recon-and-methodology

Reconnaissance and methodology playbook. Use when mapping assets, discovering endpoints, fingerprinting technology, and building a structured testing plan for a new target.

By yaklang · 3,268 installs

npx skills add yaklang/hack-skills --skill recon-and-methodology

Source repository · Upstream listing

SKILL: Recon and Methodology — Expert Bug Bounty Playbook AI LOAD INSTRUCTION : Systematic recon and bug finding methodology from top bug hunters. Covers subdomain enumeration, endpoint discovery, tech fingerprinting, and the hunter's mental model for finding bugs that others miss. Key insight: most high severity bugs are found through systematic coverage, not just clever payloads. 1. RECON HIERARCHY 2. SUBDOMAIN ENUMERATION (CRITICAL FIRST STEP) Passive (no DNS queries to target) Active (DNS brute force + resolution) Virtual Host Discovery 3. SERVICE AND PORT DISCOVERY 4. WEB TECHNOLOGY FINGERPRINTING 5. ENDPOINT DISCOVERY Directory Brute Force Parameter Discovery JavaScript Source Mining API Endpoint Discovery 6. SOURCE CODE RECON GitHub / GitLab Exposure Exposed Environment Files 7. ZSEANO'S TESTING METHODOLOGY Core Philosophy 1. Go deep on one program rather than spread across many — learn the application thoroughly 2. Build a profile of the company — tech stack, developers, processes 3. Look where others don't — check error pages, admin paths, old versions, mobile API 4. Follow the filter — if input is filtered somewhere, that functionality exists and may be bypassed Testing Sequence (One Page / Feature) Parameter Insights 8. BUG BOUNTY PROGRAM TRIAGE (WHERE TO SPEND TIME) High Value Target Selection High Value Feature Focus (by bug probability) 9. NUCLEI TEMPLATES (AUTOMATED SCANNING) 10. COMMON MISCONFIGURATIONS (QUICK WINS) 11. QUICK REFERENCE TOOLS Category Tool Subdomain enum subfinder, amass, massdns Port scan nmap, masscan HTTP probe httpx Dir brute ffuf, feroxbuster, gobuster JS mining LinkFinder, gau, waybackurls Secret scan trufflehog, gitleaks Parameter fuzz arjun, x8 Vuln scan nuclei Proxy/intercept Burp Suite Pro JWT attacks jwt tool SQLi sqlmap XSS dalfox, XSStrike SSRF SSRFmap, Gopherus 12. JAVA MIDDLEWARE FINGERPRINT MATRIX Middleware Detection Path Key Indicators Apache Tomcat /manager/html , /manager/status Default creds: tomcat:tomcat , admin:admin JBoss / WildFly /jmx console/ , /web console/ JMX MBean access, WAR deployment WebLogic /console/ , /wls wsat/ T3 protocol on 7001/7002, IIOP Spring Boot Actuator /actuator/ , /actuator/env , /actuator/heapdump JSON endpoint listing, heap dump contains secrets Spring Boot (alt paths) /actuator/jolokia , /actuator/gateway/routes Jolokia JMX bridge, Gateway route injection Jenkins /script , /manage Groovy console, API token in cookie GlassFish /common/ , /theme/ Admin on 4848, default empty password Jetty /jolokia/ JMX access Resin /resin admin/ Admin panel Spring Boot Actuator Exploitation Priority 13. INFORMATION LEAK DETECTION CHECKLIST Version Control & Backup Leaks Backup File Patterns API Documentation & Debug Cloud & Infrastructure