Welcome to the 403 and 401 Bypass Techniques and Bug Bounty Tips repository! This repo is a collection of methods and strategies to bypass 403 and 401 HTTP response codes, along with various tips and tricks for bug bounty hunting. If you're passionate about finding vulnerabilities and improving security, this is the right place for you!
☆38Dec 26, 2024Updated last year
Alternatives and similar repositories for BugBountyTips
Users that are interested in BugBountyTips are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- JS+ is a browser extension that captures JS URLs from specified domains and scans them with AI.☆22Mar 16, 2026Updated 4 months ago
- URILoot is a browser extension designed for Bug Bounty Hunters and Pentesters. Makes fetching uris easy from various sources.☆63Feb 15, 2026Updated 5 months ago
- An obsessive, expert-tier knowledge base + AI skill system for professional bug bounty hunting, security research, and penetration testin…☆24Apr 25, 2026Updated 2 months ago
- ☆39Oct 16, 2025Updated 9 months ago
- Collection of documentation, tools, and tips related to vulnerability research.☆102Updated this week
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- Get acquisitions by scraping titles of crunchbase.☆16Dec 18, 2024Updated last year
- ♥☆220Sep 7, 2025Updated 10 months ago
- Stealth hybrid URL mapper☆17May 1, 2026Updated 2 months ago
- Burp extension to log requests and responses to PostgreSQL☆16Jun 30, 2025Updated last year
- Burp Suite extension for cross-identity & cross-tenant access-control testing — BAC, IDOR, BOLA, and privilege escalation.☆43Jul 12, 2026Updated last week
- A lightweight, fast kernel exploit suggester written in C++ that automatically detects if your Linux kernel is vulnerable to known privil…☆22Jun 27, 2026Updated 3 weeks ago
- All-round bug bounty skill for Claude Code parallelized agents for smart contract audits (EVM, Move, Solana, TRON), web/API security, an…☆197Updated this week
- ☆50Feb 27, 2026Updated 4 months ago
- Firebase_Checker is Python tool to analyze APK files and web applications for Firebase-related vulnerabilities. This tool identifies secu…☆58Nov 6, 2025Updated 8 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- ☆14Mar 6, 2025Updated last year
- Agent Browser Bridge for Firefox.☆22Apr 29, 2026Updated 2 months ago
- IDOR Scanner is a Burp Suite extension that automates the detection and enumeration of potentially vulnerable numeric fields to identify …☆46Feb 24, 2025Updated last year
- 0xJS is an AI-powered JavaScript Security Tool☆64Apr 16, 2026Updated 3 months ago
- Gouge is a simple Burp extension to extract or gouge all URLs which are seen in JS files as you visit different websites/webpages in Burp…☆30Jul 21, 2024Updated 2 years ago
- bring shodan facets into your terminal without API key.☆106Oct 21, 2025Updated 9 months ago
- I-Espresso is a tool that enables users to generate Portable Executable (PE) files from batch scripts. Leveraging IExpress, it demonstrat…☆83Oct 17, 2024Updated last year
- My Main App Hacking CheckList☆32Jun 20, 2026Updated last month
- FrontHunter is a tool for testing large lists of domains to identify candidates for domain fronting.☆22May 5, 2025Updated last year
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- SSRFHunter☆18Jan 17, 2026Updated 6 months ago
- Fetch, download, and decompile Android/iOS/Exe assets from HackerOne bug bounty programs☆41Jun 24, 2026Updated 3 weeks ago
- CoupDeWeb is an automated web vulnerability scanner designed for security researchers and developers. It scans for potential vulnerable …☆34Oct 17, 2024Updated last year
- Organize, track, and share vulnerability findings effortlessly. This Burp Suite extension integrates with Obsidian, offering a proven not…☆39Apr 5, 2025Updated last year
- Fast Go-based XSS assessment toolkit☆20Mar 18, 2026Updated 4 months ago
- A Fuzzing skill based on purely what i know.☆39Jun 3, 2026Updated last month
- This script automates SQL injection testing using SQLMap with AI-powered decision making.☆29Jun 13, 2025Updated last year
- anveshan is a completed script that helps to automate your recon process, It finds subdomains, urls, js files, parameters, screenshots, a…☆30Oct 29, 2024Updated last year
- The Black Mamba — Bug bounty hunting CLI framework. 30+ scanner modules, OWASP Top 10 coverage, Kill Chain methodology and AI-assisted pe…☆16Jul 8, 2026Updated 2 weeks ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- ☆16Apr 17, 2025Updated last year
- ☆96May 11, 2026Updated 2 months ago
- ☆27May 21, 2025Updated last year
- XSSGAI is the first-ever AI-powered XSS (Cross-Site Scripting) payload generator. It leverages machine learning and deep learning to crea…☆42Feb 4, 2026Updated 5 months ago
- Burpsuite Extension for Jsmon☆25Jul 1, 2026Updated 3 weeks ago
- A tool for detecting subdomain takeover vulnerabilities by checking DNS records☆33May 28, 2026Updated last month
- ☆80Nov 4, 2025Updated 8 months ago