
AI-संचालित बग बाउंटी हंटिंग टूलकिट जो सब्सक्रिप्शन के साथ या बिना सब्सक्रिप्शन के काम करता है।
AI-संचालित बग बाउंटी हंटिंग — recon से रिपोर्ट तक, आपके टर्मिनल में।
मुफ़्त सेटअप
·
त्वरित आरंभ
·
कमांड्स
·
यह क्या खोजता है
·
इंस्टॉल
·
FAQ
द्वारा संचालित AwareXone.com — स्कैम और धोखाधड़ी के खिलाफ आपका AI एजेंट
💜 प्रायोजन के लिए खुला
BugHunter प्रायोजन के लिए खुला है। आपका समर्थन नई सुविधाओं को वित्त पोषित करता है और सभी के लिए मुफ्त स्टैंडअलोन मोड को चालू रखता है। प्रायोजकों को README में यहीं एक लोगो और लिंक मिलता है, साथ ही हर रिलीज़ में श्रेय भी मिलता है।
प्रायोजन करना चाहते हैं? AwareXone.com पर संपर्क करें या [email protected] पर ईमेल करें।
एक पेशेवर बग बाउंटी हंटिंग टूलकिट जो Claude सब्सक्रिप्शन के साथ या बिना काम करता है। इसे एक लक्ष्य दें — यह recon संभालता है, कमजोरियों का परीक्षण करता है, एक सख्त गेट के माध्यम से निष्कर्षों को मान्य करता है, और HackerOne, Bugcrowd, Intigriti और Immunefi के लिए सबमिशन-रेडी रिपोर्ट लिखता है।
यह सब कुछ याद रखता है। एक लक्ष्य पर मिले पैटर्न अगले को सूचित करते हैं। सत्र जहाँ से छूटे थे, वहीं से आगे बढ़ते हैं।
Claude Code प्लगइन के रूप में या मुफ्त AI प्रदाताओं द्वारा संचालित पूर्ण रूप से स्टैंडअलोन CLI (bughunter) के रूप में काम करता है।
आपको अब Claude Code, Claude Pro या किसी भी भुगतान वाले AI सब्सक्रिप्शन की आवश्यकता नहीं है।
एक बार इंस्टॉल करें, अपनी मशीन के किसी भी टर्मिनल से bughunter कमांड का उपयोग करें:```bash
git clone https://github.com/shuvonsec/claude-bug-bounty.git
cd claude-bug-bounty
./install.sh --agent standalone
अपडेट लाने के बाद वही कमांड दोबारा चलाएँ। इंस्टॉलर सक्रिय प्रबंधित `bughunter` कमांड का पता लगाता है और उसे रीफ़्रेश करता है, जिसमें `/usr/local/bin` या `~/.local/bin` के अंतर्गत पुराने इंस्टॉलेशन भी शामिल हैं, और साथ ही `~/.bughunter/config.json` में आपकी सहेजी गई प्रदाता कॉन्फ़िगरेशन को सुरक्षित रखता है।
कॉन्फ़िगरेशन को बनाए रखते हुए स्टैंडअलोन कमांड को अनइंस्टॉल करने के लिए:```bash
./uninstall.sh --agent standalone
~/.bughunter/config.json को भी हटाने के लिए --purge-config का उपयोग करें। अनइंस्टॉलर
claude, opencode, pi, codex, agents, और all लक्ष्यों का भी समर्थन करता है।```
bughunter help # show every command
bughunter setup # choose your AI provider (Ollama is free + offline)
bughunter recon target.com # map the attack surface
bughunter hunt target.com # hunt for vulnerabilities
bughunter validate "finding" # 7-Question Gate on your finding
bughunter report # write a submission-ready report
bughunter chat # interactive AI hunting shell
bughunter providers # list all available AI providers
bughunter models # list models and show the selected one
bughunter status # check which provider is active
bughunter h target.com # short alias for hunt
bughunter r target.com # short alias for recon
bughunter v "finding" # short alias for validate
### निःशुल्क AI प्रदाता (स्वतः-पहचाने गए, निःशुल्क-प्रथम प्राथमिकता)
| प्रदाता | लागत | गोपनीयता | गति | शुरू करें |
|:---|:---|:---|:---|:---|
| **Ollama** | 100% निःशुल्क · स्थानीय रूप से चलता है | पूर्ण — आपकी मशीन पर रहता है | तेज़ | `ollama pull qwen2.5:14b` |
| **Groq** | निःशुल्क टियर उपलब्ध | क्लाउड | बहुत तेज़ | [console.groq.com](https://console.groq.com) → API कुंजी प्राप्त करें |
