✎Grep tips for Javascript Analysis
• Extracting JavaScript Files from recursive Directories
• Searching for API Keys and Secrets
• Detecting Dangerous Function Calls
• Checking for URL Manipulation
• Searching for Cross-Origin Requests
• Analyzing
• Finding Hardcoded URLs or Endpoints
• Locating Debugging Information
• Investigating User Input Handling
#bugbounty #recon #javascript
© t.iss.one/BugBounty_Diary
• Extracting JavaScript Files from recursive Directories
find /path/to/your/folders -name "*.js" -exec mv {} /path/to/target/folder/ \;• Searching for API Keys and Secrets
cat * | grep -rE "apikey|api_key|secret|token|password|auth|key|pass|user"
• Detecting Dangerous Function Calls
cat * | grep -rE "eval|document\.write|innerHTML|setTimeout|setInterval|Function"
• Checking for URL Manipulation
cat * | grep -rE "location\.href|location\.replace|location\.assign|window\.open"
• Searching for Cross-Origin Requests
cat * | grep -rE "XMLHttpRequest|fetch|Access-Control-Allow-Origin|withCredentials" /path/to/js/files
• Analyzing
postMessage Usagecat * | grep -r "postMessage"
• Finding Hardcoded URLs or Endpoints
cat * | grep -rE "https?://|www\."
• Locating Debugging Information
cat * | grep -rE "console\.log|debugger|alert|console\.dir"
• Investigating User Input Handling
cat * | grep -rE "document\.getElementById|document\.getElementsByClassName|document\.querySelector|document\.forms"
#bugbounty #recon #javascript
© t.iss.one/BugBounty_Diary
❤13❤🔥2
Just wanted to inform you that Writeup-Miner is now live on @Daily_Writeups.
Join if you want the latest Bug Bounty and Cybersecurity write-ups.
Thank you all ♥️🙌
Join if you want the latest Bug Bounty and Cybersecurity write-ups.
Thank you all ♥️🙌
❤17❤🔥4🔥4
✎ Cloud Security One Liners
• AWS S3 Bucket Finder
• S3 Permission Check
• Firebase Database
• Azure Blob Storage
• GCP Storage
• AWS Metadata SSRF
• Cloud Credential Files
#bugbounty #recon #cloud
© t.iss.one/BugBounty_Diary
• AWS S3 Bucket Finder
cat urls.txt | grep -oE "[a-zA-Z0-9.-]+\.s3\.amazonaws\.com" | anew s3_buckets.txt
cat urls.txt | grep -oE "s3://[a-zA-Z0-9.-]+" | anew s3_buckets.txt
• S3 Permission Check
cat s3_buckets.txt | xargs -I@ sh -c 'aws s3 ls s3://@ --no-sign-request 2>/dev/null && echo "OPEN: @"'
• Firebase Database
cat urls.txt | grep -oE "[a-zA-Z0-9-]+\.firebaseio\.com" | xargs -I@ curl -s @/.json | grep -v "null"
• Azure Blob Storage
cat urls.txt | grep -oE "[a-zA-Z0-9-]+\.blob\.core\.windows\.net" | anew azure_blobs.txt
• GCP Storage
cat urls.txt | grep -oE "storage\.googleapis\.com/[a-zA-Z0-9-]+" | anew gcp_buckets.txt
• AWS Metadata SSRF
cat urls.txt | gf ssrf | qsreplace "https://169.254.169.254/latest/meta-data/iam/security-credentials/" | httpx -silent -ms "AccessKeyId"
• Cloud Credential Files
cat alive.txt | httpx -silent -path /.aws/credentials,/.docker/config.json,/kubeconfig -mc 200 | anew cloud_creds.txt
#bugbounty #recon #cloud
© t.iss.one/BugBounty_Diary
❤24❤🔥1
Hey dear subscribers,
This channel has been inactive for one week because Iran's government shut down the entire internet, preventing us from accessing free internet as usual. I was very worried about my open reports and this channel. Starting today, I am working hard and focusing on posting more content.
