
Massive-Web-Application-Penetration-Testing-Bug-Bounty-Notes
A comprehensive guide for web application penetration testing and bug bounty hunting, covering methodologies, tools, and resources for identifying…

A comprehensive guide for web application penetration testing and bug bounty hunting, covering methodologies, tools, and resources for identifying…

The Offensive Manual Web Application Penetration Testing Framework.

Go Web Application Penetration Test

Web application penetration testing project targeting a WordPress environment. Includes exploitation of CVE-2019-9978, reverse shell execution,…

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

ADAPT is a tool that performs automated Penetration Testing for WebApps.

Software for fuzzing, used on web application pentestings.

Penetration test of a Drupal web app — CVE-2018-7600 (Drupalgeddon 2) exploited using Nmap, Burp Suite & Metasploit | Internship @ BB CyberSec

w3af: web application attack and audit framework, the open source web vulnerability scanner.

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Modular penetration testing framework integrating multiple tools for automated web application security assessment, aligned with OWASP Testing Guide,…

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

Bash script that enumerates subdomains via Subfinder, resolves IPs, and identifies live web applications hosted on a domain for reconnaissance and…

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

Deliberately vulnerable Flask web application with 22 security flaws across 3 difficulty levels for hands-on penetration testing and web security…

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

Deliberately vulnerable Node.js web application containing 19+ security bugs (XSS, SSRF, Prototype Pollution, RCE) for hands-on penetration testing…

BurpFlow is one of the best Burp Suite automation tools for bug bounty hunters and penetration testers, widely used to load recon data via proxy and…