| **DeepSeek** | बहुत सस्ता (v4-flash / v4-pro) | क्लाउड | तेज़ | [platform.deepseek.com](https://platform.deepseek.com) |
| Claude API | सशुल्क | क्लाउड | तेज़ | [console.anthropic.com](https://console.anthropic.com) |
| OpenAI | सशुल्क | क्लाउड | तेज़ | [platform.openai.com](https://platform.openai.com) |
| **Grok (xAI)** | सशुल्क | क्लाउड | तेज़ | [console.x.ai](https://console.x.ai) → `grok-4.5` |
| **OpenRouter** | सदस्यता / उपयोग-आधारित भुगतान | क्लाउड | तेज़ | [openrouter.ai/keys](https://openrouter.ai/keys) → API कुंजी प्राप्त करें |
| **OrcaRouter** | सदस्यता / उपयोग-आधारित भुगतान | क्लाउड | तेज़ | [orcarouter.ai](https://www.orcarouter.ai) → API कुंजी प्राप्त करें |
BugHunter प्रदाताओं का स्वतः पता लगाता है इस क्रम में: **Ollama → Groq → DeepSeek → … → OrcaRouter → OpenRouter → Claude → OpenAI**
किसी भी समय प्रदाता बदलें या स्थापित Ollama मॉडल चुनें: `bughunter setup`।
सेटअप पूरी तरह से गैर-इंटरैक्टिव भी हो सकता है:```bash
bughunter setup --provider ollama --model qwen2.5:14b
एक बार के ओवरराइड के लिए, विकल्प को कमांड से पहले रखें:```bash bughunter --provider ollama --model qwen3:14b hunt target.com
### शून्य-लागत पूर्णतः ऑफ़लाइन सेटअप```bash
# 1. Install Ollama (runs AI locally, no internet needed after download)
curl -fsSL https://ollama.ai/install.sh | sh
ollama pull qwen2.5:14b # ~9 GB, one-time download
# 2. Install BugHunter
git clone https://github.com/shuvonsec/claude-bug-bounty.git
cd claude-bug-bounty
./install.sh --agent standalone # creates system-wide 'bughunter' command
# 3. Hunt
bughunter setup # choose Ollama, then choose one of its installed models
bughunter recon target.com
export GROQ_API_KEY="your-key-here" # free at console.groq.com ./install.sh --agent standalone bughunter setup # choose Groq bughunter hunt target.com
---
## त्वरित आरंभ
**विकल्प A — स्टैंडअलोन (कोई सदस्यता नहीं, सभी के लिए काम करता है)**```bash
git clone https://github.com/shuvonsec/claude-bug-bounty.git
cd claude-bug-bounty
./install.sh --agent standalone # creates system-wide 'bughunter' command
bughunter setup # pick a free AI provider
bughunter recon target.com
bughunter hunt target.com
bughunter validate "my finding"
bughunter report
विकल्प B — Claude Code प्लगइन (Claude Code की आवश्यकता है)```bash git clone https://github.com/shuvonsec/claude-bug-bounty.git cd claude-bug-bounty chmod +x install_tools.sh && ./install_tools.sh # subfinder · httpx · nuclei · katana · ffuf chmod +x install.sh && ./install.sh # skills + commands → ~/.claude/
I don't see any content to translate in the input. Please provide the Markdown text for chunk 19 so I can translate it from English to Hindi.```bash
claude
/recon target.com # map the attack surface
/hunt target.com # test for vulnerabilities
/validate # run the 7-Question Gate
/report # write the submission
विकल्प C — Claude से इसे इंस्टॉल करवाएं (केवल Claude Code)
अपना टर्मिनल खोलें, claude चलाएं, फिर पेस्ट करें:```text
Install the Claude Bug Bounty toolkit from https://github.com/shuvonsec/claude-bug-bounty
into ~/tools/. Clone the repo, run ./install_tools.sh then ./install.sh.