Thank you all,
🕷 Spix0r
This channel has been inactive for one week because Iran's government shut down the entire internet, preventing us from accessing free internet as usual. I was very worried about my open reports and this channel. Starting today, I am working hard and focusing on posting more content.
Thank you all,
🕷 Spix0r
1❤47👍7🔥3❤🔥2🤝1
✎ Burp Extension for API Testing in JS-Rich Targets
This tool helps identify endpoints, files, internal emails, and some secrets hidden in minified JavaScript, achieving maximum efficiency while minimizing noise in the results.
• Repository: Github
#bugbounty #recon #javascript #burp
© t.iss.one/BugBounty_Diary
This tool helps identify endpoints, files, internal emails, and some secrets hidden in minified JavaScript, achieving maximum efficiency while minimizing noise in the results.
• Repository: Github
#bugbounty #recon #javascript #burp
© t.iss.one/BugBounty_Diary
🔥10❤5❤🔥1👍1
✎ Network Basics - Module 1
I’ve decided to write the concepts of Network through the lens of security. My goal is to keep only the parts that truly matter for cybersecurity, ethical hacking, and bug bounty and remove the noise.
Module 1 is now ready, and I’m excited to share it with you.
Hope you find it useful and insightful.
• Blog: Network Basics - Module 1
#bugbounty #network
© t.iss.one/BugBounty_Diary
I’ve decided to write the concepts of Network through the lens of security. My goal is to keep only the parts that truly matter for cybersecurity, ethical hacking, and bug bounty and remove the noise.
Module 1 is now ready, and I’m excited to share it with you.
Hope you find it useful and insightful.
--Explaining Network Topologies--
• Blog: Network Basics - Module 1
#bugbounty #network
© t.iss.one/BugBounty_Diary
🔥17❤6❤🔥1
✎ Tuning Time, Depth, and Accuracy in Port Scanning
Different port scanners excel in different aspects
• Nmap → depth
• MassScan → scalability
• Naabu → simplicity
• RustScan → speed
Nabuu + Nmap
1. Service version detection
2. Full vuln scan on discovered ports
3. Quick banner grab + OS detection
• The flow: Naabu finds open ports fast → pipes them to nmap for deeper enumeration. Best of both worlds.
#bugbounty #recon #portscan
© t.iss.one/BugBounty_Diary
Different port scanners excel in different aspects
• Nmap → depth
• MassScan → scalability
• Naabu → simplicity
• RustScan → speed
Nabuu + Nmap
1. Service version detection
naabu -host https://example.com -p 80,443,8080 -nmap-cli 'nmap -sV -sC'
2. Full vuln scan on discovered ports
naabu -l targets.txt -top-ports 1000 -nmap-cli 'nmap -sV --script vuln -oN nmap-vuln.txt'
3. Quick banner grab + OS detection
naabu -host 10.0.0.0/24 -p 22,80,443 -nmap-cli 'nmap -sV -O --script banner -oG results.gnmap'
• The flow: Naabu finds open ports fast → pipes them to nmap for deeper enumeration. Best of both worlds.
#bugbounty #recon #portscan
© t.iss.one/BugBounty_Diary
🔥14❤8❤🔥2
✎ IP Spoofing to Account Takeover: You Patched It? Really?
In my previous article, I described how I found a security flaw in a popular desktop app's OAuth flow that allowed me to steal any user's account with just one click. I reported it, saw it patched, and then bypassed the patch again. Since the process of bypassing and exploiting the flaw is interesting to me, I decided to write a second article about it.
• Blog: IP Spoofing to Account Takeover
#bugbounty #ipspoofing #oauth
© t.iss.one/BugBounty_Diary
In my previous article, I described how I found a security flaw in a popular desktop app's OAuth flow that allowed me to steal any user's account with just one click. I reported it, saw it patched, and then bypassed the patch again. Since the process of bypassing and exploiting the flaw is interesting to me, I decided to write a second article about it.
• Blog: IP Spoofing to Account Takeover
#bugbounty #ipspoofing #oauth
© t.iss.one/BugBounty_Diary
1🔥15❤9👍3❤🔥1
✎ Network Basics - Module 2
Module 2 is now live on my Hashnode series.
