bug-hunting-methodology.md (12362B)
1 --- 2 title: "Bug Hunting Methodology" 3 section: "Methodology" 4 sectionSlug: "methodology" 5 sourcePath: "docs/methodology/bug-hunting-methodology.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/methodology/bug-hunting-methodology.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Bug Hunting Methodology 12 13 ## Passive Recon 14 15 * Using [shodan.io](https://www.shodan.io/), [fofa.info](https://en.fofa.info/), [zoomeye.ai](https://www.zoomeye.ai/) or [odin.io](https://search.odin.io/hosts) to detect similar app 16 17 ```ps1 18 # https://github.com/glennzw/shodan-hq-nse 19 nmap --script shodan-hq.nse --script-args 'apikey=<yourShodanAPIKey>,target=<hackme>' 20 ``` 21 22 * Search for similar websites using the same favicon: [pielco11/fav-up](https://github.com/pielco11/fav-up) or slightly different icon: [profundis.io/favicon-matcher](https://profundis.io/tools/favicon-matcher) 23 24 ```ps1 25 python3 favUp.py --favicon-file favicon.ico -sc 26 python3 favUp.py --favicon-url https://domain.behind.cloudflare/assets/favicon.ico -sc 27 python3 favUp.py --web domain.behind.cloudflare -s 28 ``` 29 30 * Search inside Shortener URLs: [shorteners.grayhatwarfare.com](https://shorteners.grayhatwarfare.com/), [utkusen/urlhunter](https://github.com/utkusen/urlhunter) 31 32 ```ps1 33 urlhunter --keywords keywords.txt --date 2020-11-20 34 ``` 35 36 * Search inside Buckets: [buckets.grayhatwarfare.com](https://buckets.grayhatwarfare.com/) 37 38 * Using [The Wayback Machine](https://archive.org/web/) to detect forgotten endpoints 39 40 ```powershell 41 # Look for JS files, old links 42 curl -sX GET "http://web.archive.org/cdx/search/cdx?url=<targetDomain.com>&output=text&fl=original&collapse=urlkey&matchType=prefix" 43 ``` 44 45 * Using [laramies/theHarvester](https://github.com/laramies/theHarvester) 46 47 ```python 48 python theHarvester.py -b all -d domain.com 49 ``` 50 51 * Look for private information in [GitHub](https://github.com) repositories with [michenriksen/GitRob](https://github.com/michenriksen/gitrob.git) 52 53 ```bash 54 gitrob analyze johndoe --site=https://github.acme.com --endpoint=https://github.acme.com/api/v3 --access-tokens=token1,token2 55 ``` 56 57 * Perform Google Dorks search: [ikuamike/GoogleDorking.md](https://gist.github.com/ikuamike/c2611b171d64b823c1c1956129cbc055) 58 59 ```ps1 60 site: *.example.com -www 61 intext:"dhcpd.conf" "index of" 62 intitle:"SSL Network Extender Login" -checkpoint.com 63 ``` 64 65 * Enumerate subdomains using HackerTarget 66 67 ```ps1 68 curl --silent 'https://api.hackertarget.com/hostsearch/?q=targetdomain.com' | grep -o '\w.*targetdomain.com' 69 ``` 70 71 * Enumerate endpoints using CommonCrawl 72 73 ```ps1 74 echo "targetdomain.com" | xargs -I domain curl -s "http://index.commoncrawl.org/CC-MAIN-2018-22-index?url=*.targetdomain.com&output=json" | jq -r .url | sort -u 75 ``` 76 77 ## Active Recon 78 79 ### Network Discovery 80 81 * Subdomains enumeration 82 * Enumerate already found subdomains: [projectdiscovery/subfinder](https://github.com/projectdiscovery/subfinder), [OWASP/Amass](https://github.com/OWASP/Amass) 83 84 ```ps1 85 subfinder -d hackerone.com 86 amass enum -passive -dir /tmp/amass_output/ -d example.com -o dir/example.com 87 ``` 88 89 * Permutate subdomains: [infosec-au/altdns](https://github.com/infosec-au/altdns) 90 * Bruteforce subdomains: [Josue87/gotator](https://github.com/Josue87/gotator) 91 * Resolve subdomains to IP with [blechschmidt/massdns](https://github.com/blechschmidt/massdns), remember to use a good list of resolvers like [trickest/resolvers](https://github.com/trickest/resolvers) 92 93 ```ps1 94 massdns -r resolvers.txt -o S -w massdns.out subdomains.txt 95 ``` 96 97 * Subdomain takeovers: [EdOverflow/can-i-take-over-xyz](https://github.com/EdOverflow/can-i-take-over-xyz) 98 99 * Network discovery 100 * Scan IP ranges with `nmap`, [robertdavidgraham/masscan](https://github.com/robertdavidgraham/masscan) and [projectdiscovery/naabu](https://github.com/projectdiscovery/naabu) 101 * Discover services, version and banners 102 103 * Review latest acquisitions 104 105 * ASN enumeration 106 * [projectdiscovery/asnmap](https://github.com/projectdiscovery/asnmap): `asnmap -a AS45596 -silent` 107 * [asnlookup.com](http://www.asnlookup.com) 108 109 * DNS Zone Transfer 110 111 ```ps1 112 host -t ns domain.local 113 domain.local name server master.domain.local. 