A list of useful payloads and bypass for Web Application Security and Pentest/CTF
-
Updated
Jul 15, 2019 - HTML
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
I find vulnerabilities in web applications before attackers do. I test web apps, APIs, and mobile apps from an attacker's point of view. I look for flaws like IDOR, XSS, SSRF, CORS issues, access control problems, and other security misconfigurations.
An archive of bug bounty reports rewritten in a standardized, structured format for easier learning and reference.
Bug bounty program ROI rankings — 581 programs across HackerOne + Bugcrowd, scored by researcher value. Updated weekly.
Add a description, image, and links to the bugcrowd topic page so that developers can more easily learn about it.
To associate your repository with the bugcrowd topic, visit your repo's landing page and select "manage topics."