-
-
Notifications
You must be signed in to change notification settings - Fork 10
Home
This wiki serves as the definitive guide and documentation hub for the Bug Bounty repository. It's a comprehensive, production-ready knowledge base for security researchers, penetration testers, and bug bounty hunters. Here, you'll find detailed explanations, usage guides, and best practices for every tool, methodology, and resource included in the project.
All techniques, tools, and methodologies documented in this wiki are intended exclusively for authorized security testing, educational purposes, and ethical hacking. You must have explicit written permission from the system owner before testing. Unauthorized use is illegal and may lead to criminal prosecution. The authors assume no liability for misuse.
To help you find what you need quickly, the wiki is organized into the same main sections as the repository:
A structured learning path for anyone new to bug bounty hunting or looking to solidify their fundamentals.
- Getting Started: Syllabus, prerequisites, and learning objectives to take you from beginner to advanced.
In-depth attack strategies and frameworks for finding and exploiting vulnerabilities.
- Web Penetration Testing: Dive deep into specific vulnerability classes like SQL Injection, XSS, CSRF, SSRF, IDOR, and more. Each guide provides step-by-step detection and exploitation techniques.
- Web Technologies & Infrastructure: Explore platform-specific exploitation guides for CMSs (WordPress, Joomla), servers (Apache Tomcat), cloud services (Firebase), and core concepts like OAuth 2.0 exploitation, WAF bypassing, and CI/CD pipeline attacks.
A curated collection of actionable cheatsheets, templates, and wordlists to accelerate your testing workflow.
- Cheatsheets: Quick-reference guides with commands and payloads for over 60 vulnerability classes and platforms.
- Templates: A standardized bug report template to ensure your findings are professionally documented for submission.
- Wordlists: Targeted lists for subdomain discovery, directory fuzzing, and XSS payload delivery.
Custom-built automation, exploitation, and reconnaissance tools designed for bug bounty workflows. Each tool's wiki page includes setup instructions and usage examples.
-
Automation: Scripts like the
bug-bounty-workflow.shto automate your entire reconnaissance and scanning pipeline. -
Exploitation: Dedicated testers for vulnerabilities like SQL Injection (
sqli-tester.py) and Cross-Site Scripting (xss-scanner.py). -
Reconnaissance: Scripts for subdomain enumeration (
subdomain-enum.py) and URL collection to map out an attack surface. - Utilities: Helper tools for generating custom payloads and managing wordlists.
Real-world examples and lessons learned from actual bug bounty reports and vulnerability disclosures. A great way to learn by seeing how vulnerabilities are discovered and exploited in practice.
- Foundation: Start with the Course if you're new to the field.
- Specialize: Pick a vulnerability class from the Web Penetration Methodologies that you want to master.
- Practice: Use the corresponding Cheatsheet for quick payloads and the Tools section to automate your attack.
- Explore: Read the Write-ups to understand real-world impact and reporting style.
- Report: When you find a valid bug, model your report after the Bug Report Template.
| Knowledge Base | Tools | Project |
|---|---|---|
| Methodologies · Cheatsheets · Write-ups · Course | Automation · Exploitation · Recon | Security Policy · Code of Conduct · License |
⚠️ This repository contains real exploitation techniques. Unauthorized use is a criminal offense under the CFAA, Computer Misuse Act, and equivalent laws worldwide. Use only on systems you own or have explicit written permission to test.
© 2026 aw-junaid · MIT License
For Security Researchers
Methodologies • Cheatsheets • Tools • Write-ups
Core vulnerability exploitation guides
- API Security Testing
- Brute Force Attacks
- CORS Exploitation
- CRLF Injection
- CSRF
- Clickjacking
- Crawling & Fuzzing
- DNS Rebinding
- Deserialization
- Email Attacks
- Exploit Broken Links
- Race Conditions
- File Upload Vulnerabilities
- GraphQL Security Testing
- HTTP Parameter Pollution
- HTTP Request Smuggling
- Hashes
- IDOR
- Injection Exploitation
- LFI & RFI
- OAuth
- Open Redirect
- Prototype Pollution
- SQL Injection
- SSRF
- SSTI
- Session Fixation
- Supply Chain Attack
- Tabnabbing
- VHost
- Web Cache Deception
- WebSocket Exploitation
- Webshell
- XXE Vulnerabilities
- Cookies Padding
- CSP
- Header Injection
- Cross-Site Scripting (XSS)
Platform-specific exploitation guides
- ASP.NET
- Apache Tomcat
- CI/CD Security
- ELK Stack
- Exploitation Methodologies
- Buffer Overflows
- C2 Frameworks
- File Transfer Exploitation
- Firebase
- Firebird Database
- Flask Application
- From Recon to Root
- GitHub Security
- GitLab
- JWT
- Jenkins
- Joomla
- Linux Kernel Exploitation
- MFA/2FA Exploitation
- NoSQL Injection
- OAuth Exploitation
- OpenID Connect
- Privilege Escalation
- Remote Code Execution
- Reverse Shells
- SaaS Security Testing
- WAF
- WebDAV
- WordPress Penetration Testing
Quick-reference payloads & commands
- API Security
- ASP.NET
- Broken Links
- Bruteforcing
- Buffer Overflow
- CRLF Injection
- CSRF
- Clickjacking
- Command Injection
- Cookie Padding
- Crawling
- CORS
- CSP
- DNS Rebinding
- DavTest
- Deserialization
- Elasticsearch
- Email Attacks
- File Transfer
- File Upload
- Firebase
- Firebird
- Flask
- GitHub Security
- GitLab
- GraphQL
- HTTP Parameter Pollution
- HTTP Request Smuggling
- Hashes
- Header Injection
- IDOR
- JWT
- Jenkins
- Joomla
- Linux Kernel Exploits
- LFI & RFI
- MFA/2FA
- Modern C2 Frameworks
- NoSQL Injection
- OAuth
- OAuth 1.0
- OpenID Connect
- Open Redirects
- Payloads
- Ports
- Privilege Escalation
- Prototype Pollution
- Race Conditions
- Recon & Exploitation Reference
- Reverse Shells
- SQL Injection
- SaaS Security Testing
- SSRF
- SSTI
- Session Fixation
- Supply Chain Attacks
- Tabnabbing
- Tomcat Security Testing
- VHosts
- WAFs
- Web Cache Deception
- Web Exploits & C2
- Web Sockets
- Webshells
- WordPress
- XXE
- XSS Cheatsheet
- Web Penetration Commands
📋 View All 68 Cheatsheets
All cheatsheets are interlinked with their corresponding methodologies. Use the search function (press
t on GitHub) to find a specific one quickly.
- 📄 Bug Report Template
- 📃 Custom Subdomains Wordlist
- 📃 Directory Brute Force Wordlist
- 📃 XSS Payloads Wordlist
⚙️ Automation
💥 Exploitation
🔍 Reconnaissance
🔧 Utilities
| Link | Destination |
|---|---|
| 🏠 Wiki Home | Home |
| 📁 Repository | GitHub |
| ❓ FAQ | FAQ |
| 🐛 Report a Bug | Security Policy |
| 📄 License | MIT License |
| 💬 Discord | Join Server |
⚡ Stay curious. Hack ethically. Report responsibly.
© 2026 @aw-junaid • Built with 🔬 for the security community