Conference notes: How to Differentiate Yourself as a Bug Bounty Hunter (OWASP Stockholm)
Posted in Conference notes on November 7, 2018
Posted in Conference notes on April 26, 2018
Hi, these are the notes I took while watching the “Doing recon like a boss” talk given by Ben Sadeghipour (@nahamsec) on LevelUp 2017.
[UPDATE] I modified these notes after watching the updated version of this talk: “It’s the little things” by Ben Sadeghipour & Jon Bottarini (Disobey 2018).
site.com -www -cdn
site:s3.amazonaws.com + ...
(for e.g site:s3.amazonaws.com + inurl:HackerOne
)site:amazonaws.com -s3
site:amazonsaws.com inurl:bugcrowd
"amazonaws.com" trello
"company.com" "dev"
"dev.company.com"
"dev.company.com" password/api_key
"company.com" API_key
"company.com" password
"api.company.com"
site:"Github.com" + "ORG" + ...
Get creative!
443.https.tls.certificate.parsed.extensions.subject_alt_name.dns_name:bugcrowd.com
"COMPANY" + internal (get creative)
Ports: 8443, 8080, 8180, 15672, etc
Title: "Dashboard [Jenkins]"
Product: Tomcat
Hostname: corp.levelup.com
Org: Bugcrowd
Org: Bugcrowd [option]
hostname: company.com [option]
Where [option] is one of the options above (filter on ports, title or product)See you next time!