Skip to main content

recon-and-methodology

Reconnaissance and methodology playbook. Use when mapping assets, discovering endpoints, fingerprinting technology, and building a structured testing plan for a new target.

설치로 이동

소스 정보

저장소
Kur1sulab/blackbox
최근 소스 활동
2026년 8월 12일 15:17
감지된 SKILL.md 언어
영어
스타
2
포크
0

설치 방법

기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.

소스 파일 검토

설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.

SKILL.md 표시 중

SKILL.md
소스 지침 · 읽기 전용 미리보기
name
recon-and-methodology
description
Reconnaissance and methodology playbook. Use when mapping assets, discovering endpoints, fingerprinting technology, and building a structured testing plan for a new target.
# SKILL: Recon and Methodology — Expert Bug Bounty Playbook > **AI LOAD INSTRUCTION**: Systematic recon and bug-finding methodology from top bug hunters. Covers subdomain enumeration, endpoint discovery, tech fingerprinting, and the hunter's mental model for finding bugs that others miss. Key insight: most high-severity bugs are found through systematic coverage, not just clever payloads. --- ## 1. RECON HIERARCHY ``` Target Selection └── Scope Definition (in-scope assets) └── Asset Discovery (subdomains, IPs, domains) └── Tech Fingerprinting (what's running) └── Endpoint Discovery (attack surface) └── Vulnerability Testing (per vulnerability type) ``` --- ## 2. SUBDOMAIN ENUMERATION (CRITICAL FIRST STEP) ### Passive (no DNS queries to target) ```bash # Subfinder (aggregates multiple sources): subfinder -d target.com -o subdomains.txt # Amass passive: amass enum -passive -d target.com # Certsh (certificate transparency): curl -s "https://crt.sh/?q=%.target.com&output=json" | jq -r '.[].name_value' | sort -u # SecurityTrails API, Shodan: # Web: https://securitytrails.com/list/apex_domain/target.com ``` ### Active (DNS brute force + resolution) ```bash # Massdns + wordlist: massdns -r /path/to/resolvers.txt -t A -o S -w output.txt \ <(cat wordlist.txt | sed 's/$/.target.com/') # ffuf for subdomain brute: ffuf -w subdomains-wordlist.txt -u https://FUZZ.target.com \ -mc 200,301,302,403 -H "Host: FUZZ.target.com" # DNSx for bulk resolution: cat subdomains.txt | dnsx -a -resp -o resolved.txt # Recommended wordlist: SecLists/Discovery/DNS/ ``` ### Virtual Host Discovery ```bash # ffuf vhost mode: ffuf -w wordlist.txt -u https://target.com \ -H "Host: FUZZ.target.com" -mc 200,301,403 # gobuster vhost: gobuster vhost -u https://target.com -w wordlist.txt ``` --- ## 3. SERVICE AND PORT DISCOVERY ```bash # Fast port scan (common ports): nmap -T4 -F target.com -oN ports.txt # Comprehensive scan on resolved subdomains: cat resolved_ips.txt | nmap -iL - --open -p 80,443,8080,8443,8888,3000,5000 -oG scan.txt # httpx for HTTP probing: cat subdomains.txt | httpx -title -tech-detect -status-code -o live_hosts.txt # masscan for speed on large IP ranges: masscan -p 80,443,8080,8443 10.0.0.0/8 --rate=1000 ``` --- ## 4. WEB TECHNOLOGY FINGERPRINTING ```bash # Wappalyzer (browser extension) or: whatweb https://target.com # httpx with tech detection: httpx -u https://target.com -tech-detect # Check headers manually: curl -sI https://target.com | grep -i "server\|x-powered-by\|x-generator\|cf-ray" # Fingerprint from: - Server header: nginx/1.18, Apache/2.4, IIS/10.0 - X-Powered-By: PHP/7.4, ASP.NET - Cookies: PHPSESSID (PHP), JSESSIONID (Java), _rails_session (Rails) - HTML comments: <!-- Drupal 9 --> - Meta generator: <meta name="generator" content="WordPress 6.2"> - JS framework files: /static/js/angular.min.js ``` --- ## 5. ENDPOINT DISCOVERY ### Directory Brute Force ```bash # ffuf (fastest): ffuf -u https://target.com/FUZZ -w /usr/share/seclists/Discovery/Web-Content/raft-medium-files.txt \ -mc 200,301,302,403 -t 50 -o dirs.txt # Gobuster: gobuster dir -u https://target.com -w wordlist.txt -x php,html,js,json # feroxbuster (recursive): feroxbuster -u https://target.com -w wordlist.txt -x php,html,txt -r ``` ### Parameter Discovery ```bash # Arjun (hidden parameter finder): arjun -u https://target.com/api/endpoint # x8: x8 -u https://target.com/api/endpoint -w params-wordlist.txt ``` ### JavaScript Source Mining ```bash # Extract endpoints from JS files: gau target.com | grep '\.js$' | httpx -mc 200 | xargs -I{} curl -s {} | \ grep -oE '"/[a-zA-Z0-9/_-]+"' | sort -u # LinkFinder: python3 linkfinder.py -i https://target.com -d -o output.html # GetAllURLs (gau): gau target.com | sort -u > all_urls.txt # Wayback URLs: waybackurls target.com | sort -u > wayback_urls.txt ``` ### Webpack / Vue CLI Chunk Mining (high-yield, low request cost) Admin panels built with Vue CLI (webpack) defer API calls to route chunks. Recipe: 1. Fetch index HTML → extract all `static/js/*.js` (app + chunk-*) — typically 2–45 small files 2. `app.*.js` usually holds only the axios `baseURL` (e.g. `baseURL:"/api-v2"`); request paths in axios calls are RELATIVE to it 3. Grep ALL downloaded JS for **relative paths**, not `/api...` prefixes — a `/api`-prefixed grep misses everything when baseURL carries the prefix (classic miss): `["'`](/[a-zA-Z][a-zA-Z0-9_\-/]{2,60})["'`]` 4. Filter out static dirs (/static /assets /images /css /js /fonts); leftovers = real handler paths 5. Also grep JS for `://subdomain` — H5/mobile bundles often hardcode the real backend host (found: h5 bundle pointing at `https://subadmin.target.cn/api-v2`) 6. Probe handlers with GET: `200 data` → open; `401` → auth OK; `404 "No handler found"` → wrong path/verb ### API Endpoint Discovery ```bash # Common API paths: ffuf -u https://target.com/FUZZ -w /SecLists/Discovery/Web-Content/api/api-endpoints.txt # Swagger/OpenAPI: test: /swagger.json /api-docs /openapi.json /v2/api-docs /.well-known/ /docs/ # GraphQL: test: /graphql /gql /v1/graphql /api/graphql ``` --- ## 6. SOURCE CODE RECON ### GitHub / GitLab Exposure ```bash # trufflehog (secret scanner in git history): trufflehog git https://github.com/target-org/target-repo # gitleaks: gitleaks detect --source /path/to/cloned/repo # Manual GitHub search: # site:github.com "target.com" "api_key" OR "secret" OR "password" # site:github.com "target.com" ".env" OR "config.php" OR "db_password" # GitHub dorks: # "target.com" extension:env # "target.com" filename:*.config password # org:target-org secret OR password OR apikey ``` ### Exposed Environment Files ``` # Check common paths: https://target.com/.env https://target.com/.git/config https://target.com/config.json https://target.com/config.yaml https://target.com/credentials.json https://target.com/secrets.json https://target.com/wp-config.php https://target.com/backup.sql https://target.com/backup.zip ``` --- ## 7. ZSEANO'S TESTING METHODOLOGY ### Core Philosophy 1. **Go deep on one program** rather than spread across many — learn the application thoroughly 2. **Build a profile of the company** — tech stack, developers, processes 3. **Look where others don't** — check error pages, admin paths, old versions, mobile API 4. **Follow the filter** — if input is filtered somewhere, that functionality exists and may be bypassed ### Testing Sequence (One Page / Feature) ``` For each input point: 1. Non-malicious HTML tags (<h2>, <img>) → are they reflected? 2. Incomplete tags → what happens? (<iframe src=//evil.com ) 3. Encoding tests → %0d, %0a, %09, <%00 4. Observe the OUTPUT too (not just response) — where does your input appear? 5. Test same input in ALL similarly-structured pages (shared code → shared vuln) 6. Check if the same parameter exists in mobile/API endpoint (less protected) ``` ### Parameter Insights ``` - Each parameter tells a story: "what does this do server-side?" - Filename → OS interaction → Path Traversal / CMDi - URL/location → HTTP fetch → SSRF - Template/HTML parameter → render function → SSTI - XML field → parser → XXE - SQL filter → query → SQLi - User-content → storage → Stored XSS ``` --- ## 8. BUG BOUNTY PROGRAM TRIAGE (WHERE TO SPEND TIME) ### High-Value Target Selection ``` ✓ Programs with large scope (*.target.com) ✓ Programs that pay for P2/P3 (not just RCE) ✓ Programs with recent tech changes (migrations = new bugs) ✓ Programs with active development (new features = new attack surface) × Avoid: frozen/old codebases with well-known CVEs (already claimed) × Avoid: