daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

bug-hunting-methodology.md (12362B)


      1 ---
      2 title: "Bug Hunting Methodology"
      3 section: "Methodology"
      4 sectionSlug: "methodology"
      5 sourcePath: "docs/methodology/bug-hunting-methodology.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/methodology/bug-hunting-methodology.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Bug Hunting Methodology
     12 
     13 ## Passive Recon
     14 
     15 * Using [shodan.io](https://www.shodan.io/), [fofa.info](https://en.fofa.info/), [zoomeye.ai](https://www.zoomeye.ai/) or [odin.io](https://search.odin.io/hosts) to detect similar app
     16 
     17   ```ps1
     18   # https://github.com/glennzw/shodan-hq-nse
     19   nmap --script shodan-hq.nse --script-args 'apikey=<yourShodanAPIKey>,target=<hackme>'
     20   ```
     21 
     22 * Search for similar websites using the same favicon: [pielco11/fav-up](https://github.com/pielco11/fav-up) or slightly different icon: [profundis.io/favicon-matcher](https://profundis.io/tools/favicon-matcher)
     23 
     24   ```ps1
     25   python3 favUp.py --favicon-file favicon.ico -sc
     26   python3 favUp.py --favicon-url https://domain.behind.cloudflare/assets/favicon.ico -sc
     27   python3 favUp.py --web domain.behind.cloudflare -s
     28   ```
     29 
     30 * Search inside Shortener URLs: [shorteners.grayhatwarfare.com](https://shorteners.grayhatwarfare.com/), [utkusen/urlhunter](https://github.com/utkusen/urlhunter)
     31 
     32   ```ps1
     33   urlhunter --keywords keywords.txt --date 2020-11-20
     34   ```
     35 
     36 * Search inside Buckets: [buckets.grayhatwarfare.com](https://buckets.grayhatwarfare.com/)
     37 
     38 * Using [The Wayback Machine](https://archive.org/web/) to detect forgotten endpoints
     39 
     40   ```powershell
     41   # Look for JS files, old links
     42   curl -sX GET "http://web.archive.org/cdx/search/cdx?url=<targetDomain.com>&output=text&fl=original&collapse=urlkey&matchType=prefix"
     43   ```
     44 
     45 * Using [laramies/theHarvester](https://github.com/laramies/theHarvester)
     46 
     47   ```python
     48   python theHarvester.py -b all -d domain.com
     49   ```
     50 
     51 * Look for private information in [GitHub](https://github.com) repositories with [michenriksen/GitRob](https://github.com/michenriksen/gitrob.git)
     52 
     53   ```bash
     54   gitrob analyze johndoe --site=https://github.acme.com --endpoint=https://github.acme.com/api/v3 --access-tokens=token1,token2
     55   ```
     56 
     57 * Perform Google Dorks search: [ikuamike/GoogleDorking.md](https://gist.github.com/ikuamike/c2611b171d64b823c1c1956129cbc055)
     58 
     59   ```ps1
     60   site: *.example.com -www
     61   intext:"dhcpd.conf" "index of"
     62   intitle:"SSL Network Extender Login" -checkpoint.com
     63   ```
     64 
     65 * Enumerate subdomains using HackerTarget
     66 
     67   ```ps1
     68   curl --silent 'https://api.hackertarget.com/hostsearch/?q=targetdomain.com' | grep -o '\w.*targetdomain.com'
     69   ```
     70 
     71 * Enumerate endpoints using CommonCrawl
     72 
     73   ```ps1
     74   echo "targetdomain.com" | xargs -I domain curl -s "http://index.commoncrawl.org/CC-MAIN-2018-22-index?url=*.targetdomain.com&output=json" | jq -r .url | sort -u
     75   ```
     76 
     77 ## Active Recon
     78 
     79 ### Network Discovery
     80 
     81 * Subdomains enumeration
     82     * Enumerate already found subdomains: [projectdiscovery/subfinder](https://github.com/projectdiscovery/subfinder), [OWASP/Amass](https://github.com/OWASP/Amass)
     83 
     84     ```ps1
     85     subfinder -d hackerone.com
