Bug Bounty Builder ¯\(ツ)/¯

GitHub forks GitHub license GitHub stars

Bug Bounty builder Project - ALL common Tools for find your Vulnerabilities.

Tested on Debian.

bb

Installation:

Tools You will find here

  • Amass

  • Sublister

  • Gauplus

  • HTTPX

  • Gf + patterns

  • Kxss

  • Sqlmap

  • Commix

  • Tplmap

  • HYDRA

  • John the ripper

  • Evilwinrm

  • Arjun

  • Paramspider

  • NoSQLmap

  • NMAP

  • Nikto

  • FFUF

  • 403-Bypass

  • Gobuster

  • Seclists

  • Hash-identifier

  • XSSMAP

  • Smuggler

  • SSRFmap

  • Gmapsapiscanner

  • Qsreplace

  • exiftool

  • XSRFProbe

  • XXE Exploiter

  • Rush

  • Rustscan

  • LFISuite

  • Wapiti

  • Nuclei + template

  • URO

  • Freq

  • Subzy


Bug Bounty TIPS and Usage of tools + One Liner TIPS :

ONE-LINER RECON for FUZZ XSS :


FUZZ all SUBDOMAINS with FUFF ONE-LINER :


COMMAND Injection with FUFF ONE-LINER :


SQL Injection Tips :


XSS + SQLi + CSTI/SSTI


EXIFTOOL + file UPLOAD Tips :


Open Redirect Tips ONE-LINER :


LFI ONE-LINER :


Best SSRF Bypass :


Email Attacks :


XSS Payload for Image


My XSS for bypass CLOUDFLARE with default rules


Find hidden params in javascript files:


IDOR to Account TakeOver quickly :


For API-KEYS :

Find sensitive information with GF tool :


Bypass RATE-LIMIT by adding :


Find Access Token with FFUF and GAUPLUS :


Find CORS vulnerabilities :


Bypass 403 and 401 :


Password poisoning bypass to account takeover :


Best Wordlists :


Thanks

^ back to top ^

License

MIT License & cc license

Creative Commons License This work is licensed under a Creative Commons Attribution 4.0 International License.

To the extent possible under law, Paul Veillard has waived all copyright and related or neighboring rights to this work.

Last updated