114 115 host master.domain.local 116 master.domain.local has address 192.168.1.1 117 118 dig axfr domain.local @192.168.1.1 119 ``` 120 121 ### Web Discovery 122 123 #### Common Files 124 125 * `security.txt`: A file that provides contact info for reporting security issues with your site (like an email or PGP key). 126 127 ```ps1 128 Contact: mailto:security@example.com 129 ``` 130 131 * `sitemap.xml`: Lists all the important URLs of your site so search engines can index them efficiently. 132 133 ```ps1 134 <urlset> 135 <url><loc>https://example.com/</loc></url> 136 <url><loc>https://example.com/about</loc></url> 137 </urlset> 138 ``` 139 140 * `robots.txt`: Tells search engine crawlers which pages or files they can or cannot access on your site. 141 142 ```ps1 143 User-agent: * 144 Disallow: /admin/ 145 ``` 146 147 #### Enumerate Files and Folders 148 149 Enumerate all accessible files and subdirectories. Once the underlying technology has been identified, prioritize the use of targeted wordlists rather than generic ones. Technology specific wordlists such as those provided by Assetnote ([https://wordlists.assetnote.io](https://wordlists.assetnote.io)), significantly improve coverage and efficiency. Examples include `httparchive_parameters_top_1m_2026_01_27.txt`, `httparchive_directories_1m_2026_01_27.txt`, and `httparchive_php_2026_01_27.txt`. 150 151 * [OJ/gobuster](https://github.com/OJ/gobuster) 152 * [ffuf/ffuf](https://github.com/ffuf/ffuf) 153 * [bitquark/shortscan](https://github.com/bitquark/shortscan) 154 155 ```ps1 156 ffuf -H 'User-Agent: Mozilla' -v -t 30 -w mydirfilelist.txt -b 'NAME1=VALUE1; NAME2=VALUE2' -u 'https://example.com/FUZZ' 157 gobuster dir -a 'Mozilla' -e -k -l -t 30 -w mydirfilelist.txt -c 'NAME1=VALUE1; NAME2=VALUE2' -u 'https://example.com/' 158 ``` 159 160 Identify and enumerate backup and temporary files that may have been unintentionally exposed. These files often contain source code, credentials, or sensitive configuration data and are commonly created by editors, deployment processes, or manual backups. 161 162 * [mazen160/bfac](https://github.com/mazen160/bfac) 163 164 ```bash 165 bfac --url http://example.com/test.php --level 4 166 bfac --list testing_list.txt 167 ``` 168 169 Crawl the website's pages and resources to identify additional attack surface and expand the assessment perimeter. 170 171 * [hakluke/hakrawler](https://github.com/hakluke/hakrawler) 172 * [projectdiscovery/katana](https://github.com/projectdiscovery/katana) 173 174 ```ps1 175 katana -u https://tesla.com 176 echo https://google.com | hakrawler 177 ``` 178 179 #### Next.js Endpoints 180 181 In Next.js, `window.__BUILD_MANIFEST` is a runtime global variable that the framework automatically injects into the client-side JavaScript bundle. 182 183 Go to `DevTools->Console` and execute this JavaScript code: 184 185 ```js 186 console.log(window.__BUILD_MANIFEST) 187 console.log(__BUILD_MANIFEST.sortedPages) 188 ``` 189 190 If you inspect your app in the browser console (for a production build), you might see something like this: 191 192 ```js 193 {__rewrites: {…}, /: Array(10), /404: Array(8), /500: Array(4), /_error: Array(1), …} 194 /: (10) ['static/chunks/2852872c-b605aca0298c2109.js', 'static/chunks/3748-2a8cf394c7270ee0.js'] 195 /404: (8) ['static/chunks/2852872c-b605aca0298c2109.js', 'static/chunks/3748-2a8cf394c7270ee0.js'] 196 /500: (4) ['static/chunks/3748-2a8cf394c7270ee0.js', 'static/chunks/1221-b44c330d41258365.js'] 197 /[slug]: (30) ['static/chunks/2852872c-b605aca0298c2109.js', 'static/chunks/29107295-4cc022cea922dbb4.js'] 198 /_error: ['static/chunks/pages/_error-6ddff449d199572c.js'] 199 /about/[slug]: (31) ['static/chunks/2852872c-b605aca0298c2109.js'] 200 ``` 201 202 #### JS and HTML Comments 203 204 Retrieve comments in source code. 205 206 ```html 207 <!-- HTML Comment --> 208 // JS Comment 209 ``` 210 211 #### Internet Archive 212 213 Identify historical URLs and endpoints by reviewing archived content from sources such as the Wayback Machine and the Internet Archive. 