Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
bugbounty-lab101 — 面向HackerOne研究人员的完整漏洞赏金工作区。包含范围强制执行、自动化侦察/漏洞流水线(400+工具)、报告模板、CVE/CWE监视列表,以及本地VM练习实验室。专为有纪律、合乎道德的狩猎而构建。 | Kitploit
工具/GitHubGitHub/devcop95/bugbounty-lab101
侦察漏洞扫描器Web漏洞扫描器脚本与自动化Web应用程序漏洞利用API安全测试信息收集渗透测试子域名枚举学习与教育实验室与实践
4117231个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
GitHub
devcop95/bugbounty-lab101

bugbounty-lab101

面向HackerOne研究人员的完整漏洞赏金工作区。包含范围强制执行、自动化侦察/漏洞流水线(400+工具)、报告模板、CVE/CWE监视列表,以及本地VM练习实验室。专为有纪律、合乎道德的狩猎而构建。

查看仓库
root@kitploit:~
          ██████╗ ███████╗██╗   ██╗ ██╗ ██████╗  ██╗██╗  ██╗
          ██╔══██╗██╔════╝██║   ██║███║██╔═████╗███║╚██╗██╔╝
          ██║  ██║█████╗  ██║   ██║╚██║██║██╔██║╚██║ ╚███╔╝
          ██║  ██║██╔══╝  ╚██╗ ██╔╝ ██║████╔╝██║ ██║ ██╔██╗
          ██████╔╝███████╗ ╚████╔╝  ██║╚██████╔╝ ██║██╔╝ ██╗
          ╚═════╝ ╚══════╝  ╚═══╝   ╚═╝ ╚═════╝  ╚═╝╚═╝  ╚═╝

BUG BOUNTY LAB

面向 HackerOne 研究员的漏洞赏金工作区

Stars Forks License HackerOne Kali Linux Tools Scope Safe


目录

  • 这是什么?
  • 快速开始
  • T3MP3ST — AI 驱动的作战室
  • 主要命令
  • 按阶段划分的工具矩阵
  • 按类别划分的工具
  • 报告示例
  • 工作流程
  • 无需触碰真实项目即可练习
  • 项目结构
  • 重要规则
  • 故障排除
  • 学习资源
  • 更新日志

这是什么?

一个围绕 HackerOne 上真实漏洞赏金工作流程 构建的工作区:选择项目、记录范围、在边界内扫描、串联漏洞发现,并以审核人员能快速接受的格式提交报告。400+ 通用渗透测试工具库和本地 VM 实验环境作为辅助提供——并非入口点。

root@kitploit:~
┌─────────────────────────────────────────────────────────────────────┐
│                                                                     │
│  SCOPE                RECON/VULN              REPORT                │
│  ═════                ══════════              ══════                │
│                                                                     │
│  ┌───────────┐      ┌───────────────────┐    ┌───────────────┐      │
│  │programs/  │────▶  bugbounty-hunter   ───▶  report.md     │      │
│  │*.md       │      │      .sh          │    │ (H1 template) │      │
│  └───────────┘      └────────┬──────────┘    └───────┬───────┘      │
│  scope check                 │                       │              │
│  (blocks if not              ▼                       ▼              │
│   documented)       ┌─────────────┐         ┌──────────────┐        │
│                     │auto-scanner │         │  Hacktivity  │        │
│                     │ (arsenal)   │         │  dedup check │        │
│                     └─────────────┘         └──────────────┘        │
│                                                                     │
└─────────────────────────────────────────────────────────────────────┘

快速开始

1. 权限

root@kitploit:~
cd bugbounty-lab101
chmod +x bugbounty/*.sh auto-scanner/*.sh
# If the repository was cloned without submodules:
git submodule update --init --recursive

2. 记录项目范围

root@kitploit:~
cd bugbounty
./bugbounty-hunter.sh new program-name
# Edit ../programs/program-name.md with the EXACT scope from the H1 policy

3. 验证范围并扫描

root@kitploit:~
./bugbounty-hunter.sh scope target.com     # must say "Scope OK" before proceeding
./bugbounty-hunter.sh full target.com       # recon -> vuln -> brute -> secrets -> api -> report

4. 报告

root@kitploit:~
./bugbounty-hunter.sh report target.com
# Complete bugbounty/reports/target.com/report-YYYYMMDD.md with the H1 template

提交之前,请阅读 docs/hackerone-workflow.md(Hacktivity 去重、报告质量、提交后步骤)。


T3MP3ST — AI 驱动的作战室

本实验环境集成了 T3MP3ST 作为其攻击性安全引擎——一个多智能体框架,可将你的 AI 编程智能体转变为零日漏洞猎手。

设置

root@kitploit:~
# 1. Clone T3MP3ST into the lab (it's .gitignored, separate repo)
git clone https://github.com/DevCop95/T3MP3ST t3mp3st
cd t3mp3st && npm install && cd ..