strict programs with narrow scope (less surface) ``` ### High-Value Feature Focus (by bug probability) ``` Priority 1: Authentication, password reset, 2FA → account takeover Priority 2: File upload, profile edit, API endpoints → stored XSS, IDOR Priority 3: Admin panels, user management → BFLA, privilege escalation Priority 4: Payment flows, subscription → business logic Priority 5: Import/export, template rendering → XXE, SSTI ``` --- ## 9. NUCLEI TEMPLATES (AUTOMATED SCANNING) ```bash # Run all on target: nuclei -u https://target.com -t /nuclei-templates/ -o nuclei-results.txt # Specific categories: nuclei -u https://target.com -t cves/ -severity critical,high nuclei -u https://target.com -t exposures/ nuclei -u https://target.com -t misconfiguration/ # On subdomain list: cat subdomains.txt | nuclei -t exposures/ -t misconfiguration/ -o exposed.txt ``` --- ## 10. COMMON MISCONFIGURATIONS (QUICK WINS) ``` □ CORS: Access-Control-Allow-Origin: * with credentials → CSRF + data theft □ S3 bucket public: curl https://target.s3.amazonaws.com/ □ Directory listing: response contains "Index of /" □ .git exposed: curl https://target.com/.git/config □ .env exposed: curl https://target.com/.env □ Debug mode: stack traces in production (source code exposure) □ Default credentials: admin:admin, admin:password on admin panels □ phpinfo.php: curl https://target.com/phpinfo.php □ Backup files: config.bak, database.sql.gz, app.zip □ GraphQL introspection enabled: POST /graphql {"query":"{__schema{types{name}}}"} □ Admin panels: /admin /manager /console /phpmyadmin /wp-admin ``` --- ## 11. QUICK REFERENCE TOOLS | Category | Tool | |---|---| | Subdomain enum | subfinder, amass, massdns | | Port scan | nmap, masscan | | HTTP probe | httpx | | Dir brute | ffuf, feroxbuster, gobuster | | JS mining | LinkFinder, gau, waybackurls | | Secret scan | trufflehog, gitleaks | | Parameter fuzz | arjun, x8 | | Vuln scan | nuclei | | Proxy/intercept | Burp Suite Pro | | JWT attacks | jwt_tool | | SQLi | sqlmap | | XSS | dalfox, XSStrike | | SSRF | SSRFmap, Gopherus | --- ## 12. JAVA MIDDLEWARE FINGERPRINT MATRIX | Middleware | Detection Path | Key Indicators | |---|---|---| | Apache Tomcat | `/manager/html`, `/manager/status` | Default creds: `tomcat:tomcat`, `admin:admin` | | JBoss / WildFly | `/jmx-console/`, `/web-console/` | JMX MBean access, WAR deployment | | WebLogic | `/console/`, `/wls-wsat/` | T3 protocol on 7001/7002, IIOP | | Spring Boot Actuator | `/actuator/`, `/actuator/env`, `/actuator/heapdump` | JSON endpoint listing, heap dump contains secrets | | Spring Boot (alt paths) | `/actuator/jolokia`, `/actuator/gateway/routes` | Jolokia JMX bridge, Gateway route injection | | Jenkins | `/script`, `/manage` | Groovy console, API token in cookie | | GlassFish | `/common/`, `/theme/` | Admin on 4848, default empty password | | Jetty | `/jolokia/` | JMX access | | Resin | `/resin-admin/` | Admin panel | ### Spring Boot Actuator Exploitation Priority ``` /actuator/env → Leak environment variables (DB creds, API keys) /actuator/heapdump → Download JVM heap → search for passwords in memory /actuator/jolokia → JMX → possible RCE via MBean manipulation /actuator/gateway/routes → Spring Cloud Gateway → SpEL injection (CVE-2022-22947) /actuator/configprops → All configuration properties /actuator/mappings → All URL mappings (hidden endpoints) /actuator/beans → All Spring beans /actuator/threaddump → Thread dump (may leak session tokens / secrets in stack frames) ``` --- ## 13. INFORMATION LEAK DETECTION CHECKLIST ### Version Control & Backup Leaks ``` /.git/HEAD → Git repository exposed /.svn/entries → SVN metadata /.svn/wc.db → SVN SQLite database /.hg/requires → Mercurial /.bzr/README → Bazaar /.DS_Store → macOS directory listing ``` ### Backup File Patterns ``` /backup.zip /backup.tar.gz /backup.sql /wwwroot.rar /www.zip /web.zip /db.sql /database.sql /dump.sql /config.php.bak /config.php~ /config.php.swp /.config.php.swp /wp-config.php.bak /.env /.env.bak /.env.production ``` ### API Documentation & Debug ```
GitHub에서 보기
이 SKILL.md는 매우 커서 SkillsMP가 여기에는 첫 섹션만 미리 보여줍니다. GitHub에서 보기