Verify /recon /hunt /validate /report are available.
---
## Commands
### Core Workflow
| Command | What It Does |
|:---|:---|
| `/recon target.com` | Subdomain enum · live host probing · URL crawl · nuclei sweep |
| `/hunt target.com` | Tests IDOR · auth bypass · SSRF · XSS · SQLi · logic flaws and more |
| `/validate` | 7-Question Gate — kills weak findings before you waste time reporting |
| `/report` | Generates an H1 · Bugcrowd · Intigriti · Immunefi submission in 60s |
| `/autopilot target.com` | Full loop, autonomous — scope → recon → hunt → validate → report |
### Recon & Enumeration
| Command | What It Does |
|:---|:---|
| `/surface target.com` | Ranked attack surface from recon data + memory |
| `/scope-aggregate <program>` | All in-scope assets across H1 · Bugcrowd · Intigriti · YWH · Immunefi |
| `/cloud-recon --keyword <name>` | Public S3 · Azure · GCP buckets + CloudFlare-bypass origin IPs |
| `/param-discover <url>` | Hidden HTTP parameters via Arjun · x8 |
| `/secrets-hunt --js-bundle <dir>` | Leaked credentials in source, JS bundles, or a GitHub org |
| `/takeover --recon <dir>` | Subdomain takeover candidates via dnsReaper · subjack |
| `/scan-cves <host>` | Focused nuclei high/critical sweep + optional log4j-scan |
| `/bypass-403 <url>` | Header · method · encoding tricks against 403/401 |
| `/portscan <host>` | Open ports + non-web services (Redis · Docker API · DBs · RDP) via naabu/smap |
| `/screenshot -l urls.txt` | Screenshot live hosts into an HTML gallery — triage + PoC evidence |
### Scanners (Web + LLM)
| Command | What It Does |
|:---|:---|
| `/cors <url>` | CORS misconfig — origin reflection · null · credentialed |
| `/crlf <url>` | CRLF / response-splitting + host-header injection |
| `/nosqli <url>` | NoSQL injection (operator bypass · `$where` timing) |
| `/jwt-scan <token>` | Offline JWT toolkit — alg:none · RS256→HS256 · secret crack |
| `/oob <target>` | Out-of-band listener (interactsh) for blind SSRF/XXE/SQLi |
| `/sast <path>` | Semgrep security packs over fetched JS/source → ranked sinks |
| `/domxss <url>` | Confirms DOM XSS in headless Chromium — reports only when the payload executes |
| `/llm-redteam <endpoint>` | LLM red-team corpus — prompt injection · jailbreak · exfil |
### Smart Contract (Web3)
| Command | What It Does |
|:---|:---|
| `/web3-audit <contract.sol>` | 10-class smart contract audit with Foundry PoC template |
| `/token-scan <contract>` | Rug pull scanner — mint authority · LP lock · honeypot · bonding curve |
### Session & Utility
| Command | What It Does |
|:---|:---|
| `/pickup target.com` | Resume from last session — untested endpoints first |
| `/intel target.com` | CVEs + disclosed reports relevant to this target |
| `/chain` | Bug A found → finds bugs B and C that chain with it |
| `/scope <asset>` | Checks if a domain or URL is in scope before you test it |
| `/triage` | Quick 2-minute go/no-go check |
| `/remember` | Logs the current finding or technique to hunt memory |