# 2. Configure API keys
cp t3mp3st/.env.example t3mp3st/.env
# Edit t3mp3st/.env with your LLM provider key(s)

# 3. Start the server
./start-server.sh
# War Room → http://127.0.0.1:3333/ui/

T3MP3ST 提供什么

无密钥模式

T3MP3ST 无需 API 密钥即可运行,通过连接你的本地 AI 智能体(Claude Code、Codex、Hermes)。在 War Room UI 中,打开 Settings 并连接你的智能体——然后用自然语言描述目标。


主要命令

bugbounty-hunter.sh 中的所有主动扫描命令在触碰目标之前都会根据 programs/*.md 验证范围。被动 Shodan CTL 集成是可选的,当未安装 recons101x 时使用固定的 vendor/shodan_reconsx 子模块。其主机名在任何 HTTP 探测之前都会进行范围过滤。


按阶段划分的工具矩阵

root@kitploit:~
╔═════════════════════════════════════════════════════════════════════════╗
║                                                                         ║
║  PHASE 1          PHASE 2          PHASE 3          PHASE 4             ║
║  RECON            SCANNING         ENUMERATION      EXPLOITATION        ║
║                                                                         ║
║  ┌───────────┐   ┌───────────┐   ┌───────────┐   ┌───────────┐          ║
║  │   nmap    │─▶   nikto     ──▶  enum4l     ──▶  sqlmap              
║  │   amass   │   │ gobuster  │   │  smbclnt  │   │metasploit │          ║
║  │   dig     │   │  whatweb  │   │  ldapsrc  │   │  xsser    │          ║
║  │   whois   │   │   wfuzz   │   │  rpcclnt  │   │  wpscan   │          ║
║  └───────────┘   └───────────┘   └───────────┘   └───────────┘          ║
║        │              │               │               │                 ║
║        ▼              ▼               ▼               ▼                 ║
║  ┌───────────┐   ┌───────────┐   ┌───────────┐   ┌───────────┐          ║
║  │  theHarv  │   │   dirb    │   │ snmpwalk  │   │ msfvenom  │          ║
║  │  recon-ng │   │   ffuf    │   │  nbtscan  │   │ searchsp  │          ║
║  └───────────┘   └───────────┘   └───────────┘   └───────────┘          ║
║                                                                         ║
╠═════════════════════════════════════════════════════════════════════════╣
║                                                                         ║
║  PHASE 5          PHASE 6          PHASE 7          PHASE 8             ║
║  BUSINESS LOGIC   API TESTING      CHAIN ATTACKS    REPORT              ║
║                                                                         ║
║  ┌───────────┐   ┌───────────┐   ┌───────────┐   ┌───────────┐          ║
║  │auth flow  │   │  swagger  │   │CORS+CSRF  │   │    H1     │          ║
║  │race cond  │   │  graphql  │   │SSRF+RCE   │   │  REPORT   │          ║
║  │mass assn  │   │  nuclei   │   │IDOR+priv  │   │   .md     │          ║
║  └───────────┘   └───────────┘   └───────────┘   └───────────┘          ║
║                                                                         ║
╚═════════════════════════════════════════════════════════════════════════╝

按类别划分的工具(auto-scanner/ — 辅助工具库)

侦察(50+ 工具)

root@kitploit:~
┌────────────────────────────────────────────────────────────────┐
│  NETWORK SCANNING:                                             │
│  nmap        masscan      zmap         unicornscan             │
│  netdiscover                                                   │
│                                                                │
│  DNS ENUMERATION:                                              │
│  dnsrecon    dig          host         dnsenum                 │
│  dnsmap      sublist3r    subfinder    subbrute                │
│  dnsgen      gotator      fierce       dnspoodle               │
│                                                                │
│  HTTP RECON:                                                   │
│  httpx       httprobe     gau          waybackurls             │
│  katana      gospider     hakrawler    linkfinder              │
│  jsfinder    secretfinder paramspider  arjun                   │
│                                                                │
│  CLOUD RECON:                                                  │
│  s3scanner   cloud_enum   lazys3       bucket_finder           │
│                                                                │
│  SUBDOMAIN TAKEOVER:                                           │
│  subjack     subover      nuclei       canari                  │
└────────────────────────────────────────────────────────────────┘

报告示例(HackerOne 格式)

root@kitploit:~
# Bug Bounty Report

## Platform
HackerOne

## Program
[program name]

## Researcher
[your-handle]

## Target
prime.example.com

## Weakness (H1 taxonomy)
CWE-538: Insertion of Sensitive Information into Externally-Accessible File

## Executive Summary
S3 bucket with listing enabled exposes N files without authentication,
including internal HR documents.

