Reference · technique-writeupsdual-uselicence
Awesome Bug Bounty Builder
A security-specific collection: a bash installer that deploys 40+ recon and exploitation tools (Amass, Sublist3r, SQLmap, Nikto, FFUF) plus curated usage examples and one-liners for testing XSS, SQLi, SSRF, LFI and auth-bypass. GPL-3.0.
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
Dual-use security content. We link to the upstream project rather than re-hosting ready-to-fire files. Use only in authorized security testing.
More references
- Bug Bounty Disclosed Reportstechnique-writeupsA curated archive of publicly disclosed bug bounty reports in Markdown, each covering vulnerability type, impact, reproduction steps, remediation and links to the original disclosure. Organized under a /reports directory as an educational reference for security researchers and developers.
- Bug Bounty Referencetechnique-writeupsA curated index of publicly disclosed bug bounty write-ups organized by vulnerability type (XSS, SQLi, CSRF, RCE, SSRF, auth bypass, etc.), linking out to the original researcher reports.
- HackerOne Reportstechnique-writeupsA repository that aggregates and ranks disclosed HackerOne bug bounty reports, categorizing them by vulnerability type (XSS, SQLi, RCE, SSRF, etc.) and by affected program, linking out to the original disclosures.
- macOS-iOS-system-securitytechnique-writeupsCurated catalogue of macOS/iOS security research: a large CVE table (2014–2025) mapped to affected components with links to technical write-ups, plus references to analysis tools (IOKit probing, dyld cache analysis, kernel driver analyzers), fuzzing frameworks, and conference talks (Black Hat, CanSecWest, DEFCON).
- PortSwigger Researchtechnique-writeupsPortSwigger's web-security research writeups, cited as an authoritative source for polyglot and injection technique maintenance (educational reference, not a payload dump).
- [un]prompted 2026 slide archiveai-security-programCommunity GitHub archive of 49 slide decks from [un]prompted 2026, the AI Security Practitioner Conference (March 3-4, San Francisco), spanning AI governance, agent security, offensive AI and agent evaluation; no licence stated.