bb-huge 🤗 , Personal bug bounty findings hub and bug bounty orchestration for multiple agents
-
Updated
Jul 11, 2026 - Python
bb-huge 🤗 , Personal bug bounty findings hub and bug bounty orchestration for multiple agents
CTF and Bug Bounty Hunting WriteUps.
Webshell generator - obfuscated PHP/ASP/Java shells and detection-evasion demos for labs.
HTTP directory brute-forcer for authorized web testing: recursive scanning, status-code filtering, custom wordlists/extensions, configurable thread pool, and redirect detection.
XSS scanner - payload fuzzing, context-aware detection and CSP-bypass checks.
Web subdomain sweeper - name resolution, wildcard detection and takeover checks.
XXE injection toolkit — entity expansion, blind-OOB exfiltration and parser hardening tests.
SSTI scanner — Jinja2/Twig/Mako/ERB/FreeMarker/Velocity/Smarty fingerprinting, math-eval detection, RCE/file-read payloads and multi-target fuzzing.
CSRF security testing toolkit: token extraction and entropy analysis, form replay, HTML PoC generation, and bypass-technique assessment for authorized web pentests.
CORS misconfiguration scanner - origin validation and preflight-response flaw detection.
SQL injection automation suite - detection, extraction and exploit scaffolding for sqli labs.
Browser exploitation lab - DOM-based attacks and client-side defense exercises.
HTTP request-smuggling tester - CL.TE/TE.CL desync payload validation.
CMS vulnerability scanner — WordPress/Joomla/Drupal fingerprinting, version extraction, plugin/theme enumeration, exposed-config checks and security-header audit.
Writeups from PicoCTF challenges across different categories such as Cryptography, Web Exploitation, Reverse Engineering, and more.
Master cybersecurity skills with this TryHackMe free path, includes a collection of my write-ups, solutions and progress tracking.
PicoCTF-Writeup: A collection of solutions and writeups for PicoCTF challenges, documenting problem-solving steps and techniques.
Solutions and write-up for 2025 PicoCTF competition
To associate your repository with the webexploitation topic, visit your repo's landing page and select "manage topics."