Bug Bounty writeups, Vulnerability Research, Tutorials, Tips&Tricks
The most exhaustive list of reliable DNS resolvers.
Tools, data, and contact lists relevant to The disclose.io Project.
A list of resources for those interested in getting started in bug bounties
Detects the use of JavaScript libraries with known vulnerabilities. Available as a CLI tool, browser extension, Grunt plugin, and Burp Suite…
Tests URLs for Local File Inclusion (LFI), Remote File Inclusion (RFI), SQL injection (SQLi), and Cross Site Scripting (XSS), Server Side …
Earn RTC crypto by contributing to the RustChain ecosystem. Bounties from 1-150 RTC. Star, code, write tutorials, find bugs.
Markdown to HTML using marked and DOMPurify. Safe by default.
SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.
rewrite constructor arguments, call DOMPurify, profit
ScanT3r - Module based Bug Bounty Automation Tool ( use Lotus instead github.com/bugBlocker/lotus )
Websites Vulnerability Scanner
If these strings are in your code, you might have a problem!
An automated GitHub Actions-based crawler that fetches and updates public scopes from popular bug bounty platforms (like Hackerone/Bugcrowd/…
ScopeSentry-Cyberspace mapping, subdomain enumeration, port scanning, sensitive information discovery, vulnerability scanning, distributed n…
A Holistic OSINT and Threat Hunting Platform
恶意IP全自动封禁平台。支持收集如下安全设备告警:长亭WAF社区版(SafeLine)、微步蜜罐HFish、奇安信天眼、奇安信椒图、绿盟WAF、天融信WAF、科来网络安全分析审计系统、深信服态势感知、启明星辰全网安全态势感知系统。支持如下设备联动封禁:RouterOS、OPNse…
My useful files for penetration tests, security assessments, bug bounty and other security related stuff
Second-order subdomain takeover scanner
ChatGPT加持的,多人在线协同信息安全报告编写平台。目前支持的报告类型:渗透测试报告,APP隐私合规报告。
Open source templates you can use to bootstrap your security programs
A Modern Bug Bounty and Security Research Management Platform
Modern Python library for HTTP security headers with safe defaults, configurable presets, and first-class ASGI/WSGI middleware (FastAPI, Dja…
secureCodeBox (SCB) - continuous secure delivery out of the box