that don't have a Detectify modules.☆21Updated last year
- JsValidator is a tool created for validating the JS files after crawlling it from waybackurls☆18Updated last year
- ☆21Updated 4 years ago
- Credax - Fuzzing Tool with Slack Notifications. Also removes false positive responses.☆10Updated 3 years ago
- gup aka Get All Urls parameters to create wordlists for brute forcing parameters.☆17Updated 3 years ago
- A repo for tools, utils, and wrappers that are to small to put in their own repo.☆23Updated last year
- Some wordlists collected form github to all bug bounty hunters.☆27Updated 3 years ago
- ☆10Updated 2 years ago
- SubzzZ to find possible subdomains using passive recon. Tool also support Permutations, Mutations, Alterations.☆38Updated 3 years ago
- JSNotify is a Python script designed to monitor JavaScript files in a specified directory for changes. This tool can be used by developer…☆18Updated last year
- Blind spot is a python tool for blind injection vulnerabilities , SQLi time based , Command injection , code injection , SSTI☆27Updated 4 years ago
- Cool HackerOne Reports☆19Updated 2 years ago
- Generating Sub-Sub-Subdomain + validating all of them☆10Updated 2 years ago
- Quick tool to create custom wordlists like how fuzzers work☆11Updated last year
- Enhanced 403 bypass header☆21Updated 2 years ago
- ☆14Updated 3 years ago
- This includes all the templates of nuclei collected from different sources☆17Updated 2 years ago
- ☆20Updated last year
- ☆21Updated 3 years ago
- Magic Header Blind Xss tool (deliver blind xss payloads in request headers).☆27Updated 3 years ago
- Some Tutorials and Things to Help Bug Hunter☆28Updated 3 years ago
- Automated Recon Tool Installer☆17Updated 2 years ago
- Turns a list of URLs into hostnames.☆16Updated last year
- ☆42Updated 3 years ago
- 10 Reset Password Flaws Based on Web Application Security☆11Updated 4 years ago
- Automate bug bounty recon using bash alias☆15Updated 6 months ago
- An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability☆16Updated 4 years ago
- Tool to fuzz for interesting vhost.☆21Updated last month