A collection of various awesome lists for hackers, pentesters and security researchers
-
Updated
Dec 31, 2019
A collection of various awesome lists for hackers, pentesters and security researchers
Subfinder is a subdomain discovery tool that discovers valid subdomains for websites. Designed as a passive framework to be useful for bug bounties and safe for penetration testing.
Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the active and passive scanner by means of personalized rules through a very intuitive graphical interface.
There's currently no way to learn about newly featured modules besides running quickstart occisionally. We could include the list of featured modules in the update check response.
Sublert is a security and reconnaissance tool which leverages certificate transparency to automatically monitor new subdomains deployed by specific organizations and issued TLS/SSL certificate.
Operating System: Ubuntu 18.04
Describe the bug
When navigating to the payloads section from a sub-section of the targets page, the sub-section stays highlighted and is no longer clickable.
To Reproduce
Steps to reproduce the behavior:
Collection of small security tools created mostly in Python. CTFs, pentests and so on
A web crawler (for bug hunting) that gathers more than you can imagine.
Keye is a reconnaissance tool that was written in Python with SQLite3 integrated. After adding a single URL, or a list of URLs, it will make a request to these URLs and try to detect changes based on their response's body length.
A permutation generation tool written in golang
🎯 XML External Entity (XXE) Injection Payload List
Automatic finder for subdomains vulnerable to takeover. Written in Go, based on @haccer's subjack.
This is a simple tool to automate google hacking when doing web penetration testing or bug hunting.
Simple Server Side Request Forgery services enumeration tool.
My collection of custom scripts, plugins, exploits and others small things
❄️ Research project for SubFinder core API V2
A python script designed to check if the website if vulnerable of clickjacking and create a poc
A comprehensive curated list of available Blockchain Bug Bounty Programs.
Add a description, image, and links to the bug-bounty topic page so that developers can more easily learn about it.
To associate your repository with the bug-bounty topic, visit your repo's landing page and select "manage topics."
Dirsearch has an option that will force the use of hostname and by default it search by IP. I think it should be the opposite. It should search by hostname by default and an option could be used to search by IP.
This behavior is not expected by user that briefly read the help and this may result in not finding files or directories on server using vhost.