Before you fill all the informations here, please give a read at the guidelines:
#1
Put your data between the [opening-tags] and the [/closing-tags].
Link to the tool: https://... (minimum 1 required):
[link]https://github.com/atikrahman1/bbhelp [/link]
[link][/link]
[link][/link]
List of tags separated by comma: tag1,tag2,tag3... (required):
[tags]bugbounty,bugbounty-tool,automation,fuzzing,chrome,recon[/tags]
Short description of the tool (required, maximum 100 characters):
[short_descr]
A comprehensive Chrome extension for bug bounty hunters and security researchers. Automates reconnaissance, JavaScript analysis, secret detection, and sensitive file discovery with smart filtering.
[/short_descr]
A bigger description (optional, but nice to have):
[long_descr]
BBHelp is a comprehensive Chrome extension designed for security researchers and bug bounty hunters to streamline reconnaissance and vulnerability discovery directly in the browser. The extension automatically scans websites for sensitive files like .env, config.php, backup files, and database dumps using intelligent false positive filtering and domain exclusion capabilities. It features a Service Discovery Scanner that probes the top 100 most common ports to identify exposed web services, admin panels, databases (MySQL, MongoDB, Redis), and development servers with real-time progress tracking and JSON export functionality. The JavaScript Analysis Engine extracts custom JS files while filtering out common libraries, then scans for hidden API endpoints, secret keys, AWS credentials, JWT tokens, and other exposed sensitive data using advanced entropy analysis and confidence scoring. Users get instant access to popular reconnaissance tools like Shodan, Crt.sh, and Subdomain Center with automatic domain population, plus customizable Google dorks for finding login pages, admin panels, and exposed files. The extension includes a Quick Command Generator that creates ready-to-use security testing commands (nmap, subfinder, ffuf, nuclei) with automatic variable replacement for the current target domain. All scanning is highly configurable with adjustable intervals, preview lengths, notification controls, and custom file lists, while maintaining ethical safeguards through prominent warnings and domain exclusion features. The tool operates entirely locally with no data collection, using Chrome's secure storage APIs and efficient background processing to provide persistent results per domain with visual badge notifications (red for fresh findings, orange for cached results). Perfect for authorized bug bounty programs, penetration testing, and security assessments, this extension transforms any browser into a powerful reconnaissance platform that combines automated scanning, manual testing tools, and comprehensive analysis capabilities in a clean, dark-themed interface that's both beginner-friendly and powerful enough for experienced security researchers.
[/long_descr]
A link or an attached image (minimum 1 required):
[image]
[/image]
[image]
[/image]
[image]
[/image]
[image]
[/image]
[image]
[/image]
Before you fill all the informations here, please give a read at the guidelines:
#1
Put your data between the
[opening-tags]and the[/closing-tags].Link to the tool: https://... (minimum 1 required):
[link]https://github.com/atikrahman1/bbhelp [/link]
[link][/link]
[link][/link]
List of tags separated by comma: tag1,tag2,tag3... (required):
[tags]bugbounty,bugbounty-tool,automation,fuzzing,chrome,recon[/tags]
Short description of the tool (required, maximum 100 characters):
[short_descr]
A comprehensive Chrome extension for bug bounty hunters and security researchers. Automates reconnaissance, JavaScript analysis, secret detection, and sensitive file discovery with smart filtering.
[/short_descr]
A bigger description (optional, but nice to have):
[long_descr]
BBHelp is a comprehensive Chrome extension designed for security researchers and bug bounty hunters to streamline reconnaissance and vulnerability discovery directly in the browser. The extension automatically scans websites for sensitive files like .env, config.php, backup files, and database dumps using intelligent false positive filtering and domain exclusion capabilities. It features a Service Discovery Scanner that probes the top 100 most common ports to identify exposed web services, admin panels, databases (MySQL, MongoDB, Redis), and development servers with real-time progress tracking and JSON export functionality. The JavaScript Analysis Engine extracts custom JS files while filtering out common libraries, then scans for hidden API endpoints, secret keys, AWS credentials, JWT tokens, and other exposed sensitive data using advanced entropy analysis and confidence scoring. Users get instant access to popular reconnaissance tools like Shodan, Crt.sh, and Subdomain Center with automatic domain population, plus customizable Google dorks for finding login pages, admin panels, and exposed files. The extension includes a Quick Command Generator that creates ready-to-use security testing commands (nmap, subfinder, ffuf, nuclei) with automatic variable replacement for the current target domain. All scanning is highly configurable with adjustable intervals, preview lengths, notification controls, and custom file lists, while maintaining ethical safeguards through prominent warnings and domain exclusion features. The tool operates entirely locally with no data collection, using Chrome's secure storage APIs and efficient background processing to provide persistent results per domain with visual badge notifications (red for fresh findings, orange for cached results). Perfect for authorized bug bounty programs, penetration testing, and security assessments, this extension transforms any browser into a powerful reconnaissance platform that combines automated scanning, manual testing tools, and comprehensive analysis capabilities in a clean, dark-themed interface that's both beginner-friendly and powerful enough for experienced security researchers.
[/long_descr]
A link or an attached image (minimum 1 required):
[image]
[/image]
[image]
[/image]
[image]
[/image]
[image]
[/image]
[image]
[/image]