Skip to content
View Xifeng2009's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report Xifeng2009

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!

Go 967 118 Updated Jan 12, 2024

All about bug bounty (bypasses, payloads, and etc)

6,519 1,233 Updated Sep 8, 2023

A community-powered collection of all known bug bounty platforms, vulnerability disclosure platforms, and crowdsourced security platforms currently active on the Internet.

817 173 Updated Jun 23, 2025

Gov domains and urls from some countries

Shell 6 1 Updated Nov 21, 2023

This repo contains hourly-updated data dumps of bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) that are eligible for reports

3,541 634 Updated Nov 26, 2025

Streamline your recon and vulnerability detection process with SCRIPTKIDDI3, A recon and initial vulnerability detection tool built using shell script and open source tools.

Shell 152 26 Updated Dec 26, 2023

Here we discuss how one can investigate crypto hacks and security incidents, and collect all the possible tools and manuals! PRs are welcome! If any tool is missing - please open PR!

1,812 227 Updated Jun 22, 2025

Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one place

Go 1,024 166 Updated Aug 23, 2025

Data set of top third party web domains with rich metadata about them

JavaScript 1,646 239 Updated Nov 18, 2025

Shodan Dorks 2023

Python 245 39 Updated Jan 13, 2025

The Bug Hunters Methodology

4,179 821 Updated Aug 1, 2023

Notify is a Go-based assistance package that enables you to stream the output of several tools (or read from a file) and publish it to a variety of supported platforms.

Go 1,519 152 Updated Nov 24, 2025

The recursive internet scanner for hackers. 🧡

Python 9,165 758 Updated Nov 25, 2025

Bucket Flaws ( S3 Bucket Mass Scanner ): A Simple Lightweight Script to Check for Common S3 Bucket Misconfigurations

Shell 58 17 Updated Jul 26, 2020

XSS payloads designed to turn alert(1) into P1

JavaScript 1,379 226 Updated Sep 12, 2023

fsociety Hacking Tools Pack – A Penetration Testing Framework

Python 11,690 2,095 Updated Aug 8, 2024

An easy-to-setup version of XSS Hunter. Sets up in five minutes and requires no maintenance!

JavaScript 2,133 394 Updated Mar 7, 2024

Notes about attacking Jenkins servers

Python 2,090 334 Updated Jul 10, 2024

Ghost Driver is an implementation of the Remote WebDriver Wire protocol, using PhantomJS as back-end

Java 1,910 332 Updated Feb 8, 2019

Scrapts Scrapts Scrapts

Shell 240 101 Updated Apr 12, 2024

A GUI client for Windows, Linux and macOS, support Xray and sing-box and others

C# 90,928 13,708 Updated Nov 26, 2025

A fast, simple, recursive content discovery tool written in Rust.

Rust 7,231 574 Updated Nov 17, 2025

dnsReaper - subdomain takeover tool for attackers, bug bounty hunters and the blue team!

Python 2,168 187 Updated Oct 6, 2025

An step by step fuzzing tutorial. A GitHub Security Lab initiative

3,626 399 Updated Jun 3, 2024

Dorks for Bug Bounty Hunting

188 46 Updated Jul 16, 2024

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

HTML 1,309 328 Updated Jan 10, 2025

Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application

Go 4,940 534 Updated Dec 21, 2024

For basic researches, top 25 vulnerability parameters that can be used in automation tools or manual recon. 🛡️⚔️🧙

1,807 282 Updated Jun 9, 2024

Top disclosed reports from HackerOne

Python 5,035 912 Updated Nov 9, 2025
Next