214 215 * [tomnomnom/waybackurls](https://github.com/tomnomnom/waybackurls) 216 * [lc/gau](https://github.com/lc/gau) 217 218 ```ps1 219 gau --o example-urls.txt example.com 220 gau --blacklist png,jpg,gif example.com 221 ``` 222 223 #### Hidden Parameters 224 225 Search for `hidden` parameters: 226 227 * [PortSwigger/param-miner](https://github.com/PortSwigger/param-miner) 228 * [s0md3v/Arjun](https://github.com/s0md3v/Arjun) 229 * [Sh1Yo/x8](https://github.com/Sh1Yo/x8) 230 231 ```ps1 232 x8 -u "https://example.com/?something=1" -w <wordlist> 233 ``` 234 235 #### Map Technologies 236 237 * Web service enumeration using [projectdiscovery/httpx](https://github.com/projectdiscovery/httpx) or [projectdiscovery/wappalyzergo](https://github.com/projectdiscovery/wappalyzergo) 238 * Favicon hash 239 * JARM fingerprint 240 * ASN 241 * Status code 242 * Services 243 * Technologies (Github Pages, Cloudflare, Ruby, Nginx,...) 244 245 ```ps1 246 httpx -title -tech-detect -status-code -follow-redirects -jarm -asn -json -silent -ports 80,443 -l urls.txt 247 ``` 248 249 * Look for WAF with [projectdiscovery/cdncheck](https://github.com/projectdiscovery/cdncheck) and identify the real IP with [christophetd/CloudFlair](https://github.com/christophetd/CloudFlair) 250 251 ```ps1 252 echo www.hackerone.com | cdncheck -resp 253 www.hackerone.com [waf] [cloudflare] 254 ``` 255 256 * Take screenshots for every websites using [sensepost/gowitness](https://github.com/sensepost/gowitness) 257 258 #### Manual Testing 259 260 Explore the website with a proxy: 261 262 * [Caido - A lightweight web security auditing toolkit](https://caido.io/) 263 * [ZAP - OWASP Zed Attack Proxy](https://www.zaproxy.org/) 264 * [Burp Suite - Community Edition](https://portswigger.net/burp/communitydownload) 265 266 #### Automated vulnerability scanners 267 268 * [projectdiscovery/nuclei](https://github.com/projectdiscovery/nuclei): 269 270 ```ps1 271 nuclei -u https://example.com 272 ``` 273 274 * [Burp Suite's web vulnerability scanner](https://portswigger.net/burp/vulnerability-scanner) 275 * [sullo/nikto](https://github.com/sullo/nikto) 276 277 ```ps1 278 ./nikto.pl -h http://www.example.com 279 ``` 280 281 ## Looking for Web Vulnerabilities 282 283 * Explore the website and look for vulnerabilities listed in this repository: SQL injection, XSS, CRLF, Cookies, .... 284 * Test for Business Logic weaknesses 285 * High or negative numerical values 286 * Try all the features and click all the buttons 287 * [The Web Application Hacker's Handbook Checklist](https://web.archive.org/web/20210126221152/https://gist.github.com/gbedoya/10935137) 288 289 * Subscribe to the site and pay for the additional functionality to test 290 291 * Inspect Payment functionality - [@gwendallecoguic](https://twitter.com/gwendallecoguic/status/988138794686779392) 292 > If the webapp you're testing uses an external payment gateway, check the doc to find the test credit numbers, purchase something and if the webapp didn't disable the test mode, it will be free 293 294 From [https://stripe.com/docs/testing](https://stripe.com/docs/testing#cards) : "Use any of the following test card numbers, a valid expiration date in the future, and any random CVC number, to create a successful payment. Each test card's billing country is set to U.S." 295 296 Test card numbers and tokens 297 298 | NUMBER | BRAND | TOKEN | 299 | :------------- | :------------- | :------------- | 300 | 4242424242424242 | Visa | tok_visa | 301 | 4000056655665556 | Visa (debit) | tok_visa_debit | 302 | 5555555555554444 | Mastercard | tok_mastercard | 303 304 International test card numbers and tokens 305 306 | NUMBER | TOKEN | COUNTRY | BRAND | 307 | :------------- | :------------- | :------------- | :------------- | 308 | 4000000400000008 | tok_at | Austria (AT) | Visa | 309 | 4000000560000004 | tok_be | Belgium (BE) | Visa | 310 | 4000002080000001 | tok_dk | Denmark (DK) | Visa | 311 | 4000002460000001 | tok_fi | Finland (FI) | Visa | 312 | 4000002500000003 | tok_fr | France (FR) | Visa | 313 314 ## References 315 316 * [Nmap CheatSheet - HackerTarget](https://hackertarget.com/nmap-cheatsheet-a-quick-reference-guide/) 317 * [Yahoo phpinfo.php disclosure - Patrik Fehrenbach - January 20, 2013](https://blog.wss.sh/bugbounty-yahoo-phpinfo-php-disclosure/) 318 * [Bug Bounty Masterclass - Wiz, Gal Nagli](https://www.wiz.io/bug-bounty-masterclass)