Conference notes: How to Differentiate Yourself as a Bug Bounty Hunter (OWASP Stockholm)
Posted in Conference notes on November 7, 2018
Posted in Conference notes on April 26, 2018

Hi, these are the notes I took while watching the “Doing recon like a boss” talk given by Ben Sadeghipour (@nahamsec) on LevelUp 2017.
[UPDATE] I modified these notes after watching the updated version of this talk: “It’s the little things” by Ben Sadeghipour & Jon Bottarini (Disobey 2018).
site.com -www -cdnsite:s3.amazonaws.com + ... (for e.g site:s3.amazonaws.com + inurl:HackerOne)site:amazonaws.com -s3site:amazonsaws.com inurl:bugcrowd"amazonaws.com" trello"company.com" "dev""dev.company.com""dev.company.com" password/api_key"company.com" API_key"company.com" password"api.company.com"site:"Github.com" + "ORG" + ...Get creative!
443.https.tls.certificate.parsed.extensions.subject_alt_name.dns_name:bugcrowd.com"COMPANY" + internal (get creative)Ports: 8443, 8080, 8180, 15672, etcTitle: "Dashboard [Jenkins]"Product: TomcatHostname: corp.levelup.comOrg: BugcrowdOrg: Bugcrowd [option]hostname: company.com [option]
Where [option] is one of the options above (filter on ports, title or product)See you next time!