Stripped down to the essentials, focusing only on what actually matters for understanding networks from a cybersecurity perspective.
• Blog: Network Basics - Module 2
#bugbounty #network
© t.iss.one/BugBounty_Diary
Module 2 is now live on my Hashnode series.
--Ethernet--
Stripped down to the essentials, focusing only on what actually matters for understanding networks from a cybersecurity perspective.
• Blog: Network Basics - Module 2
#bugbounty #network
© t.iss.one/BugBounty_Diary
🔥13
✎ ASN → IP Recon Workflow (BGPView alternative)
I used to rely on bgpview.io for extracting IP ranges from ASNs it was free and useful for recon workflows. But after it went down, I looked for an alternative and found this awesome repo:
• as-ip-blocks: Github
It lets you pull IPv4/IPv6 prefixes per ASN directly from raw GitHub data, which is ideal for automation.
</> Bash Function for ASN → IP Enumeration
You can plug this directly into your recon pipeline or customize it for your tools
• Single ASN → IP Ranges
• List of ASNs → IP Ranges
#bugbounty #recon #automation
© t.iss.one/BugBounty_Diary
I used to rely on bgpview.io for extracting IP ranges from ASNs it was free and useful for recon workflows. But after it went down, I looked for an alternative and found this awesome repo:
• as-ip-blocks: Github
It lets you pull IPv4/IPv6 prefixes per ASN directly from raw GitHub data, which is ideal for automation.
</> Bash Function for ASN → IP Enumeration
You can plug this directly into your recon pipeline or customize it for your tools
asn2ip() {
local base="https://raw.githubusercontent.com/ipverse/as-ip-blocks/master/as"
fetch_asn() {
curl -fsSL "$base/$1/aggregated.json" \
| jq -r '.prefixes.ipv4[]?' 2>/dev/null \
| sort -u
}
if [ ! -t 0 ]; then
while IFS= read -r asn; do
fetch_asn "$asn"
done
else
fetch_asn "$1"
fi
}• Single ASN → IP Ranges
asn2ip 1234
• List of ASNs → IP Ranges
cat asnList | asn2ip
#bugbounty #recon #automation
© t.iss.one/BugBounty_Diary
❤24
✎ Network Basics - Module 3
Module 3 is now live on my Hashnode series.
As always stripped down to the essentials with no fluff.
• Blog: Network Basics - Module 3
#bugbounty #network
© t.iss.one/BugBounty_Diary
Module 3 is now live on my Hashnode series.
--Interfaces & Switches--
As always stripped down to the essentials with no fluff.
• Blog: Network Basics - Module 3
#bugbounty #network
© t.iss.one/BugBounty_Diary
❤8
-----‐-------------------------------
✎ Linux Security → SUID & Privilege Boundaries
-----‐-------------------------------
In Linux, security heavily depends on permission architecture.
One critical mechanism is SUID (Set User ID).
● What is SUID?
When SUID is applied to an executable, it runs with the file owner’s permissions instead of the executing user’s.
If the file is owned by root, it grants elevated privileges.
• The s indicates SUID.
This allows normal users to run passwd, which needs root access to update /etc/shadow.
SUID itself is legitimate, misconfigured SUID binaries are dangerous.
If powerful binaries like:
• bash
• vim
• find
are improperly assigned SUID, they may be abused for privilege escalation.
● Enumerating SUID Binaries
This way we can find the files with SUID.
● A Usage example:
Let's say find has SUID
With this you can open a shell as the root.
● To Audit
You need find the files with SUID the way I said before and delete the tag :
#bugbounty #Linux
© t.iss.one/BugBounty_Diary
✎ Linux Security → SUID & Privilege Boundaries
-----‐-------------------------------
In Linux, security heavily depends on permission architecture.
One critical mechanism is SUID (Set User ID).
● What is SUID?
When SUID is applied to an executable, it runs with the file owner’s permissions instead of the executing user’s.
If the file is owned by root, it grants elevated privileges.
[me@linux ~]$ ls -l /usr/bin/passwd
-rwsr-xr-x 1 root root ...
