This is your work, valued
awesome-bugbounty-tools. A curated list of various bug bounty tools
6.1kawesome-vulnerable-apps. Awesome Vulnerable Applications
1.5kxss2png. PNG IDAT chunks XSS payload generator
215dvwp. Damn Vulnerable WordPress
207js-snitch. Scans remote JavaScript files with Trufflehog + Semgrep to detect leaked secrets
147XFFenum. X-Forwarded-For [403 forbidden] enumeration
99wp-update-confusion. WordPress Plugin Update Confusion
67XSSwagger. A simple Swagger-ui scanner that can detect old versions vulnerable to various XSS attacks
61dkimsc4n. Asynchronous wordlist based DKIM scanner
57BBClip. Bug Bounty Clipboard
17bugbountytip.com. Flask powered website to display tweets with a hashtag #bugbountytip
16h1_2_nuclei. Scan any HackerOne program with Nuclei
14SpyPortal. Sniffing & geolocating saved SSIDs
10wp2burp. Intercept WordPress requests with Burp Suite
9old-repos-backup. Back-up of my old unmaintained GitHub repositories
9XSSworm.dev. Self-replication contest
6vavkamil.cz. My personal blog at https://vavkamil.cz
5web-security-notify. Telegram bot to notify about new Web Security Academy labs
5bb_tldr_bot. tldr; bot for r/bugbounty
4API-Keys-Snitch. Burp extension to detect & report exposed API keys as an Informative issue
4openvpn_proton. OpenVPN / ProtonVPN
4xml-rpc-settings. Configure XML-RPC methods to increase the security of your website
4r-bugbounty-automod. reddit.com/r/bugbounty AutoModerator config
4dvnc. Damn Vulnerable Nginx Config
3vavkamil.
2pocket-cvss. Offline CVSS v3.1 base score calculator for Flipper Zero.
2securitytxt.cz. https://securitytxt.cz/
1