| `/memory-gc` | Inspect or rotate hunt-memory JSONL files (10 MB cap, 3 backups) |
| `/arsenal [tool]` | Lists installed external tools or prints an install hint |
---
## What It Finds
<details>
<summary><b>26 Web2 Vulnerability Classes</b></summary>
<br>
| Vulnerability | Typical Payout |
|:---|:---|
| IDOR / BOLA | $500 – $5K |
| Auth Bypass | $1K – $10K |
| XSS (Stored / Reflected / DOM) | $500 – $5K |
| SSRF | $1K – $15K |
| Business Logic | $500 – $10K |
| Race Conditions | $500 – $5K |
| SQL Injection | $1K – $15K |
| OAuth / OIDC | $500 – $5K |
| File Upload → RCE | $500 – $10K |
| GraphQL Auth Bypass | $1K – $10K |
| LLM / Prompt Injection | $500 – $10K |
| API Misconfiguration (mass assignment · JWT · CORS) | $500 – $5K |
| Account Takeover | $1K – $20K |
| SSTI | $2K – $10K |
| Subdomain Takeover | $200 – $5K |
| Cloud / Infra Exposure | $500 – $20K |
| HTTP Request Smuggling | $5K – $30K |
| Cache Poisoning | $1K – $10K |
| MFA / 2FA Bypass | $1K – $10K |
| SAML / SSO Attack | $2K – $20K |
| Error Disclosure / Debug Endpoints | $200 – $5K |
| CSS Injection | $500 – $5K |
| LFI → RCE | $1K – $15K |
| Insecure Deserialization | $5K – $30K |
| Dependency Confusion / Supply Chain | $1K – $20K |
| Padding Oracle / Crypto Misuse | $2K – $20K |
</details>
<details>
<summary><b>10 Web3 / Smart Contract Bug Classes</b></summary>
<br>
| Vulnerability | Typical Payout |
|:---|:---|
| Accounting Desync | $50K – $2M |
| Access Control | $50K – $2M |
| Incomplete Code Path | $50K – $2M |
| Off-By-One | $10K – $100K |
| Oracle Manipulation | $100K – $2M |
| ERC4626 Share Inflation | $50K – $500K |
| Reentrancy | $10K – $500K |
| Flash Loan Attack | $100K – $2M |
| Signature Replay | $10K – $200K |
| Proxy / Upgrade | $50K – $2M |
</details>
---
## AI Agents
Nine specialists, each built for one job:
| Agent | Role |
|:---|:---|
| `recon-agent` | Subdomain enum · live host discovery · URL crawl |
| `report-writer` | Impact-first reports that get paid, not N/A'd |
| `validator` | Runs the 7-Question Gate — kills weak findings |
| `web3-auditor` | Smart contract audit across 10 bug classes |
| `chain-builder` | Bug A → finds bugs B and C that chain with it |
| `autopilot` | Full hunt loop with safety checkpoints |
| `recon-ranker` | Ranks attack surface by highest-value targets first |
| `token-auditor` | Meme coin / token rug pull and security scan |
| `credential-hunter` | Wordlist gen → OSINT → breach-check → spray (hard-stop before spray) |
---
## How It Works
<div align="center">```
You ─▶ /recon ─▶ /hunt ─▶ /validate ─▶ /report
│ │
▼ ▼
Hunt Memory 7-Question Gate
(persists across (kills weak findings
sessions) before you submit)
पाइपलाइन में हर टूल इस बात पर निर्भर करता है कि वह इंस्टॉल है या नहीं — जो टूल मौजूद नहीं होते, उन्हें छोड़ दिया जाता है, त्रुटि के रूप में नहीं। एक बार सेट किए गए Auth headers अपने आप httpx · katana · ffuf · nuclei · dalfox तक पहुँचते हैं।
पूर्वापेक्षाएँ:```bash
brew install go python3 jq