• The s indicates SUID.
This allows normal users to run passwd, which needs root access to update /etc/shadow.
SUID itself is legitimate, misconfigured SUID binaries are dangerous.
If powerful binaries like:
• bash
• vim
• find
are improperly assigned SUID, they may be abused for privilege escalation.
● Enumerating SUID Binaries
find / -perm -4000 -type f 2>/dev/null
This way we can find the files with SUID.
● A Usage example:
Let's say find has SUID
find . -exec /bin/sh -p \; -quit
With this you can open a shell as the root.
● To Audit
You need find the files with SUID the way I said before and delete the tag :
chmod u-s /path/to/binary
#bugbounty #Linux
© t.iss.one/BugBounty_Diary
🔥10❤2
-----‐-------------------------------
✎ Discovering Domains via NS Correlation
-----‐-------------------------------
● What is a Nameserver?
A nameserver (NS) is a specialised server within the Domain Name System (DNS) which translates human-readable domain names into IP addresses. Essentially, nameservers tell the internet where to find your web server.
In this post I will describe a simple technique which can be used to correlate one or more websites using NS data.
● Finding Nameservers
To find the nameservers for a domain name, the simplest way is to use the
● Finding Related Domains
Some DNS providers like Cloudflare will assign you a NS pair at the account level. This means that all domain names you add to your account will share the same NS pair.
In the example above,
● Downloading The Dataset
Merklemap provides a DNS record database containing 4 billion+ records. You can download it here.
The dataset is provided in JSONL format and is compressed using
● Querying the Dataset
One way to query the parsed data is using
Looking at
In a lot of cases you might not be able to correlate one website to another based on just a keyword in the domain name. In those cases you can do things like:
• Fingerprint HTTP responses
• Compare WHOIS information
• Compare technologies used
• DNS similarities
#bugbounty #recon #DNS
© t.iss.one/BugBounty_Diary
✎ Discovering Domains via NS Correlation
-----‐-------------------------------
● What is a Nameserver?
A nameserver (NS) is a specialised server within the Domain Name System (DNS) which translates human-readable domain names into IP addresses. Essentially, nameservers tell the internet where to find your web server.
In this post I will describe a simple technique which can be used to correlate one or more websites using NS data.
● Finding Nameservers
To find the nameservers for a domain name, the simplest way is to use the
dig tool:$ dig +noall +answer ns deliveroo.com
deliveroo.com. 86400 IN NS mona.ns.cloudflare.com.
deliveroo.com. 86400 IN NS phil.ns.cloudflare.com.
● Finding Related Domains
Some DNS providers like Cloudflare will assign you a NS pair at the account level. This means that all domain names you add to your account will share the same NS pair.
In the example above,
deliveroo.com uses the Cloudflare nameserver pair mona.ns.cloudflare.com and phil.ns.cloudflare.com. Domains added under the same Cloudflare account are often assigned the same NS pair. Since the number of possible Cloudflare NS pair combinations is limited, many domains share them, making it relatively easy to identify other domains that may be managed by the same operator.● Downloading The Dataset
Merklemap provides a DNS record database containing 4 billion+ records. You can download it here.
The dataset is provided in JSONL format and is compressed using
xz. The uncompressed raw data is around ~500GB in size. If you just want to extract domain/NS pairs in the format domain,ns1,ns2,ns... you can use xzcat with jq like so:xzcat dns_records_database.jsonl.xz | jq -r '
select([.results[] | .success?.records?.NS? // empty] | length > 0) |
[.hostname] + [.results[].success?.records?.NS? // empty | .[]] |
join(",")
' > domains.csv
● Querying the Dataset
One way to query the parsed data is using
DuckDB. grep will also work but will probably be a bit slower.NS1="phil.ns.cloudflare.com."
