Private Bug Bounty tool (Webapp)
by - Thursday, January 1, 1970 at 12:00 AM
I am selling an private Bug Bounty tool, which I personally use during bug hunting. I decided to sell it. It is a python script (all in one tool) which can find the following vulnerabilities:

- XSS scanning
- SQLi scanning
- CORS scanning
- CRLF scanning
- Cookie analysing scan (find desirialization patterns, and many more)
- HTTP2 vulnerabilities (DoS and HTTP2 Smuggling)
- LFI
- OS Command Injection (Blind and normal) (both Linux and Windows)
- Open redirect
- SSTI
- XXE
- Desirialization pattern scanner on data/strings
- HTTP-Header analysis
- Parameter pollution -> XSS

The tool works on .json packages, so it's very easy to edit and change things (and functionality) to your needs.
Each vulnerability is scanned by the most simple to the most advanced payloads (from different bug bounty tweets and from my own researches as well, thats why its a private program).

If you are interested, dm me on Telegram @nadeshot1
Reply
3 sells by far :), still opened for requests
Reply
That can be done as well, but my tool has more advanced payloads and the logic behind the scanning is a little more complex. Plus it detects vulnerabilities that nuclei doesn't do.
Reply
eyooo one more tool sold!!! Still available for selling!
Reply
dumb reply for visibility...
Reply


 Users viewing this thread: Private Bug Bounty tool (Webapp): No users currently viewing.