Welcome to the 403 and 401 Bypass Techniques and Bug Bounty Tips repository! This repo is a collection of methods and strategies to bypass 403 and 401 HTTP response codes, along with various tips and tricks for bug bounty hunting. If you're passionate about finding vulnerabilities and improving security, this is the right place for you!
☆38Dec 26, 2024Updated last year
Alternatives and similar repositories for BugBountyTips
Users that are interested in BugBountyTips are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- JS+ is a browser extension that captures JS URLs from specified domains and scans them with AI.☆22Mar 16, 2026Updated 5 months ago
- URILoot is a browser extension designed for Bug Bounty Hunters and Pentesters. Makes fetching uris easy from various sources.☆64Feb 15, 2026Updated 6 months ago
- An obsessive, expert-tier knowledge base + AI skill system for professional bug bounty hunting, security research, and penetration testin…☆39Apr 25, 2026Updated 4 months ago
- ☆39Oct 16, 2025Updated 10 months ago
- Collection of documentation, tools, and tips related to vulnerability research.☆108Aug 12, 2026Updated 2 weeks ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Get acquisitions by scraping titles of crunchbase.☆16Dec 18, 2024Updated last year
- ♥☆221Sep 7, 2025Updated 11 months ago
- Stealth hybrid URL mapper☆31May 1, 2026Updated 4 months ago
- Burp extension to log requests and responses to PostgreSQL☆16Jun 30, 2025Updated last year
- Burp Suite extension for cross-identity & cross-tenant access-control testing — BAC, IDOR, BOLA, and privilege escalation.☆61Jul 12, 2026Updated last month
- A lightweight, fast kernel exploit suggester written in C++ that automatically detects if your Linux kernel is vulnerable to known privil…☆23Jun 27, 2026Updated 2 months ago
- ☆50Feb 27, 2026Updated 6 months ago
- Firebase_Checker is Python tool to analyze APK files and web applications for Firebase-related vulnerabilities. This tool identifies secu…☆59Nov 6, 2025Updated 9 months ago
- All-round bug bounty skill for Claude Code parallelized agents for smart contract audits (EVM, Move, Solana, TRON), web/API security, an…☆405Updated this week
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- ☆13Mar 6, 2025Updated last year
- Agent Browser Bridge for Firefox.☆21Apr 29, 2026Updated 4 months ago
- IDOR Scanner is a Burp Suite extension that automates the detection and enumeration of potentially vulnerable numeric fields to identify …☆46Feb 24, 2025Updated last year
- 0xJS is an AI-powered JavaScript Security Tool☆67Apr 16, 2026Updated 4 months ago
- Gouge is a simple Burp extension to extract or gouge all URLs which are seen in JS files as you visit different websites/webpages in Burp…☆30Jul 21, 2024Updated 2 years ago
- bring shodan facets into your terminal without API key.☆109Oct 21, 2025Updated 10 months ago
- I-Espresso is a tool that enables users to generate Portable Executable (PE) files from batch scripts. Leveraging IExpress, it demonstrat…☆84Oct 17, 2024Updated last year
- My Main App Hacking CheckList☆35Jun 20, 2026Updated 2 months ago
- FrontHunter is a tool for testing large lists of domains to identify candidates for domain fronting.☆22May 5, 2025Updated last year
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- SSRFHunter☆18Jan 17, 2026Updated 7 months ago
- Fetch, download, and decompile Android/iOS/Exe assets from HackerOne bug bounty programs☆41Jun 24, 2026Updated 2 months ago
- CoupDeWeb is an automated web vulnerability scanner designed for security researchers and developers. It scans for potential vulnerable …☆34Oct 17, 2024Updated last year
- Organize, track, and share vulnerability findings effortlessly. This Burp Suite extension integrates with Obsidian, offering a proven not…☆40Apr 5, 2025Updated last year
- Burp Suite extension + port-based highlighter: dedupes HTTP history into a live unique-request feed and color-codes attacker/victim traff…☆13Aug 14, 2026Updated 2 weeks ago
- Fast Go-based XSS assessment toolkit☆20Mar 18, 2026Updated 5 months ago
- A Fuzzing skill based on purely what i know.☆43Jun 3, 2026Updated 2 months ago
- This script automates SQL injection testing using SQLMap with AI-powered decision making.☆31Jun 13, 2025Updated last year
- anveshan is a completed script that helps to automate your recon process, It finds subdomains, urls, js files, parameters, screenshots, a…☆29Oct 29, 2024Updated last year
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- The Black Mamba — Bug bounty hunting CLI framework. 30+ scanner modules, OWASP Top 10 coverage, Kill Chain methodology and AI-assisted pe…☆16Aug 16, 2026Updated 2 weeks ago
- ☆16Apr 17, 2025Updated last year
- ☆96May 11, 2026Updated 3 months ago
- ☆28May 21, 2025Updated last year
- XSSGAI is the first-ever AI-powered XSS (Cross-Site Scripting) payload generator. It leverages machine learning and deep learning to crea…☆43Feb 4, 2026Updated 6 months ago
- Burpsuite Extension for Jsmon☆25Jul 1, 2026Updated 2 months ago
- A tool for detecting subdomain takeover vulnerabilities by checking DNS records☆34May 28, 2026Updated 3 months ago