     86     amass enum -passive -dir /tmp/amass_output/ -d example.com -o dir/example.com
     87     ```
     88 
     89     * Permutate subdomains: [infosec-au/altdns](https://github.com/infosec-au/altdns)
     90     * Bruteforce subdomains: [Josue87/gotator](https://github.com/Josue87/gotator)
     91     * Resolve subdomains to IP with [blechschmidt/massdns](https://github.com/blechschmidt/massdns), remember to use a good list of resolvers like [trickest/resolvers](https://github.com/trickest/resolvers)
     92 
     93     ```ps1
     94     massdns -r resolvers.txt -o S -w massdns.out subdomains.txt
     95     ```
     96 
     97     * Subdomain takeovers: [EdOverflow/can-i-take-over-xyz](https://github.com/EdOverflow/can-i-take-over-xyz)
     98 
     99 * Network discovery
    100     * Scan IP ranges with `nmap`, [robertdavidgraham/masscan](https://github.com/robertdavidgraham/masscan) and [projectdiscovery/naabu](https://github.com/projectdiscovery/naabu)
    101     * Discover services, version and banners
    102 
    103 * Review latest acquisitions
    104 
    105 * ASN enumeration
    106     * [projectdiscovery/asnmap](https://github.com/projectdiscovery/asnmap): `asnmap -a AS45596 -silent`
    107     * [asnlookup.com](http://www.asnlookup.com)
    108 
    109 * DNS Zone Transfer
    110 
    111   ```ps1
    112   host -t ns domain.local
    113   domain.local name server master.domain.local.
    114 
    115   host master.domain.local        
    116   master.domain.local has address 192.168.1.1
    117  
    118   dig axfr domain.local @192.168.1.1
    119   ```
    120 
    121 ### Web Discovery
    122 
    123 #### Common Files
    124 
    125 * `security.txt`: A file that provides contact info for reporting security issues with your site (like an email or PGP key).
    126 
    127   ```ps1
    128   Contact: mailto:security@example.com
    129   ```
    130 
    131 * `sitemap.xml`: Lists all the important URLs of your site so search engines can index them efficiently.
    132 
    133   ```ps1
    134   <urlset>
    135     <url><loc>https://example.com/</loc></url>
    136     <url><loc>https://example.com/about</loc></url>
    137   </urlset>
    138   ```
    139 
    140 * `robots.txt`: Tells search engine crawlers which pages or files they can or cannot access on your site.
    141 
    142   ```ps1
    143   User-agent: *
    144   Disallow: /admin/
    145   ```
    146 
    147 #### Enumerate Files and Folders
    148 
    149 Enumerate all accessible files and subdirectories. Once the underlying technology has been identified, prioritize the use of targeted wordlists rather than generic ones. Technology specific wordlists such as those provided by Assetnote ([https://wordlists.assetnote.io](https://wordlists.assetnote.io)), significantly improve coverage and efficiency. Examples include `httparchive_parameters_top_1m_2026_01_27.txt`, `httparchive_directories_1m_2026_01_27.txt`, and `httparchive_php_2026_01_27.txt`.
    150 
    151 * [OJ/gobuster](https://github.com/OJ/gobuster)
    152 * [ffuf/ffuf](https://github.com/ffuf/ffuf)
    153 * [bitquark/shortscan](https://github.com/bitquark/shortscan)
    154 
    155   ```ps1
    156   ffuf -H 'User-Agent: Mozilla' -v -t 30 -w mydirfilelist.txt -b 'NAME1=VALUE1; NAME2=VALUE2' -u 'https://example.com/FUZZ'
    157   gobuster dir -a 'Mozilla' -e -k -l -t 30 -w mydirfilelist.txt -c 'NAME1=VALUE1; NAME2=VALUE2' -u 'https://example.com/'
    158   ```
    159 
    160 Identify and enumerate backup and temporary files that may have been unintentionally exposed. These files often contain source code, credentials, or sensitive configuration data and are commonly created by editors, deployment processes, or manual backups.