NS2="mona.ns.cloudflare.com."
duckdb -csv -noheader -c "
SELECT column0 AS domain, column1 AS ns
FROM read_csv('domains.csv', header=false)
WHERE list_sort(str_split(column1, ',')) = list_sort(['${NS1}','${NS2}'])
" > results.csv
Looking at
results.csv we have ~300 entries. A lot are false positives, but there are some new domains which definitely belong to the same operator:$ grep -i deliveroo results.csv | cut -d, -f1
deliveroo.de
deliveroo.blog
deliveroo.xn--9dbq2a
... 32 more
In a lot of cases you might not be able to correlate one website to another based on just a keyword in the domain name. In those cases you can do things like:
• Fingerprint HTTP responses
• Compare WHOIS information
• Compare technologies used
• DNS similarities
#bugbounty #recon #DNS
© t.iss.one/BugBounty_Diary
🔥11❤2
✎ RoboFinder v0.2.2 is out
● Installation
● What's new?
• Supports both single and multiple URLs
• Pipe results directly into other tools:
• JSON output for automation:
I also focused more on data quality than raw speed. Wayback lookups, especially on older targets, may take a little longer :( but you'll get much more complete results instead of missing valuable historical data.
• Repository: Github
#bugbounty #recon
© t.iss.one/BugBounty_Diary
RoboFinder is now more powerful, stable, and easier to fit into your recon workflow.
● Installation
pip install robofinder
● What's new?
• Supports both single and multiple URLs
robofinder -u https://example.com
#or
robofinder -u urls.txt
• Pipe results directly into other tools:
robofinder -u https://example.com -c | httpx
• JSON output for automation:
robofinder -u https://example.com -c -f json
I also focused more on data quality than raw speed. Wayback lookups, especially on older targets, may take a little longer :( but you'll get much more complete results instead of missing valuable historical data.
• Repository: Github
#bugbounty #recon
© t.iss.one/BugBounty_Diary
1❤🔥21👍8🔥3❤2
✎ Network Basics - Module 4
Chapter 4 has finally arrived - hope you find it helpful!
• Blog: Network Basics - Module 4
#bugbounty #network
© t.iss.one/BugBounty_Diary
Chapter 4 has finally arrived - hope you find it helpful!
--Configuring Network Addressing--
• Blog: Network Basics - Module 4
#bugbounty #network
© t.iss.one/BugBounty_Diary
❤15🔥4
✎ Hacking Google with A.I. for $500,000
After earning $500,000 in Google bug bounties, BruteCat shared the AI-powered prompts, workflows, and techniques used to analyze Google's massive attack surface, which offers valuable insights for security researchers looking to scale their reconnaissance and vulnerability discovery.
I highly recommend you read this writeup because it gives you a good methodology for hacking using AI.
• Blog: Hacking Google with A.I. for $500,000
#bugbounty #AI
© t.iss.one/BugBounty_Diary
After earning $500,000 in Google bug bounties, BruteCat shared the AI-powered prompts, workflows, and techniques used to analyze Google's massive attack surface, which offers valuable insights for security researchers looking to scale their reconnaissance and vulnerability discovery.
I highly recommend you read this writeup because it gives you a good methodology for hacking using AI.
• Blog: Hacking Google with A.I. for $500,000
#bugbounty #AI
© t.iss.one/BugBounty_Diary
❤🔥19👍5❤3
✎ FlareProx - Simple IP Rotation & URL Redirection via Cloudflare Workers
FlareProx automatically deploys HTTP proxy endpoints on Cloudflare Workers for easy redirection of all traffic to any URL you specify. It supports all HTTP methods (GET, POST, PUT, DELETE, etc.) and provides IP masking through Cloudflare's global network. (100k requests per day are free.)
● How It Works?
FlareProx deploys Cloudflare Workers that act as HTTP proxies.
1. Request Routing: When you make a request, your request is sent to a FlareProx endpoint.
2. URL Extraction: The Worker extracts the target URL from query params or a custom HTTP header.
3. Request Proxying: The Worker forwards your request to the target URL.
4. Response Relay: The target's response is relayed back through Cloudflare.
5. IP Masking: Your original IP is masked by Cloudflare's infrastructure.
● Repository: Github
#bugbounty #burp
© t.iss.one/BugBounty_Diary
FlareProx automatically deploys HTTP proxy endpoints on Cloudflare Workers for easy redirection of all traffic to any URL you specify. It supports all HTTP methods (GET, POST, PUT, DELETE, etc.) and provides IP masking through Cloudflare's global network. (100k requests per day are free.)