## Steps to Reproduce
1. curl -k https://prime.example.com/file-service/static/
2. ...

## Impact
[Concrete business impact, not generic]

完整模板见 bugbounty/templates/report-template.md。


工作流程

root@kitploit:~
                      ┌─────────────────────┐
                      │  Choose H1 Program  │
                      └──────────┬──────────┘
                                 ▼
                      ┌─────────────────────┐
                      │ bugbounty-hunter.sh │
                      │   new <program>     │
                      └──────────┬──────────┘
                                 ▼
                      ┌─────────────────────┐
                      │  Document scope in  │
                      │   programs/*.md     │
                      └──────────┬──────────┘
                                 ▼
                ┌────────────────────────────────┐
                │ bugbounty-hunter.sh full <t>   │
                └────────────────┬───────────────┘
                                 │
              ┌──────────────────┼──────────────────┐
              ▼                  ▼                  ▼
       ┌──────────────┐   ┌──────────────┐   ┌──────────────┐
       │ RECON/VULN   │   │ MANUAL VERIF │   │ CHAIN ATTACK │
       │  (scripts)   │   │  (manual)    │   │  (manual)    │
       └──────┬───────┘   └──────┬───────┘   └──────┬───────┘
              └──────────────────┼──────────────────┘
                                 ▼
                      ┌─────────────────────┐
                      │  Dedup in Hacktivity│
                      └──────────┬──────────┘
                                 ▼
                      ┌─────────────────────┐
                      │  Submit H1 Report   │
                      └─────────────────────┘

完整方法论见 docs/hackerone-workflow.md。


无需触碰真实项目即可练习

legacy-vm-practice/ 属于你自己:你启动的私有 IP,无需遵守第三方范围。在将新技术应用于真实项目之前,用它来学习。

root@kitploit:~
cd legacy-vm-practice
./scripts/setup_network.sh   # requires sudo
./scripts/download_vms.sh
./scripts/start_lab.sh
./scripts/verify_lab.sh

参见 legacy-vm-practice/README.md 和 legacy-vm-practice/docs/quickstart.md。


项目结构

root@kitploit:~
bugbounty-lab/
│
├── README.md                       # This file — overview + usage guide
│
├── programs/                       # Scope tracker: one .md per H1 program
│   ├── README.md
│   └── _template.md
│
├── bugbounty/                      # Core bug bounty engine
│   ├── bugbounty-hunter.sh         # scope/new/recon/vuln/brute/secrets/api/report
│   ├── QUICK-REFERENCE.md          # Commands, payloads, bounty by severity
│   ├── templates/report-template.md
│   └── reports/<target>/           # Output per phase + final report
│
├── auto-scanner/                   # Generic arsenal (400+ tools, not H1-specific)
│   ├── pentest.sh                  # Unified command (incl. `pentest.sh bounty ...`)
│   ├── tools/registry.sh
│   ├── burp-integration/
│   └── reports/
│
├── docs/
│   ├── hackerone-workflow.md       # H1 methodology: choose program, dedup, quality
│   ├── ai-assisted-code-review.md  # AI-assisted code/JS review
│   ├── known-cve-watchlist.md      # Most reported CVEs in Hacktivity
│   ├── known-cwe-watchlist.md      # Most reported vuln classes in Hacktivity
│   └── recursos/learning-resources.md
│
└── legacy-vm-practice/             # Classic VM lab (DVWA, Metasploitable...)

重要规则

  1. 切勿扫描未在 programs/<program>.md 中记录为 In Scope 的资产。 所有主动扫描器都会阻止它,且没有 FORCE 绕过。
  2. 遵守每个项目的排除项和特殊规则(速率限制、排除的漏洞类型、测试账户)。
  3. 在报告之前检查 Hacktivity 中的重复项。
  4. 不要对真实目标执行破坏性操作——参见 bugbounty/templates/report-template.md 中的检查清单。
  5. legacy-vm-practice/ 属于你自己:你启动的私有 IP,无需遵守第三方范围。用它来学习新技术。

故障排除

bugbounty-hunter.sh 提示 "No scope file" 运行 ./bugbounty-hunter.sh new <program>,并将域名添加到 programs/ 中生成文件的 ## In Scope 部分。