sudo apt install golang python3 jq
**स्कैनिंग टूल्स** (इंस्टॉल करता है subfinder · httpx · nuclei · katana · ffuf · gau · dnsx · nmap · dalfox और भी):```bash
chmod +x install_tools.sh && ./install_tools.sh
स्टैंडअलोन bughunter कमांड (कोई सदस्यता नहीं, Claude Code के बिना काम करता है):```bash
./install.sh --agent standalone
bughunter setup # choose Ollama (free) · Groq (free tier) · DeepSeek (cheap) · Claude · OpenAI
**AI कौशल + कमांड** Claude Code में:```bash
chmod +x install.sh && ./install.sh
अन्य एजेंट हार्नेस:```bash ./install.sh --agent opencode # OpenCode ./install.sh --agent pi # Pi Agent ./install.sh --agent codex # Codex ./install.sh --agent all # every supported target
**वैकल्पिक: Chaos API key** (बेहतर सबडोमेन कवरेज)```bash
export CHAOS_API_KEY="your-key"
echo 'export CHAOS_API_KEY="your-key"' >> ~/.zshrc
हर सत्र में सात नियम लागू होते हैं, कोई अपवाद नहीं:
PR स्वागत योग्य हैं। सबसे मूल्यवान:
skills/security-arsenal/SKILL.md में पेलोड जोड़ना---
## उपयोगकर्ता
<p align="center"><i>BugHunter को अपने कार्यप्रवाह में चलाने वाली टीमें और शोधकर्ता।</i></p>
<table align="center">
<tr>
<td align="center" width="200">
<a href="https://awarexone.com">
<img src="https://assets.kitploit.com/production/public/readmes/51067/29e21784cbe8b37142a688801ddd02d4084136effa303a59c67cdd8621e4ac2a/b44baafd696ad5280f1c515671c279895b049b007d04ef2400f00b7eaef441fc-display-v1.webp" alt="AwareXone" width="72"/>
<br/><b>AwareXone</b>
</a>
<br/><sub>AI एजेंट बनाम घोटाले और धोखाधड़ी</sub>
</td>
<td align="center" width="200">
<a href="ADOPTERS.md">
<img src="https://img.shields.io/badge/+-Add_your_team-7F55FF?style=for-the-badge" alt="अपनी टीम जोड़ें"/>
</a>
<br/><sub>एक-लाइन PR खोलें</sub>
</td>
</tr>
</table>
<p align="center">
क्या आपकी टीम, प्रोग्राम या कार्यप्रवाह में BugHunter का उपयोग हो रहा है? <b><a href="ADOPTERS.md">खुद को जोड़ें</a></b> — <code>ADOPTERS.md</code> में एक त्वरित PR, या एक <a href="https://github.com/shuvonsec/claude-bug-bounty/issues">issue</a> खोलें। केवल वास्तविक, सत्यापन योग्य प्रविष्टियाँ।
</p>
---
## स्टार इतिहास
<p align="center">
<a href="https://star-history.dera.page/#shuvonsec/claude-bug-bounty&type=date&legend=top-left">
<picture>
<source media="(prefers-color-scheme: dark)" srcset="https://star-history.dera.page/svg?repos=shuvonsec/claude-bug-bounty&type=date&theme=dark&legend=top-left" />
<source media="(prefers-color-scheme: light)" srcset="https://star-history.dera.page/svg?repos=shuvonsec/claude-bug-bounty&type=date&legend=top-left" />
<img alt="स्टार इतिहास चार्ट" src="https://star-history.dera.page/svg?repos=shuvonsec/claude-bug-bounty&type=date&legend=top-left" width="560" />
</picture>
</a>
</p>
---
## समर्थन
यदि BugHunter आपके हंट्स में मदद करता है, तो आप उन्हें और अधिक बढ़ावा दे सकते हैं:
<p align="center">
<a href="https://www.buymeacoffee.com/shuvonsec">
<img src="https://assets.kitploit.com/production/public/readmes/51067/322a7c99f1dd15a03b3c1b00b0d18ddd87443d80b823d3467a240721ae02357e/37540ef5b455c7e9fd2e680a883fa3eaa5ac7dfe7ea38853db90363dee628a84-display-v1.webp" alt="Buy Me A Coffee" height="50"/>