    161 
    162 * [mazen160/bfac](https://github.com/mazen160/bfac)
    163 
    164 ```bash
    165 bfac --url http://example.com/test.php --level 4
    166 bfac --list testing_list.txt
    167 ```
    168 
    169 Crawl the website's pages and resources to identify additional attack surface and expand the assessment perimeter.
    170 
    171 * [hakluke/hakrawler](https://github.com/hakluke/hakrawler)
    172 * [projectdiscovery/katana](https://github.com/projectdiscovery/katana)
    173 
    174 ```ps1
    175 katana -u https://tesla.com
    176 echo https://google.com | hakrawler
    177 ```
    178 
    179 #### Next.js Endpoints
    180 
    181 In Next.js, `window.__BUILD_MANIFEST` is a runtime global variable that the framework automatically injects into the client-side JavaScript bundle.
    182 
    183 Go to `DevTools->Console` and execute this JavaScript code:
    184 
    185 ```js
    186 console.log(window.__BUILD_MANIFEST)
    187 console.log(__BUILD_MANIFEST.sortedPages)
    188 ```
    189 
    190 If you inspect your app in the browser console (for a production build), you might see something like this:
    191 
    192 ```js
    193 {__rewrites: {…}, /: Array(10), /404: Array(8), /500: Array(4), /_error: Array(1), …}
    194 /: (10) ['static/chunks/2852872c-b605aca0298c2109.js', 'static/chunks/3748-2a8cf394c7270ee0.js']
    195 /404: (8) ['static/chunks/2852872c-b605aca0298c2109.js', 'static/chunks/3748-2a8cf394c7270ee0.js']
    196 /500: (4) ['static/chunks/3748-2a8cf394c7270ee0.js', 'static/chunks/1221-b44c330d41258365.js']
    197 /[slug]: (30) ['static/chunks/2852872c-b605aca0298c2109.js', 'static/chunks/29107295-4cc022cea922dbb4.js']
    198 /_error: ['static/chunks/pages/_error-6ddff449d199572c.js']
    199 /about/[slug]: (31) ['static/chunks/2852872c-b605aca0298c2109.js']
    200 ```
    201 
    202 #### JS and HTML Comments
    203 
    204 Retrieve comments in source code.
    205 
    206 ```html
    207 <!-- HTML Comment -->
    208 // JS Comment
    209 ```
    210 
    211 #### Internet Archive
    212 
    213 Identify historical URLs and endpoints by reviewing archived content from sources such as the Wayback Machine and the Internet Archive.
    214 
    215 * [tomnomnom/waybackurls](https://github.com/tomnomnom/waybackurls)
    216 * [lc/gau](https://github.com/lc/gau)
    217 
    218 ```ps1
    219 gau --o example-urls.txt example.com
    220 gau --blacklist png,jpg,gif example.com
    221 ```
    222 
    223 #### Hidden Parameters
    224 
    225 Search for `hidden` parameters:
    226 
    227 * [PortSwigger/param-miner](https://github.com/PortSwigger/param-miner)
    228 * [s0md3v/Arjun](https://github.com/s0md3v/Arjun)
    229 * [Sh1Yo/x8](https://github.com/Sh1Yo/x8)
    230 
    231   ```ps1
    232   x8 -u "https://example.com/?something=1" -w <wordlist>
    233   ```
    234 
    235 #### Map Technologies
    236 
    237 * Web service enumeration using [projectdiscovery/httpx](https://github.com/projectdiscovery/httpx) or [projectdiscovery/wappalyzergo](https://github.com/projectdiscovery/wappalyzergo)
    238     * Favicon hash
    239     * JARM fingerprint
    240     * ASN
    241     * Status code
    242     * Services
    243     * Technologies (Github Pages, Cloudflare, Ruby, Nginx,...)
