Ecosyste.ms: Awesome

An open API service indexing awesome lists of open source software.

Awesome Lists | Featured Topics | Projects

Bug Bounty

A bug bounty program is a deal offered by many websites, organizations and software developers by which individuals can receive recognition and compensation for reporting bugs, especially those pertaining to security exploits and vulnerabilities.

https://github.com/4m3rr0r/gitversionhashsearch

GitVersionHashSearch is a bash script designed for bug bounty hunters, CTF participants, and red team operations. It allows you to search for specific patterns in the MD5 hashes of all versions of a file in a Git repository, making it a valuable tool for security assessments and exploit development.

bugbounty ctf gitversion gitversionhashsearch red-team

Last synced: 03 Feb 2025

https://github.com/palanioffcl/CTFation

I made this for my personal use to automate things like enumeration and all other stuffs to reduce time in recon and helps to claim first blood. ⛳ 😀

automation bash-script bugbounty ctf hacking linux penetration-testing pentesting

Last synced: 23 Oct 2024

https://github.com/mathis2001/jsembed

Simple Python tool to embed JavaScript code in different types of files (pdf and svg for now)

bugbounty fileupload javascript pdf pentest svg xss

Last synced: 09 Jan 2025

https://github.com/johnsaigle/hacking-toolkit

A collection of hacking utilities. Useful for CTFs and bug bounties.

bugbounty ctf-tools hacking penetration-testing

Last synced: 16 Jan 2025

https://github.com/GabrielCS0/security-trails

This is a tool to automate the search for subdomains on the website securitytrails.com

bugbounty pentesting python recon subdomains

Last synced: 23 Oct 2024

https://github.com/rix4uni/backupx

BackupX - Finding backup files using ffuf

backup backup-files backupx bugbounty ffuf wordlist

Last synced: 07 Feb 2025

https://github.com/carloocchiena/subdomain_scanner

A simple script that ping up to 10K most common subdomains in a target website and returns a list of finding.

bugbounty networking scanner vulnerability-scanners

Last synced: 26 Jan 2025

https://github.com/farinap5/headerparsing

Web Header Dump For Parsing

bugbounty header header-dump pentesting webpwn

Last synced: 21 Jan 2025

https://github.com/hunthubspace/bb-bugbountybash

This repository contains a collection of custom Bash functions designed to streamline and enhance the bug bounty hunting process.

automation bash-scripting bugbounty penetration-testing penetration-testing-tools

Last synced: 31 Jan 2025

https://github.com/macmod/forever

A simple tool that generates SSH command-line arguments to forward local addresses to multiple remote targets.

bugbounty pentest port-forwarding redteam ssh tools

Last synced: 01 Feb 2025

https://github.com/D0N-B0T/scripts

short Scripts i use for bugbounty and others.

bugbounty script

Last synced: 23 Oct 2024

https://github.com/rix4uni/gosqli

gosqli is a fast and simple tool for detecting blind SQL injection vulnerabilities. It supports scanning URLs with custom payloads, parallel requests, and response time-based verification.

bug-bounty bugbounty bugbountytips hacking infosec osint osint-resources osint-tool penetration-testing pentest-tool pentesting recon reconnaissance security security-tools sql-injection sqli threat-intelligence

Last synced: 07 Feb 2025

https://github.com/rix4uni/jscrawler

Fetches javascript file from a list of URLS or subdomains.

bugbounty hacking javascript pentesting recon reconnaissance urls

Last synced: 07 Feb 2025

https://github.com/mamad-1999/google-dorker

Simple Google Dork Generator for Cybersecurity

bug-bounty bugbounty cybersecurity dork dorker google-dorks googledork osint security

Last synced: 30 Jan 2025

https://github.com/mathis2001/EzComments

EzComments is a tool allowing you to get all html and js comments of each url given to him

bugbounty comments pentest recon

Last synced: 23 Oct 2024

https://github.com/cak/foot

Foot is a library that fetches a list of URLs and silly walks through each site to gather information.

bugbounty crawler scraping

Last synced: 14 Jan 2025

https://github.com/session-x/gitvulnexplorer

GitVulnExplorer is a tool for ethical hackers and bug bounty hunters to scan GitHub repositories for vulnerabilities using Google and GitHub dorks. It helps identify sensitive files, exposed credentials, and misconfigurations, making it easier to find and report security issues.

automationbugbounty bugbounty bugbountytools dorks dorksgithub github gitvulnexplorer gitvulnexplorerhacking hacking

Last synced: 24 Jan 2025

https://github.com/emrekybs/web-auditchain

Automated script for advanced web security reconnaissance and enumeration, integrating popular tools to streamline the information gathering phase

bash bugbounty enumeration information-extraction information-gathering owasp reconnaissance websecurity

Last synced: 19 Jan 2025

https://github.com/hunthubspace/cve-2024-3105-poc

A PoC Exploit for CVE-2024-3105 - The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress Remote Code Execution (RCE)

bugbounty cve cve-2024-3105 ethical-hacking exploit penetration-testing web

Last synced: 31 Jan 2025

https://github.com/y-mo4n1ngst3r/evillan

A tool for create encoded payloads and test them on targets

bugbounty bugbounty-tools cybersecurity hacking-tool offensive-security pentesting

Last synced: 09 Feb 2025

https://github.com/luis8456/minesweeper

A classic Minesweeper implementation built with HTML, CSS, and JavaScript. Features multilingual support, modular code, and a clean UI. Perfect for learning game development and refactoring practices. Play, explore, and contribute! 🚀

blacklist blacklist-extension bugbounty burpsuite coinhive cryptojacking game hacking java minesweeper-game mvi roboelectric room-database windows

Last synced: 10 Feb 2025

https://github.com/ichbinbork/JS_lookup

Tool that helps javascript source code analysis processes

bugbounty codereview websecurity

Last synced: 23 Oct 2024

https://github.com/codeb0ss/CVE-2023-20073-

Mass Exploit - CVE-2023-20073 - Cisco VPN Routers - [Unauthenticated Arbitrary File Upload and Stored XSS]

0day bug bugbounty cisco codeb0ss codeboss cve cve-2023-20073 exploit hackerone mass mass-exploit uncodeboss vpn-router

Last synced: 23 Oct 2024

https://github.com/incogbyte/lazyorigin

Find Origin IP Behind WAFs

bugbounty bugbounty-tool golang infosec pentesting

Last synced: 23 Jan 2025

https://github.com/sudosuraj/Dorks

List of Google Dorks for sites that have responsible disclosure program / bug bounty program

bounty bug bugbounty dork dorks google googledorks sudosuraj

Last synced: 23 Oct 2024

https://github.com/rtfmkiesel/geopipe

A pipeline tool to filter domains by server location

bugbounty golang maxmind

Last synced: 26 Jan 2025

https://github.com/cbrnrd/lacewing

🦗Your neighborhood bug bounty assistant

bug bugbounty bugcrowd hackerone ruby rubygems

Last synced: 31 Jan 2025

https://github.com/prvvv/submapper

A subdomain enumeration tool designed to find WAF's and 404 pages for takeover and enumeration

404 404-page amazon bug-bounty bugbounty cloudflare python3 subdomain-enumeration subdomain-scanner subdomain-takeover waf-detection

Last synced: 12 Jan 2025

https://github.com/bypasswin/js-monitor

Track JavaScript changes websites. Website bot can detected new API endpoints & more!

api api-change-log bugbounty hacking javascript js js-monitor monitor osint toolkit tools website

Last synced: 11 Feb 2025