🏳️One-Liners For Bug Hunting

One-Liners Awesomearrow-up-right

Thanks to all who create these Awesome One Liners❤️


Subdomain Enumeration

Juicy Subdomains

from BufferOver.run

from Riddler.io

from nmap

from CertSpotter

from Archive

from JLDC

from crt.sh

from ThreatMiner

from Anubis

from ThreatCrowd

from HackerTarget

SubDomain Bruteforcing - ffuf


Subdomain Takeover:


LFI:


Open Redirect:


SSRF:


XSS:


Hidden Dirs:

ffuf json to txt output

Search for Sensitive files from Wayback


SQLi:

Bypass WAF using TOR


CORS:


Prototype Pollution:


CVEs:

CVE-2020-5902:

CVE-2020-3452:

CVE-2021-44228:

CVE-2022-0378:

CVE-2022-22954:

CVE-2022-41040:


RCE:

vBulletin 5.6.2


JS Files:

Find JS Files:

Hidden Params in JS:

Extract sensitive end-point in JS:


SSTI:


HeartBleed


Scan IPs

Portscan

Screenshots using Nuclei

IPs from CIDR

SQLmap Tamper Scripts - WAF bypass

Shodan Cli

ffuf txt output

Ffuf json to only url

Recon Oneliner from Stok

Update golang

Censys CLI

Last updated