mud1t's Stars
denysdovhan/wtfjs
🤪 A list of funny and tricky JavaScript examples
daffainfo/AllAboutBugBounty
All about bug bounty (bypasses, payloads, and etc)
KingOfBugbounty/KingOfBugBountyTips
Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are already exploitable, so we can report them. We wish to influence Onelinetips and explain the commands, for the better understanding of new hunters..
foospidy/payloads
Git All the Payloads! A collection of web attack payloads.
jbtronics/CrookedStyleSheets
Webpage tracking only using CSS (and no JS)
swisskyrepo/SSRFmap
Automatic SSRF fuzzer and exploitation tool
cujanovic/SSRF-Testing
SSRF (Server Side Request Forgery) testing resources
Ignitetechnologies/BurpSuite-For-Pentester
This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and completely with "BurpSuite".
bugcrowd/HUNT
inonshk/31-days-of-API-Security-Tips
This challenge is Inon Shkedy's 31 days API Security Tips.
hannob/snallygaster
Tool to scan for secret files on HTTP servers
HolyBugx/HolyTips
A Collection of Notes, Checklists, Writeups on Bug Bounty Hunting and Web Application Security.
zeroc00I/AllVideoPocsFromHackerOne
This script grab public report from hacker one and make some folders with poc videos
googleinurl/SCANNER-INURLBR
Advanced search in search engines, enables analysis provided to exploit GET / POST capturing emails & urls, with an internal custom validation junction for each target / url found.
federicodotta/Java-Deserialization-Scanner
All-in-one plugin for Burp Suite for the detection and the exploitation of Java deserialization vulnerabilities
chrislockard/api_wordlist
A wordlist of API names for web application assessments
evilsocket/ditto
A tool for IDN homograph attacks and detection.
Coalfire-Research/java-deserialization-exploits
A collection of curated Java Deserialization Exploits
abhi-r3v0/Adhrit
Android Security Suite for in-depth reconnaissance and static bytecode analysis based on Ghera benchmarks.
waf-bypass-maker/waf-community-bypasses
M4DM0e/DirDar
DirDar is a tool that searches for (403-Forbidden) directories to break it and get dir listing on it
dievus/threader3000
Multi-threaded Python Port Scanner with Nmap Integration
JamieFarrelly/Popular-Site-Subdomains
A list of subdomains for some of the most popular sites on the internet
0xtz/Enum_For_All
sensepost/dwn
d(ockerp)wn - a docker pwn tool manager
federicodotta/HandyCollaborator
Burp Suite plugin created for using Collaborator tool during manual testing in a comfortable way!
az0mb13/frida_setup
One-click installer for Frida and Burp certs for SSL Pinning bypass
spenkk/rapiddns-extractor
Extract subdomains from rapiddns.io
h-yde/VulnWebApp
Intentionally vulnerable web application
keerok/HUNT