bug-bounty

Open-source projects categorized as bug-bounty

Top 23 bug-bounty Open-Source Projects

  • Awesome-Hacking

    A collection of various awesome lists for hackers, pentesters and security researchers

  • Project mention: Cyber Security iPhone Application Idea | /r/iOSDevelopment | 2023-07-03

    8. Security Knowledge Base: - Utilize resources like The-book-of-secret-knowledge (e.g., https://github.com/trimstray/the-book-of-secret-knowledge) and Awesome-Hacking (e.g., https://github.com/Hack-with-Github/Awesome-Hacking) to build a knowledge base. - Extract relevant security information and create a structured knowledge base within SecurIoT. - Implement functionality to query and retrieve security information from the knowledge base. - Thoroughly test the knowledge base integration, ensuring accurate retrieval of security knowledge.

  • dirsearch

    Web path scanner

  • Project mention: Looking for some help with this Python package | /r/learnpython | 2023-08-19

    I am new to Python. With the help of several users (thanks u/Diapolo10 and u/shiftybyte)I've been able to install Python and the dirsearch package. Dirsearch (https://github.com/maurosoria/dirsearch) allows for checking website paths with a wordlist. For example, I have a wordlist file with words like "dog", "cat", "bird", etc and I want to check the validity of those words as extensions on a website. Something like "example.com/bird", "example.com/cat", etc. I have a test wordlist in the same directory as dirsearch, but I am confused on how to proceed with the commands. I want to have it check my wordlist as extensions on the example.com website and then save output on if the webpath is valid or not. Just need a little bit of help.

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
  • Resources-for-Beginner-Bug-Bounty-Hunters

    A list of resources for those interested in getting started in bug bounties

  • Project mention: Getting started with bb journey | /r/bugbounty | 2023-06-28
  • rengine

    reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.

  • Project mention: Any self-host FOSS suites for running phishing testing campaigns? | /r/selfhosted | 2023-05-21

    I couldn't find anything named reEngine, but I found reNgine ( https://yogeshojha.github.io/rengine/ ) which I think is what you meant.

  • reconftw

    reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities

  • Project mention: Automated recognition frameworks? | /r/bugbounty | 2023-06-23
  • osmedeus

    A Workflow Engine for Offensive Security

  • axiom

    The dynamic infrastructure framework for everybody! Distribute the workload of many different scanning tools with ease, including nmap, ffuf, masscan, nuclei, meg and many more!

  • WorkOS

    The modern identity platform for B2B SaaS. The APIs are flexible and easy-to-use, supporting authentication, user identity, and complex enterprise features like SSO and SCIM provisioning.

    WorkOS logo
  • black-hat-rust

    Applied offensive security with Rust - https://kerkour.com/black-hat-rust

  • Project mention: Cloudflare for Speed and Security | /r/CloudFlare | 2023-10-20

    Bonuses: If you purchase Cloudflare for Speed and Security before November 4, 2023, you'll get my bestseller, Black Hat Rust, for free! Yes, you read it right, two books for less than the price of one!

  • afrog

    A Security Tool for Bug Bounty, Pentest and Red Teaming.

  • Project mention: Afrog explained for bug bounty hunters | dev.to | 2023-12-28
  • awesome-oneliner-bugbounty

    A collection of awesome one-liner scripts especially for bug bounty tips.

  • 31-days-of-API-Security-Tips

    This challenge is Inon Shkedy's 31 days API Security Tips.

  • sn0int

    Semi-automatic OSINT framework and package manager

  • API-SecurityEmpire

    API Security Project aims to present unique attack & defense methods in API Security field (by Cyber-Guy1)

  • Project mention: Massive-Web-Application-Penetration-Testing-Bug-Bounty-Notes | /r/bugbounty | 2023-05-26
  • metabigor

    OSINT tools and more but without API key

  • v3-periphery

    🦄 🦄 🦄 Peripheral smart contracts for interacting with Uniswap v3

  • Project mention: I get an "ambiguous primary types or unused types" error when trying to mint an NFT requiring 2 signatures via EIP712 | /r/solidity | 2023-05-24

    I modified my code to use EIP712 to require an authorized wallet to also sign in order for an NFT to be minted. I based this off of this: https://github.com/OpenZeppelin/openzeppelin-contracts/blob/7e814a3074baa921db584c180ff6e300cdec8735/contracts/token/ERC20/extensions/ERC20Permit.sol. This is an example of someone calling a smart contract containing this ERC20Permit.sol code https://github.com/Uniswap/v3-periphery/blob/main/test/shared/permit.ts. This particular ERC20Permit.sol code is designed to allow an account to approve ERC20 spend limits without spending gas fees but the same underlying mechanisms could be applied to my use case.

  • diodb

    Open-source vulnerability disclosure and bug bounty program database

  • clairvoyance

    Obtain GraphQL API schema even if the introspection is disabled

  • Project mention: nikitastupin/clairvoyance: Obtain GraphQL API schema even if the introspection is disabled | /r/bugbountybeginner | 2023-09-08
  • offensive-docker

    Offensive Docker is an image with the more used offensive tools to create an environment easily and quickly to launch assessment to the targets.

  • DataSurgeon

    Quickly Extracts IP's, Email Addresses, Hashes, Files, Credit Cards, Social Security Numbers and a lot More From Text

  • socialhunter

    crawls the website and finds broken social media links that can be hijacked

  • Facebook-BugBounty-Writeups

    Collection of Facebook Bug Bounty Writeups

  • awesome-bbht

    A bash script that will automatically install a list of bug hunting tools that I find interesting for recon, exploitation, etc. (minus burp) For Ubuntu/Debain.

  • SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
NOTE: The open source projects on this list are ordered by number of github stars. The number of mentions indicates repo mentiontions in the last 12 Months or since we started tracking (Dec 2020).

bug-bounty related posts

Index

What are some of the best open-source bug-bounty projects? This list will help you:

Project Stars
1 Awesome-Hacking 77,275
2 dirsearch 11,253
3 Resources-for-Beginner-Bug-Bounty-Hunters 10,141
4 rengine 6,737
5 reconftw 5,231
6 osmedeus 5,083
7 axiom 3,817
8 black-hat-rust 3,047
9 afrog 2,819
10 awesome-oneliner-bugbounty 2,429
11 31-days-of-API-Security-Tips 2,057
12 sn0int 1,847
13 API-SecurityEmpire 1,285
14 Massive-Web-Application-Penetration-Testing-Bug-Bounty-Notes 1,175
15 metabigor 1,139
16 v3-periphery 1,106
17 diodb 955
18 clairvoyance 908
19 offensive-docker 709
20 DataSurgeon 699
21 socialhunter 608
22 Facebook-BugBounty-Writeups 571
23 awesome-bbht 540

Sponsored
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com