Resources

PayloadsAllTheThings

A list of useful payloads and bypasses for Web Application Security. Feel free to improve with your payloads and techniques!

Web Penetration Testing Checklist

More than 200 custom test cases

(Sub)Domains take over

A list of services and how to claim (sub)domain with dangling DNS records.

Wordlists

SecLists

A collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.

Fuzz4Bounty

1337 Wordlists for Bug Bounty Hunting