
bug-bounty-library
Curated bug-bounty methodology library with runbooks, recon/fuzz playbooks, checklists, and CLI helpers for target scoping, cert enumeration, and…

Curated bug-bounty methodology library with runbooks, recon/fuzz playbooks, checklists, and CLI helpers for target scoping, cert enumeration, and…

A curated list of AI Security materials and resources for Pentesters, Bug Hunters, and Security Researchers.

Hands-on CVE triage lab: analyze NVD entries, decode CVSS vectors, map CWE weaknesses, and contextualize risk for high-profile exploits like…

Local intentionally vulnerable lab with a guided workshop and CTF challenges for practicing Git push-option RCE, unsafe deserialization,…

CVE-2019-15588 靶场: RCE 命令注入漏洞

Resources related to GitHub Security Lab


Browser-based Merkle tree demo — build a tree, generate inclusion proofs, recompute the root hash by hash, and replay the RFC 6962 second-preimage…

Take first steps in CodeQL for Python by writing a query to find CVE-2024-32022

Educational walkthrough of CVE-2018-4416, a WebKit JavaScriptCore type confusion vulnerability, with PoC, debugging setup, and analysis of common…

Cursor plugin for Hono v4 (TypeScript edge web framework). 59 LLM regressions with BAD/CORRECT pairs. Pinned to hono ^4.12.19 (>= 4.9.7 for…

Report written on CVE-2024-38112

AngularJS 1.x -> Angular 18 migration guidance for GitHub Copilot. Source-of-truth repo for…

In December 2021, the world of cybersecurity was shaken by the discovery of the Log4Shell vulnerability (CVE-2021-44228), embedded within the…

The most comprehensive LLM + MCP security guide i.e. OWASP aligned, real CVEs, actionable checklists

My personal hacklab, create your own.

The goal of this guide is very simple - to teach anyone interested in cyber security, regardless of their knowledge level, how to make the most of…