mr-xhunt's Stars
KingOfBugbounty/KingOfBugBountyTips
Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are already exploitable, so we can report them. We wish to influence Onelinetips and explain the commands, for the better understanding of new hunters..
dwisiswant0/awesome-oneliner-bugbounty
A collection of awesome one-liner scripts especially for bug bounty tips.
luigigubello/PayloadsAllThePDFs
PDF Files for Pentesting
gprime31/nuclei-templates
Community curated list of templates for the nuclei engine to find security vulnerabilities.
MobSF/Mobile-Security-Framework-MobSF
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
mazen160/xless
The Serverless Blind XSS App
The-XSS-Rat/SecurityTesting
masatokinugawa/filterbypass
Browser's XSS Filter Bypass Cheat Sheet
0xInfection/Awesome-WAF
🔥 Web-application firewalls (WAFs) from security standpoint.
mr-xhunt/NahamCon-CTF-2022-Writeup
nahamsec/Resources-for-Beginner-Bug-Bounty-Hunters
A list of resources for those interested in getting started in bug bounties
0xsha/GoLinkFinder
A fast and minimal JS endpoint extractor
jobertabma/relative-url-extractor
A small tool that extracts relative URLs from a file.
003random/getJS
A tool to fastly get all javascript sources/files
D4Vinci/One-Lin3r
Gives you one-liners that aids in penetration testing operations, privilege escalation and more
streaak/keyhacks
Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.
vavkamil/awesome-vulnerable-apps
Awesome Vulnerable Applications
ant4g0nist/Vulnerable-Kext
A WIP "Vulnerable by Design" kext for iOS/macOS to play & learn *OS kernel exploitation
t0thkr1s/allsafe
Intentionally vulnerable Android application.
oversecured/ovaa
Oversecured Vulnerable Android App
jaiswalakshansh/Vuldroid
Vuldroid is a Vulnerable Android Application made with security issues in order to demonstrate how they can occur in code
dineshshetty/Android-InsecureBankv2
Vulnerable Android application for developers and security enthusiasts to learn about Android insecurities
mr-xhunt/My_Portfolio
mr-xhunt/Mx_Stock_Screener
mr-xhunt/Port-Scanner
Port Scanning tool
tp7309/TTPassGen
密码生成 flexible and scriptable password dictionary generator which can support brute-force、combination、complex rule mode etc...
sc0tfree/mentalist
Mentalist is a graphical tool for custom wordlist generation. It utilizes common human paradigms for constructing passwords and can output the full wordlist as well as rules compatible with Hashcat and John the Ripper.
OWASP/owasp-mastg
The Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes the technical processes for verifying the controls listed in the OWASP Mobile Application Security Verification Standard (MASVS).
payloadbox/rfi-lfi-payload-list
🎯 RFI/LFI Payload List
payloadbox/xxe-injection-payload-list
🎯 XML External Entity (XXE) Injection Payload List