缺少工具(subfinder、nuclei、httpx 等)

root@kitploit:~
./auto-scanner/pentest.sh install

VM 实验环境无法启动 参见 legacy-vm-practice/README.md 中的故障排除(Host-Only Adapter、NAT、防火墙)。


学习资源

资源重点

完整列表见 docs/recursos/learning-resources.md。


免责声明

root@kitploit:~
╔══════════════════════════════════════════════════════════════════════════════╗
║                                                                              ║
║  WARNING                                                                     ║
║                                                                              ║
║  This lab is designed for AUTHORIZED bug bounty via HackerOne.               ║
║                                                                              ║
║  Only test assets within the program's published scope                       ║
║  bugbounty-hunter.sh blocks targets without documented scope in programs/    ║
║  Unauthorized use of these tools is ILLEGAL                                  ║
║  Respect each program's exclusions and special rules                         ║
║  Always use these tools ETHICALLY and RESPONSIBLY                            ║
║                                                                              ║
╚══════════════════════════════════════════════════════════════════════════════╝

工具库统计

root@kitploit:~
┌─────────────────────────────────────────────────────────────────┐
│                                                                 │
│   RECON              200+ tools   ████████████████ 100%         │
│   ENUMERATION         60+ tools   ██████████░░░░░░  60%         │
│   WEB                 20+ tools   ████░░░░░░░░░░░░  20%         │
│   EXPLOITATION        80+ tools   ████████████████  80%         │
│   POST-EXPLOIT        50+ tools   ████████████░░░░  60%         │
│                                                                 │
│   TOTAL: 400+ categorized tools                                 │
│                                                                 │
└─────────────────────────────────────────────────────────────────┘

更新日志

完整变更列表见 CHANGELOG.md。


root@kitploit:~
+=============================================================+
|                                                             |
|   Bug Bounty Lab  •  HackerOne  •  400+ Tools               |
|                                                             |
+=============================================================+

祝狩猎愉快。

下载工具
功能描述
War Room UI用于任务规划和执行的 Web 界面
Recon Enginenmap、DNS、HTTP 指纹识别——在 XBEN 上 pass@1 达 90.1%
Exploit Loop8 操作员杀伤链(Recon → Scanner → Exploiter → ...)
Payload DB200+ payload(SQLi、XSS、SSTI、LFI、SSRF、CMDi、XXE)
MCP Servernode t3mp3st/dist/mcp-server.js 用于智能体集成
Evidence Vault持久化发现、证据和复测跟踪
命令描述示例
bugbounty-hunter.sh new <prog>为项目创建范围跟踪器./bugbounty-hunter.sh new acme-corp
bugbounty-hunter.sh scope <target>验证目标在范围内./bugbounty-hunter.sh scope target.com
bugbounty-hunter.sh full <target>完整流水线(从侦察到报告)./bugbounty-hunter.sh full target.com
bugbounty-hunter.sh recon <target>仅侦察,包括被动 Shodan CTL 增强./bugbounty-hunter.sh recon target.com
bugbounty-hunter.sh report <target>使用 H1 模板生成报告./bugbounty-hunter.sh report target.com
pentest.sh <url>通用工具库(400+ 工具)pentest.sh https://target.com
pentest.sh matrix完整工具矩阵pentest.sh matrix
pentest.sh search <function>搜索工具pentest.sh search sql_injection
pentest.sh express <url>快速扫描pentest.sh express https://target.com
pentest.sh install安装缺失的工具pentest.sh install
./start-server.sh启动 T3MP3ST War Room(AI 驱动)./start-server.sh
npm run server从 t3mp3st/ 目录启动 T3MP3STcd t3mp3st && npm run server

Web(20+ 工具)

root@kitploit:~
┌─────────────────────────────────────────────────────────────────┐
│  SCANNERS:        nikto  whatweb  wapiti  arachni  skipfish     │
│  DIRECTORY BRUTE: gobuster  dirb  feroxbuster  dirsearch        │
│  FUZZING:         wfuzz  ffuf  arjun  x8  paramspider           │
│  VULNERABILITIES: sqlmap  xsser  dalfox  commix  xsstrike       │
│  CMS:             wpscan  joomscan  droopescan  cmseek  cariddi │
└─────────────────────────────────────────────────────────────────┘
Hacker101CTF + HackerOne 视频,私有项目徽章
HackerOne Hacktivity公开报告——研究质量并避免重复
HackerOne Directory根据范围和响应统计选择项目
PortSwigger Web Security AcademyWeb 漏洞的技术基础