Web_Hacking

Bug Bounty Tricks and useful payloads and bypasses for Web Application Security.

M

Mehdi0x90

Dernière activité 22 août 2026
Mehdi0x90/Web_Hacking

815

étoiles

152

forks

1

issues ouvertes

api-pentestapi-securitybug-bounty-huntersbugbountybypasscheatsheetenumerationexploithackingowasppayloadspenetration-testingpentestreconredteamsecurityvulnerabilityweb-application-securitywebhackingwebsecurity

Ce README est souvent en anglais.

Web Hacking + Bug Bounty Tricks

5829442

These are my Bug Bounty / Pentest notes that I have gathered from various sources.

You can also contribute.

Twitter URL

Golden Tips

Recon & OSINT Techniques

List of Vulnerabilities

Bypass Techniques

Cloud / Docker

Top Tools & Extensions

  • Nuclei - Nuclei is a modern, high-performance vulnerability scanner that leverages simple YAML-based templates
  • inql - Burp extension for advanced GraphQL testing
  • Logger++ - Burp extension, a multithreaded logging extension for Burp Suit
  • param-miner - Burp extension, identifies hidden, unlinked parameters
  • Oralyzer - a simple python script that probes for Open Redirection vulnerability in a website
  • Darkmoon - Open source (GPL-3.0) autonomous AI penetration testing platform covering web, API, Active Directory and Kubernetes, orchestrating 80+ offensive tools as an MCP host with proof of exploitation and a local privacy gateway (the LLM never sees real IPs or credentials).
  • SQLiPy Sqlmap Integration - SQLiPy is a Python plugin for Burp Suite that integrates SQLMap using the SQLMap API
  • ParamSpider - Parameter miner for humans
  • gf - A wrapper around grep to avoid typing common patterns

Mindmaps for Bug Hunters

Red Team Attacks

Secure Coding


All content of this repository will always be updated...

Projets similaires

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Pythonbountybugbountybypass
Sswisskyrepo
81,3 k étoiles17,4 k

A list of web application security

appsechackinghacking-tools
Iinfoslack
7,3 k étoiles1,4 k

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

Pythonapplication-securityappsecbest-practices
OOWASP
9,9 k étoiles1,7 k