</a>
</p>
---
## धन्यवाद
BugHunter में योगदान देने वाले सभी लोगों को धन्यवाद। किसी भी अवतार पर क्लिक करके उनकी GitHub प्रोफ़ाइल खोलें।
<p align="center">
<a href="https://github.com/shuvonsec"><img src="https://assets.kitploit.com/production/public/readmes/51067/3c71ec4e8d747afbf17f2422c15a990e89b1e4c711129890ae2c2ddc0cf33b11/c28f708717c97d5e9032426d44661d39e54cbb0ea831351e3da7862fa89b0266-display-v1.webp" width="48" height="48" alt="shuvonsec" title="shuvonsec"/></a>
<a href="https://github.com/shuv0n"><img src="https://assets.kitploit.com/production/public/readmes/51067/d1087f300aa2f159be8a3f20f1da3b0d498d1a3b086006f00bba2e96bcafa1ca/3e4e701d8d7199dbc4aa5bfd0872da422c3630a3682e81bd4f00fb4b3eff796a-display-v1.webp" width="48" height="48" alt="shuv0n" title="shuv0n"/></a>
<a href="https://github.com/letztek"><img src="https://assets.kitploit.com/production/public/readmes/51067/8236747fa6130ad14ab79ca13ad7e1f727530cf03388d5ff69f6522d1202855b/850834b0bcf7305c85e3e2eef40eae2829896eb40992635126a5b518430569e3-display-v1.webp" width="48" height="48" alt="letztek" title="letztek"/></a>
<a href="https://github.com/bertolikimberly"><img src="https://assets.kitploit.com/production/public/readmes/51067/03de9cce0dd4aa48faa6d9c325d8b68533d34370322e235b459eb7cf8985aba7/610e73a3dd0ebcd37db0f1d16bb7ebf6cc7810df13cbebe65d77871ec3115621-display-v1.webp" width="48" height="48" alt="bertolikimberly" title="bertolikimberly"/></a>
<a href="https://github.com/venkatas"><img src="https://assets.kitploit.com/production/public/readmes/51067/b8248121001fa656e73d22b66e556f5416729e73c034c3df7e6fd6d178f69c64/2adc3afc7934f533642edb4278fcd3d4ad503b268bc0bd5a5d5cee7828190544-display-v1.webp" width="48" height="48" alt="venkatas" title="venkatas"/></a>
<a href="https://github.com/adityaax"><img src="https://assets.kitploit.com/production/public/readmes/51067/61029b5a332921d3cf18ee1f45ed1f427923e6e6afe082118104fa9f2ffde0c0/de5f88e6b6618bb8d52d8728c2dad1a3e20822f2d382e341792edf29758d2956-display-v1.webp" width="48" height="48" alt="adityaax" title="adityaax"/></a>
<a href="https://github.com/BeargleIndustries"><img src="https://assets.kitploit.com/production/public/readmes/51067/2b982731b11d958663f6cd0e2f70004401d97951366a574498718441f4314048/0cee9f5a6efcd85c280bd743ededb88faa88ed95b04ecb8966c302f7aa3065ec-display-v1.webp" width="48" height="48" alt="BeargleIndustries" title="BeargleIndustries"/></a>
<a href="https://github.com/ultra-supara"><img src="https://assets.kitploit.com/production/public/readmes/51067/c6d39ef6033dbeac0f1ed6bdbca50a78aa2f7b6cf92ef3270fda4163eb45e7c6/caae781831ae9859baa23bdbc1048e2ea737179d71af9e6f126644d53a111129-display-v1.webp" width="48" height="48" alt="ultra-supara" title="ultra-supara"/></a>
