Skip to main content

Recently Updated Pages

Nikto

Bug Bounty Path WebApp Tools

https://github.com/sullo/nikto Nikto is an Open Source (GPL) web server scanner which performs c...

Updated 1 year ago by SEGuy

File Upload via CSRF, XSS, SSRF, RCE, LFI, XXE

Bug Bounty Path WebApps Opportunities

    HTB https://whitehatlab.eu/en/blog/writeup/hackthebox/machine/linux/doctor/

Updated 1 year ago by SEGuy

Cross-origin resource sharing (CORS)

Bug Bounty Path WebApps Opportunities

Cross-origin resource sharing (CORS)  Cross-origin resource sharing (CORS) is a browser mechan...

Updated 1 year ago by SEGuy

Active Scanning

Bug Bounty Path Mitre ATT&CK: Recon

Updated 1 year ago by SEGuy

Lepus

Bug Bounty Path Name Service Takeover

Subdomain Takeover Lepus has a list of signatures in order to identify if a domain can be taken ...

Updated 1 year ago by SEGuy

Rengine

Bug Bounty Path GitHub Recon

reNgine is a web application reconnaissance suite with focus on a highly configurable streamlined...

Updated 1 year ago by SEGuy

Nuclei (in Regine)

Bug Bounty Path WebApp Tools

https://github.com/projectdiscovery/nuclei Nuclei is used to send requests across targets based ...

Updated 1 year ago by SEGuy

AMASS (in Rengine?)

Bug Bounty Path WebApp Tools

https://github.com/owasp-amass/amass The OWASP Amass Project performs network mapping of attack ...

Updated 1 year ago by SEGuy

GoSpider

Bug Bounty Path WebApp Tools

https://github.com/jaeles-project/gospider GoSpider GoSpider - Fast web spider written in Go    

Updated 1 year ago by SEGuy

gau (get all urls)

Bug Bounty Path WebApp Tools

https://github.com/lc/gau which replaces Rengine's  https://github.com/bp0lr/gauplus   getallu...

Updated 1 year ago by SEGuy

Clickjacking via IFRAME

Bug Bounty Path WebApps Opportunities

Clickjacking is an attack that tricks a user into clicking a webpage element which is invisible o...

Updated 1 year ago by SEGuy

SNMP and HOST Header Injection

Bug Bounty Path WebApps Opportunities

    How to Test Initial testing is as simple as supplying another domain (i.e. attacker.com) i...

Updated 1 year ago by SEGuy

Password Reset Vulnerability

Bug Bounty Path WebApps Opportunities

Password reset poisoning is a technique whereby an attacker manipulates a vulnerable website into...

Updated 1 year ago by SEGuy

theFuzz (formerly known as fuzzywuzzy)

Bug Bounty Path Find Subdomains

https://github.com/seatgeek/thefuzz TheFuzz Fuzzy string matching like a boss. It uses Levensht...

Updated 1 year ago by SEGuy

tomnomnom tools in Rengine

Bug Bounty Path Find Subdomains

https://github.com/tomnomnom/gf The examples are GREAT!!!!!! gf A wrapper around grep to avo...

Updated 1 year ago by SEGuy

Naabu (in Rengine)

Bug Bounty Path Port Scanning

Naabu is a port scanning tool written in Go that allows you to enumerate valid ports for hosts in...

Updated 1 year ago by SEGuy

Lepus Tool

Bug Bounty Path Find Subdomains

Lepus is a tool for enumerating subdomains, checking for subdomain takeovers and perform port sca...

Updated 1 year ago by SEGuy

FFUF Tool

Bug Bounty Path Find Subdomains

  https://github.com/ffuf/ffuf ffuf - Fuzz Faster U Fool A fast web fuzzer written in Go. I...

Updated 1 year ago by SEGuy

NMAP

Bug Bounty Path Port Scanning

Nmap is short for “Network Mapper” and was originally released in September 1997 by Gordon Lyon...

Updated 1 year ago by SEGuy

Access Controls and Parameter Tampering

Bug Bounty Path WebApps Opportunities

Updated 1 year ago by labadmin