Bug Bounty - Web Recon
Web recon playbook for single asset
Last updated
Was this helpful?
Web recon playbook for single asset
Last updated
Was this helpful?
Read all bug bounty program conditions, especially FAQ section, excluded domains and max probe rate.
Create project and set max rate for resource pool (automated tasks).
Add the domain to the scope
Edit Craws and Audit tasks and set Suited scope
Discover server ports and platform
Perform the detailed scan with adjusted probe speed (T1-T3) or (--max-rate 1)
This can app/domain /robots.txt
Fingerprint the webserver / web cache
Nonsense method, proto version
Path traversal
Host header injection - different domain, IP, multiple host headers
review HTML, title & comments