<a href="https://github.com/AurisDSP"><img src="https://assets.kitploit.com/production/public/readmes/51067/faa96c27e7d0493d309fee7b94e79aed51b991d83f17a44f605d22e2657691f0/50c186ab21c94f2b974570ebf01f896c770a361ab066e25338625993193d5604-display-v1.webp" width="48" height="48" alt="AurisDSP" title="AurisDSP"/></a>
<a href="https://github.com/Edneam"><img src="https://assets.kitploit.com/production/public/readmes/51067/e1a7a36a04544478fa1984f793aa3cea48f8a51bb090ce74a28e13334aafa6ab/bb9611fa7eeb5ebb5e58ae2a2cd4103c7bdf917f9191babf517d83f1eb5a6852-display-v1.webp" width="48" height="48" alt="Edneam" title="Edneam"/></a>
<a href="https://github.com/depapp"><img src="https://assets.kitploit.com/production/public/readmes/51067/3156944f4894fdd30b89baf215623103e46a7481c2858849d76016d17169c5ba/d8b617a44887e6737983e20cff14f61af07d18706bf0e3752ffeae54f5a7cc8b-display-v1.webp" width="48" height="48" alt="depapp" title="depapp"/></a>
<a href="https://github.com/Realgagenichols"><img src="https://assets.kitploit.com/production/public/readmes/51067/422e70caa8cce448ca55f0a63c0d7620f721b53821309c0291242ad0e4ff2043/9ce2cb2bd457ba0b88efca09db59c1264da78e7b854bb96352514aac13183d90-display-v1.webp" width="48" height="48" alt="Realgagenichols" title="Realgagenichols"/></a>
<a href="https://github.com/thuvh"><img src="https://assets.kitploit.com/production/public/readmes/51067/1dc37fcd3ddadd6b175572a34e2c86c44aedbc97fba2d79a1809a65aa4dce155/5a8b7a48be2c5e81eff7134f4d3f42b6e3ef9d4da35f88e87e99d129aa874859-display-v1.webp" width="48" height="48" alt="thuvh" title="thuvh"/></a>
<a href="https://github.com/onlybugs05"><img src="https://assets.kitploit.com/production/public/readmes/51067/f529bc0c7273b2e98e26352bb1a174c515dee670826bdf519240b63774f05b33/a89875927c1da3655d8c5880c93d1b13c30af04928b7a8335c4bb57e7a2f858d-display-v1.webp" width="48" height="48" alt="onlybugs05" title="onlybugs05"/></a>
<a href="https://github.com/savioruz"><img src="https://assets.kitploit.com/production/public/readmes/51067/362ee5f394d18365f33beae9d4e24b1f54a3bb299ceaa69aad6476c7912add35/fadecab17667be841099372f346c2892398fc55069a8d6c9e7c1031745fa92e9-display-v1.webp" width="48" height="48" alt="savioruz" title="savioruz"/></a>
<a href="https://github.com/Paebak"><img src="https://assets.kitploit.com/production/public/readmes/51067/0f26c58b1801e41175d39ad5df2ed02574c2bbff6e72a0999f278a962aaf9a2e/56ab94c06cf38bfc7c83550efc5b06597a135c4855b2f3122a79e9c493ef5310-display-v1.webp" width="48" height="48" alt="Paebak" title="Paebak"/></a>
<a href="https://github.com/nurazhardotcom"><img src="https://assets.kitploit.com/production/public/readmes/51067/3af62ef52780b5fac95a8b00db8fb562b8d03bf151a4a34c51dd4df37d47b4ab/e29f4b8a62da7772a4fbf0d385cc827efa746d74ec6cdc4f854c217e3d3b539d-display-v1.webp" width="48" height="48" alt="nurazhardotcom" title="nurazhardotcom"/></a>
<a href="https://github.com/SeekAndExploit"><img src="https://assets.kitploit.com/production/public/readmes/51067/943bffd56ab7cd823f6226ba45e1b2d8bfb24e2c705cf7285cd30c12d54b4d29/50579361c6456568868e787108a75c019b117b43e79ad16bfb43546876ffb1f1-display-v1.webp" width="48" height="48" alt="SeekAndExploit" title="SeekAndExploit"/></a>