● How It Works?
FlareProx deploys Cloudflare Workers that act as HTTP proxies.
1. Request Routing: When you make a request, your request is sent to a FlareProx endpoint.
2. URL Extraction: The Worker extracts the target URL from query params or a custom HTTP header.
3. Request Proxying: The Worker forwards your request to the target URL.
4. Response Relay: The target's response is relayed back through Cloudflare.
5. IP Masking: Your original IP is masked by Cloudflare's infrastructure.
● Repository: Github
#bugbounty #burp
© t.iss.one/BugBounty_Diary
❤🔥13❤1
-------‐-----------------------------
✎ cURL Cheatsheet — The Swiss Knife of HTTP Requests
-------‐-----------------------------
● Basic Requests
1. GET request
2. Save response to a file
3. Follow redirects
-------‐-----------------------------
● HTTP Methods
1. POST request
2. Send JSON data
3. PUT request
4. DELETE request
-------‐-----------------------------
● Headers & Authentication
1. Add custom header
2. View response headers
3. Include headers in output
-------‐-----------------------------
● Cookies
1. Send cookies
2. Save cookies
3. Load cookies
-------‐-----------------------------
● Proxy Usage
1. HTTP Proxy
2. SOCKS5 Proxy
-------‐-----------------------------
● Useful Flags
1. "-v" → Verbose output
2. "-I" → Headers only
3. "-L" → Follow redirects
4. "-k" → Ignore SSL verification
5. "-s" → Silent mode
6. "-o" → Output to file
7. "-X" → Specify HTTP method
8. "-H" → Add header
9. "-d" → Send data
#BugBounty #curl #CheatSheet
© t.iss.one/BugBounty_Diary
✎ cURL Cheatsheet — The Swiss Knife of HTTP Requests
-------‐-----------------------------
● Basic Requests
1. GET request
curl https://example.com
2. Save response to a file
curl -o output.html https://example.com
3. Follow redirects
curl -L https://example.com
-------‐-----------------------------
● HTTP Methods
1. POST request
curl -X POST https://example.com/login
2. Send JSON data
curl -X POST https://api.example.com/users \
-H "Content-Type: application/json" \
-d '{"username":"admin","password":"1234"}'
3. PUT request
curl -X PUT https://example.com/user/1
4. DELETE request
curl -X DELETE https://example.com/user/1
-------‐-----------------------------
● Headers & Authentication
1. Add custom header
curl -H "Authorization: Bearer TOKEN" https://api.example.com
2. View response headers
curl -I https://example.com
3. Include headers in output
curl -i https://example.com
-------‐-----------------------------
● Cookies
1. Send cookies
curl -b "session=abc123" https://example.com
2. Save cookies
curl -c cookies.txt https://example.com
3. Load cookies
curl -b cookies.txt https://example.com
-------‐-----------------------------
● Proxy Usage
1. HTTP Proxy
curl -x https://127.0.0.1:8080 https://example.com
2. SOCKS5 Proxy
curl --socks5 127.0.0.1:9050 https://example.com
-------‐-----------------------------
● Useful Flags
1. "-v" → Verbose output
2. "-I" → Headers only
3. "-L" → Follow redirects
4. "-k" → Ignore SSL verification
5. "-s" → Silent mode
6. "-o" → Output to file
7. "-X" → Specify HTTP method
8. "-H" → Add header
9. "-d" → Send data
#BugBounty #curl #CheatSheet
© t.iss.one/BugBounty_Diary
🔥16👍7❤6
✎ Network Basics - Module 5
Chapter 5 - part1 is live now - hope you find it helpful!
• Blog: Network Basics - Module 5
#bugbounty #network
© t.iss.one/BugBounty_Diary
Chapter 5 - part1 is live now - hope you find it helpful!
-- Configuring Routing and Advance Switching — part 1--
• Blog: Network Basics - Module 5
#bugbounty #network
© t.iss.one/BugBounty_Diary
🔥7❤3