Giter Site home page Giter Site logo

subn0x / awesome-bbht Goto Github PK

View Code? Open in Web Editor NEW
545.0 15.0 99.0 281 KB

A bash script that will automatically install a list of bug hunting tools that I find interesting for recon, exploitation, etc. (minus burp) For Ubuntu/Debain.

Shell 100.00%
hacking hacking-tools hacking-tool bugbounty bug-bounty reconnaissance security-tools enumerate-subdomains recon penetration-testing

awesome-bbht's People

Contributors

mhdabdurahiman avatar rohitgupta3050 avatar subn0x avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

awesome-bbht's Issues

Repositories not found

I have been checking the script for any errors and I found 2 incompatible git repositories.

Tools Affected:

  1. XSS Finder (XSS)
  2. Open Redirect Scanner

SCRIPT OUTPUT

XSS FINDER

XSSFINDER_NOT_FOUND

Open Redirect Scanner

OPENREDIRECT_SCANNER_NOT_FOUND

Current version does not install gf, gau, waybackurls Ubuntu Or Kali Linux. It does not show installation path to add API, or other keys for censys, shodan based scripts or tools.

Dear Sir,

Current version does not install gf, gau, waybackurls Ubuntu Or Kali Linux. It does not show installation path to add API, or other keys for censys, shodan based scripts or tools.

Second thing, please make it world no.01 web bug hunting installer by adding these top notch bug hunting tools.

Subdomains enumeration:

Amass
Assetfinder
Crobat
Findomain
Github-subdomains
Subfinder
Sudomy
subdomainizer
sublister
findomain

Subdomain Takeover:

Subover
Autosubtakeover
Tko-subs
Subjack

Cloud Workflow: AWS_Recon
festin
lazys3
s3brute
flumberboozle
slurp

DNS resolver

dnsx
MassDNS
PureDNS
ShuffleDNS
DNSvalidator

Visual Inspection - Screenshots

Aquatone
Gowitness
httpscreenshot

HTTP probe

httprobe
httpx

Web crawler / Content Discovery

Gospider
Hakrawler
ParamSpider
gau
waybackurls
paramspider
GF
GF_Pattern
Photon

Network scanner

Rustscan
Masscan
Naabu
Nmap
Brutespray

HTTP Parameter

Arjun
x8 *

Fuzzing tools

Ffuf
Gobuster
Wfuzz
Gobuster
Dirsearch
Dirb

LFI/RFI tools

LFISuite
Fimap

XPR1M3 / sqli-lfi-xss-rce-dorker-and-auto-exploiter-Python
https://github.com/XPR1M3/sqli-lfi-xss-rce-dorker-and-auto-exploiter-Python-.git

Spring4Shell:
redhuntlabs / Hunt4Spring | https://github.com/redhuntlabs/Hunt4Spring.git

Log4j:
log4jscan for Linux | https://github.com/intezer/log4jscan.git

SSRF tools

SSRFmap
Gopherus
Interactsh

SSTI tools

tplmap *

API hacking tools

Kiterunner + API routes

Wordlists

SecLists

Vulns - XSS

Dalfox
Bxss
XSpear
kxss
XSStrike
Gxss
FinDOM-XSS
X5S
Xenotix XSS Exploit Framework

Vulns - SQL Injection

SQLbit
BSQL hacker
SQLMap
SQLninja
Safe3 SQL injector
SQLSus
Mole
NoSQLMap
SQLmate
ATLAS (WAF Bypass Suggester for SQLmap)
SQLiScanner
AutoSQLi
Bypass-WAF-SQLMAP
KhetaguriDimitri/SQL-Injection
Agressiv1njector/psqli-pro
AngelSecurityTeam/SQLiDumper-AngelSecurityTeam
JohnTroony/Blisqy
quadcoreside/QuadCore-Web-SQLi-Injecter-DB-Dumper
enjoiz/BSQLinjector
lanmaster53/sqli-exploiter
Sqliv
Havij
BBQSQL
Leviathan
WhiteWidow
jSQL Injection

CMS Scanner

WPscan
droopescan
AEM-Hacker
Drupwn
Wig

Vulns - Scanner

Jaeles
Nikto **
Nuclei

JavaScript hunting

LinkFinder
SecretFinder
subjs
GetJS

Find_Web_Technologies

Wappalyzer CLI

Git Hunting / GIT Enum Tools:

GitDorker *
gitGraber *
GitHacker *
GitTools *
Githound
Trufflehog
Gitscanner

Sensitive Stuff Finding

DumpsterDiver *
EarlyBird *
Ripgrep

Useful tools

anew
anti-burl
getallurls
gron
Interlace
jq *
qsreplace
Tmux
unfurl
Uro *

Web Exploitation Frameworks:

Sn1per
Vajra
Jok3r v3 beta
osmedeus
cobra
Arachni
TIDoS Framework
sudomy
Grabber
Vega
Zed Attack Proxy
Wapiti
W3af
WebScarab
Skipfish
Ratproxy
Wfuzz
Grendel-Scan
Watcher

JS Enumeration Tools:

jsscanner
jsparser
linkfinder

Fingerprint & CVE Tools:

nuclei
webtech
waf

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.