recon-and-methodology
Reconnaissance and methodology playbook. Use when mapping assets, discovering endpoints, fingerprinting technology, and building a structured testing plan for a new target.
By yaklang · 3,268 installs
npx skills add yaklang/hack-skills --skill recon-and-methodology
Source repository · Upstream listing
SKILL: Recon and Methodology — Expert Bug Bounty Playbook
AI LOAD INSTRUCTION : Systematic recon and bug finding methodology from top bug hunters. Covers subdomain enumeration, endpoint discovery, tech fingerprinting, and the hunter's mental model for finding bugs that others miss. Key insight: most high severity bugs are found through systematic coverage, not just clever payloads.
1. RECON HIERARCHY
2. SUBDOMAIN ENUMERATION (CRITICAL FIRST STEP)
Passive (no DNS queries to target)
Active (DNS brute force + resolution)
Virtual Host Discovery
3. SERVICE AND PORT DISCOVERY
4. WEB TECHNOLOGY FINGERPRINTING
5. ENDPOINT DISCOVERY
Directory Brute Force
Parameter Discovery
JavaScript Source Mining
API Endpoint Discovery
6. SOURCE CODE RECON
GitHub / GitLab Exposure
Exposed Environment Files
7. ZSEANO'S TESTING METHODOLOGY
Core Philosophy
1. Go deep on one program rather than spread across many — learn the application thoroughly
2. Build a profile of the company — tech stack, developers, processes
3. Look where others don't — check error pages, admin paths, old versions, mobile API
4. Follow the filter — if input is filtered somewhere, that functionality exists and may be bypassed
Testing Sequence (One Page / Feature)
Parameter Insights
8. BUG BOUNTY PROGRAM TRIAGE (WHERE TO SPEND TIME)
High Value Target Selection
High Value Feature Focus (by bug probability)
9. NUCLEI TEMPLATES (AUTOMATED SCANNING)
10. COMMON MISCONFIGURATIONS (QUICK WINS)
11. QUICK REFERENCE TOOLS
Category Tool
Subdomain enum subfinder, amass, massdns
Port scan nmap, masscan
HTTP probe httpx
Dir brute ffuf, feroxbuster, gobuster
JS mining LinkFinder, gau, waybackurls
Secret scan trufflehog, gitleaks
Parameter fuzz arjun, x8
Vuln scan nuclei
Proxy/intercept Burp Suite Pro
JWT attacks jwt tool
SQLi sqlmap
XSS dalfox, XSStrike
SSRF SSRFmap, Gopherus
12. JAVA MIDDLEWARE FINGERPRINT MATRIX
Middleware Detection Path Key Indicators
Apache Tomcat /manager/html , /manager/status Default creds: tomcat:tomcat , admin:admin
JBoss / WildFly /jmx console/ , /web console/ JMX MBean access, WAR deployment
WebLogic /console/ , /wls wsat/ T3 protocol on 7001/7002, IIOP
Spring Boot Actuator /actuator/ , /actuator/env , /actuator/heapdump JSON endpoint listing, heap dump contains secrets
Spring Boot (alt paths) /actuator/jolokia , /actuator/gateway/routes Jolokia JMX bridge, Gateway route injection
Jenkins /script , /manage Groovy console, API token in cookie
GlassFish /common/ , /theme/ Admin on 4848, default empty password
Jetty /jolokia/ JMX access
Resin /resin admin/ Admin panel
Spring Boot Actuator Exploitation Priority
13. INFORMATION LEAK DETECTION CHECKLIST
Version Control & Backup Leaks
Backup File Patterns
API Documentation & Debug
Cloud & Infrastructure