    244 
    245     ```ps1
    246     httpx -title -tech-detect -status-code -follow-redirects -jarm -asn -json -silent -ports 80,443 -l urls.txt
    247     ```
    248 
    249 * Look for WAF with [projectdiscovery/cdncheck](https://github.com/projectdiscovery/cdncheck) and identify the real IP with [christophetd/CloudFlair](https://github.com/christophetd/CloudFlair)
    250 
    251   ```ps1
    252   echo www.hackerone.com | cdncheck -resp
    253   www.hackerone.com [waf] [cloudflare]
    254   ```
    255 
    256 * Take screenshots for every websites using [sensepost/gowitness](https://github.com/sensepost/gowitness)
    257 
    258 #### Manual Testing
    259 
    260 Explore the website with a proxy:
    261 
    262 * [Caido - A lightweight web security auditing toolkit](https://caido.io/)
    263 * [ZAP - OWASP Zed Attack Proxy](https://www.zaproxy.org/)
    264 * [Burp Suite - Community Edition](https://portswigger.net/burp/communitydownload)
    265 
    266 #### Automated vulnerability scanners
    267 
    268 * [projectdiscovery/nuclei](https://github.com/projectdiscovery/nuclei):
    269 
    270   ```ps1
    271   nuclei -u https://example.com
    272   ```
    273 
    274 * [Burp Suite's web vulnerability scanner](https://portswigger.net/burp/vulnerability-scanner)
    275 * [sullo/nikto](https://github.com/sullo/nikto)
    276 
    277   ```ps1
    278   ./nikto.pl -h http://www.example.com
    279   ```
    280 
    281 ## Looking for Web Vulnerabilities
    282 
    283 * Explore the website and look for vulnerabilities listed in this repository: SQL injection, XSS, CRLF, Cookies, ....
    284 * Test for Business Logic weaknesses
    285     * High or negative numerical values
    286     * Try all the features and click all the buttons
    287 * [The Web Application Hacker's Handbook Checklist](https://web.archive.org/web/20210126221152/https://gist.github.com/gbedoya/10935137)
    288 
    289 * Subscribe to the site and pay for the additional functionality to test
    290 
    291 * Inspect Payment functionality - [@gwendallecoguic](https://twitter.com/gwendallecoguic/status/988138794686779392)
    292   > If the webapp you're testing uses an external payment gateway, check the doc to find the test credit numbers, purchase something and if the webapp didn't disable the test mode, it will be free
    293 
    294   From [https://stripe.com/docs/testing](https://stripe.com/docs/testing#cards) : "Use any of the following test card numbers, a valid expiration date in the future, and any random CVC number, to create a successful payment. Each test card's billing country is set to U.S."
    295 
    296   Test card numbers and tokens  
    297 
    298   | NUMBER           | BRAND          | TOKEN          |
    299   | :-------------   | :------------- | :------------- |
    300   | 4242424242424242 | Visa           | tok_visa       |
    301   | 4000056655665556 | Visa (debit)   | tok_visa_debit |
    302   | 5555555555554444 | Mastercard     | tok_mastercard |
    303 
    304   International test card numbers and tokens
    305 
    306   | NUMBER           | TOKEN          | COUNTRY        | BRAND          |
    307   | :-------------   | :------------- | :------------- | :------------- |
    308   | 4000000400000008 | tok_at         | Austria (AT)   | Visa           |
    309   | 4000000560000004 | tok_be         | Belgium (BE)   | Visa           |
    310   | 4000002080000001 | tok_dk         | Denmark (DK)   | Visa           |
    311   | 4000002460000001 | tok_fi         | Finland (FI)   | Visa           |
    312   | 4000002500000003 | tok_fr         | France (FR)    | Visa           |
    313 
    314 ## References
    315 
    316 * [Nmap CheatSheet - HackerTarget](https://hackertarget.com/nmap-cheatsheet-a-quick-reference-guide/)
    317 * [Yahoo phpinfo.php disclosure - Patrik Fehrenbach - January 20, 2013](https://blog.wss.sh/bugbounty-yahoo-phpinfo-php-disclosure/)
    318 * [Bug Bounty Masterclass - Wiz, Gal Nagli](https://www.wiz.io/bug-bounty-masterclass)