Pinned Repositories
AdminBomber
bruteforce the admin panel
advanced-sql-injection-for-awae
all-about-apikey
Detailed information about API key / OAuth token (Description, Request, Response, Regex, Example)
Arjun
HTTP parameter discovery suite.
autopoisoner
Web cache poisoning vulnerability scanner.
awesome-wordlists
A curated list wordlists for bruteforcing and fuzzing
BBTz
BBT - Bug Bounty Tools (examplesđź’ˇ)
xr0r's Repositories
xr0r/awesome-wordlists
A curated list wordlists for bruteforcing and fuzzing
xr0r/Breacher
An advanced multithreaded admin panel finder written in python.
xr0r/BSQLi
timebased blind sqli with 99% success rate
xr0r/CloakQuest3r
Uncover the true IP address of websites safeguarded by Cloudflare & Others
xr0r/collectvars
collectvars collects JavaScript variables, highlights risky ones, and helps you understand code structure, while you casually browse.
xr0r/Conferences
Conference presentation slides
xr0r/customBsqli
xr0r/DockerSpy
DockerSpy searches for images on Docker Hub and extracts sensitive information such as authentication secrets, private keys, and more.
xr0r/docs
xr0r/Dorks
Bug Bounty Dorks
xr0r/favicon-hash.kmsec.uk
Cloudflare Worker to get favicon hashes for Shodan hunting
xr0r/ffufwebparser
Parse FFUF results in GUI with option to sort based by response code , size , keyword
xr0r/gofuzz
xr0r/google-dorks-bug-bounty
A list of Google Dorks for Bug Bounty, Web Application Security, and Pentesting
xr0r/Goosle
The best Meta Search engine running on simple PHP servers that keeps privacy and ease of use in mind!
xr0r/gungnir
CT Log Scanner
xr0r/LazySql
xr0r/linkfinder-
xr0r/lol
xr0r/lostools
xr0r/netscan
NetScan CLI is a command-line tool for retrieving and analyzing IP address information. It provides detailed subnet and organization data for given IP addresses using various online services.
xr0r/payloads
xr0r/priv8-Nuclei
this repo contains all nuclei templates for particular vulnerability that i used mosty while hunting..
xr0r/recollapse
REcollapse is a helper tool for black-box regex fuzzing to bypass validations and discover normalizations in web applications
xr0r/SQL_Injection-Techniques
Advanced SQL Injection Techniques for Bug Bounty Hunters
xr0r/SQLiDetector
Simple python script supported with BurpBouty profile that helps you to detect SQL injection "Error based" by sending multiple requests with 14 payloads and checking for 152 regex patterns for different databases.
xr0r/subfalcon
subfalcon is a subdomain enumeration tool that allows you to discover and monitor subdomains for a given list of domains. It fetches subdomains from various sources [crtsh, hackertargetapi, anubis, alienvault, rappiddns, urlscan ] , saves them to a SQLite database, and can notify updates via Discord.
xr0r/tib3rius.github.io
xr0r/uuid-grep
Simple CLI utility to search UUID from string
xr0r/XSS