Skip to content

InTruder.sec || My Personal Favourite Bug Bounty Hunting Tools.

License

Notifications You must be signed in to change notification settings

InTruder-Sec/Bug-Bounty-Tools

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

22 Commits
 
 
 
 
 
 

Repository files navigation

BUG BOUNTY HUNTING TOOLS


PROXY AND NETWORK SNIFFER

TOOLS DISCRIPTION
Burp Suite Proxy for intercepting and manipulating web traffic You can use community version(free) or proffessional version(paid).
Wireshark For analyzing network protocols.
OWASP ZAP Proxy for intercepting and manipulating web traffic.

RECONISSANS & OSINT

TOOLS DISCRIPTION
Whois WHOIS looks for the owner of a domain or IP
nslookup It queries internet name servers for IP information about host.
FFUF For Brute forcing directories.
sublist3r Sub-domain enumerator.
Gobuster For enumerating Sub-domains
Altdns Bruteforces subdomains
Dirsearch Directory bruteforcers for hidden file paths
dnsdumpster Finding WAF and Sub-domain enumeration
crt.sh SSL Certificate search tool.
Wfuzz For brute forcing directories.
Lazys3 Brute force buckets by using keywords
GHDB Usefull Google search terms that frequently reveal vulnerable or sensitive files
WayBack Machinr For finding old versions of site
TruffleHog Specializes in finding secrets in public GitHub
Gitrob Finds potential sensitive files that are pushed to public repositaries
Wapalyzer To identfy frameworks, prgramming languages
Retire.js Deteccts outdated Javascript libraries and Node,js packages

EXPLOITATION

TOOLS DISCRIPTION
sqlmap Automate exploitation of sql.
XSStrike Automate exploitation of XSS.
CNAME-Lookup Bash script made by me, for subdomain takeover

SCANNERS

TOOLS DISCRIPTION
nmap A well known and multi-purpose tool.
Masscan Port scanner tool
Nikto Excellent web app vulnerability scanner.

WORDLISTS & HOOKUP TOOLS

TOOLS DISCRIPTION
Seclist A huge collection of wordlists.
webhook.site A perfect hookup tool.

IDEs for code analysis

TOOLS DISCRIPTION
Android studio For android applications
Visual studio code For coding and code analysis

About

InTruder.sec || My Personal Favourite Bug Bounty Hunting Tools.

Topics

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published