<a href="https://github.com/Shawanga"><img src="https://assets.kitploit.com/production/public/readmes/51067/2f168dbf41d11829183809a1ada43bd407eb789ca322351b72544e9d8d689490/161721c856e5630413a4d7dabf33e2aadec45ff7a97f101952bbeeef8fff1b11-display-v1.webp" width="48" height="48" alt="Shawanga" title="Shawanga"/></a>
<a href="https://github.com/zeze-zeze"><img src="https://assets.kitploit.com/production/public/readmes/51067/6712b474717b9a0d31df50db07c0679323d745992e6905ef146ba93f059f1a0e/ea68d492a788a174c59ee241475e4ec6ba168ef8671359c2af6dc0db53d2aa7f-display-v1.webp" width="48" height="48" alt="zeze-zeze" title="zeze-zeze"/></a>
<a href="https://github.com/grave0x"><img src="https://assets.kitploit.com/production/public/readmes/51067/b177d7f1eb1e5f5f4ea6b0f01927068568d92feeb450c3588da3eb4ee444be3f/997770039b73abeb34cfa1bf34430cdd81e54b96626c1d856317711f6e55a15f-display-v1.webp" width="48" height="48" alt="grave0x" title="grave0x"/></a>
<a href="https://github.com/kevinaimonster"><img src="https://assets.kitploit.com/production/public/readmes/51067/eebb78e8387a8f45d69ee11489aa55bcefe42e934c61b6200470d4b3f8b8bc03/4dbb85af058868212ac2306d2ecd5f376ae81eb8faed80e96d9144193aea57c8-display-v1.webp" width="48" height="48" alt="kevinaimonster" title="kevinaimonster"/></a>
</p>
---
<p align="center">
<img src="https://assets.kitploit.com/production/public/readmes/51067/d32053d974d60dcec5ad625a665f0d22dbbddbc152b6d1184ad7b3774f0839e0/85e958d2288223e9020199c1ab154ead84e0e2170b64e9c21ce4ea15d6830014-display-v1.webp" alt="BugHunter" width="48"/><br>
<a href="https://github.com/shuvonsec">GitHub</a>
·
<a href="https://x.com/shuvonsec">Twitter</a>
·
<a href="mailto:[email protected]">[email protected]</a><br>
<b>बग हंटर्स द्वारा, बग हंटर्स के लिए निर्मित।</b><br>
<sub>MIT लाइसेंस · केवल अधिकृत सुरक्षा परीक्षण के लिए। हमेशा अनुमोदित बग बाउंटी प्रोग्राम के दायरे में परीक्षण करें।</sub>
</p>
<p align="center">
<a href="https://awarexone.com">
<img src="https://assets.kitploit.com/production/public/readmes/51067/29e21784cbe8b37142a688801ddd02d4084136effa303a59c67cdd8621e4ac2a/b44baafd696ad5280f1c515671c279895b049b007d04ef2400f00b7eaef441fc-display-v1.webp" alt="AwareXone" width="56"/>
</a>
<br/>
<sub><a href="https://awarexone.com"><b>AwareXone.com</b></a> द्वारा संचालित · घोटालों और धोखाधड़ी के विरुद्ध आपका AI एजेंट</sub>
</p>
| # | नियम | कारण |
|---|
| 1 | पहले पूरा दायरा पढ़ें | केवल वही परीक्षण करें जो प्रोग्राम अधिकृत करता है |
| 2 | केवल वास्तविक बग | "क्या कोई हमलावर इसे अभी कर सकता है?" — यदि नहीं, तो रुकें |
| 3 | कमज़ोर निष्कर्षों को हटाएँ | 30 सेकंड की जाँच घंटों की बर्बाद रिपोर्टिंग बचाती है |
| 4 | कभी भी दायरे से बाहर न जाएँ | एक गलत अनुरोध आपको प्रतिबंधित करवा सकता है |
| 5 | 5 मिनट का नियम | 5 मिनट में कोई प्रगति नहीं? आगे बढ़ें |
| 6 | रिपोर्ट से पहले सत्यापित करें | /validate लिखने में 30 मिनट बिताने से पहले |
| 7 | पहले प्रभाव | सबसे गंभीर परिणाम वाले बगों का पहले परीक्षण करें |