Welcome to the 403 and 401 Bypass Techniques and Bug Bounty Tips repository! This repo is a collection of methods and strategies to bypass 403 and 401 HTTP response codes, along with various tips and tricks for bug bounty hunting. If you're passionate about finding vulnerabilities and improving security, this is the right place for you!
☆38Dec 26, 2024Updated last year
Alternatives and similar repositories for BugBountyTips
Users that are interested in BugBountyTips are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- JS+ is a browser extension that captures JS URLs from specified domains and scans them with AI.☆22Mar 16, 2026Updated 4 months ago
- URILoot is a browser extension designed for Bug Bounty Hunters and Pentesters. Makes fetching uris easy from various sources.☆64Feb 15, 2026Updated 5 months ago
- An obsessive, expert-tier knowledge base + AI skill system for professional bug bounty hunting, security research, and penetration testin…☆28Apr 25, 2026Updated 3 months ago
- ☆39Oct 16, 2025Updated 9 months ago
- Collection of documentation, tools, and tips related to vulnerability research.☆105Jul 29, 2026Updated 2 weeks ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Get acquisitions by scraping titles of crunchbase.☆16Dec 18, 2024Updated last year
- ♥☆220Sep 7, 2025Updated 11 months ago
- Stealth hybrid URL mapper☆26May 1, 2026Updated 3 months ago
- Burp extension to log requests and responses to PostgreSQL☆16Jun 30, 2025Updated last year
- Burp Suite extension for cross-identity & cross-tenant access-control testing — BAC, IDOR, BOLA, and privilege escalation.☆58Jul 12, 2026Updated last month
- A lightweight, fast kernel exploit suggester written in C++ that automatically detects if your Linux kernel is vulnerable to known privil…☆23Jun 27, 2026Updated last month
- ☆50Feb 27, 2026Updated 5 months ago
- Firebase_Checker is Python tool to analyze APK files and web applications for Firebase-related vulnerabilities. This tool identifies secu…☆58Nov 6, 2025Updated 9 months ago
- All-round bug bounty skill for Claude Code parallelized agents for smart contract audits (EVM, Move, Solana, TRON), web/API security, an…☆334Updated this week
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- ☆13Mar 6, 2025Updated last year
- Agent Browser Bridge for Firefox.☆22Apr 29, 2026Updated 3 months ago
- IDOR Scanner is a Burp Suite extension that automates the detection and enumeration of potentially vulnerable numeric fields to identify …☆46Feb 24, 2025Updated last year
- 0xJS is an AI-powered JavaScript Security Tool☆66Apr 16, 2026Updated 3 months ago
- Gouge is a simple Burp extension to extract or gouge all URLs which are seen in JS files as you visit different websites/webpages in Burp…☆30Jul 21, 2024Updated 2 years ago
- bring shodan facets into your terminal without API key.☆107Oct 21, 2025Updated 9 months ago
- I-Espresso is a tool that enables users to generate Portable Executable (PE) files from batch scripts. Leveraging IExpress, it demonstrat…☆84Oct 17, 2024Updated last year
- My Main App Hacking CheckList☆33Jun 20, 2026Updated last month
- FrontHunter is a tool for testing large lists of domains to identify candidates for domain fronting.☆22May 5, 2025Updated last year
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- SSRFHunter☆18Jan 17, 2026Updated 6 months ago
- Fetch, download, and decompile Android/iOS/Exe assets from HackerOne bug bounty programs☆41Jun 24, 2026Updated last month
- CoupDeWeb is an automated web vulnerability scanner designed for security researchers and developers. It scans for potential vulnerable …☆34Oct 17, 2024Updated last year
- Organize, track, and share vulnerability findings effortlessly. This Burp Suite extension integrates with Obsidian, offering a proven not…☆39Apr 5, 2025Updated last year
- Fast Go-based XSS assessment toolkit☆20Mar 18, 2026Updated 4 months ago
- A Fuzzing skill based on purely what i know.☆43Jun 3, 2026Updated 2 months ago
- This script automates SQL injection testing using SQLMap with AI-powered decision making.☆29Jun 13, 2025Updated last year
- anveshan is a completed script that helps to automate your recon process, It finds subdomains, urls, js files, parameters, screenshots, a…☆30Oct 29, 2024Updated last year
- The Black Mamba — Bug bounty hunting CLI framework. 30+ scanner modules, OWASP Top 10 coverage, Kill Chain methodology and AI-assisted pe…☆16Jul 8, 2026Updated last month
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- ☆16Apr 17, 2025Updated last year
- ☆96May 11, 2026Updated 3 months ago
- ☆27May 21, 2025Updated last year
- XSSGAI is the first-ever AI-powered XSS (Cross-Site Scripting) payload generator. It leverages machine learning and deep learning to crea…☆43Feb 4, 2026Updated 6 months ago
- Burpsuite Extension for Jsmon☆25Jul 1, 2026Updated last month
- A tool for detecting subdomain takeover vulnerabilities by checking DNS records☆33May 28, 2026Updated 2 months ago
- ☆80Nov 4, 2025Updated 9 months ago