Bug Bounty — Tips / Tricks / JS
(JavaScript Files)
Prateek Tiwari Follow
Feb 21, 2018 · 4 min read
It all started in month of August when I reached out to Gerben Javado
regarding a question, yes it was a basic question but a quick chat with him
that day gave me some con dence to hunt for Bugs when he pointed
towards his blog post The race to the top of a bug bounty program, and
asked me to look for Bugs in that particular program.
The game began, I never knew that I was about to turn the tables and be at
the top of that program pretty soon. Within a span of 6 Months I learned a
hell lot of techniques / tricks and how to read JS (that was most important
for me).
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD
Sharing is Caring :) Straight to the Point now.
Recon?
Recon Recon Recon
Everyone knows about Recon and how to do it, the most important is what
more you can add in your recon techniques to nd some more bugs:
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD
Number 1 — Do you search for endpoints on Twitter, Facebook, LinkedIn,
etc.? No, don’t ask me how, here it is > If you know of an endpoint which
returns 403 since it’s an admin endpoint but have you ever imagined
knowing the correct directories and parameters sometimes can turn 403
into 200 (because of miscon gurations) and then into a SQLi? ;)
Endpoint Discovered on a Social Media Platform
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD
Result of that ^^ particular endpoint
Number 2 — CSP Headers? Anyone? It had one subdomain, I scanned for
the IP ranges and found an interesting one which gave me full admin access
[that report is already public ;)]. Whoaaa!
Number 3 — Google, please give me all the results which has
“[Link]/{directory}/{directory}" > No, I’m not using
site:[Link] inurl:, I’m just using DOUBLE QUOTES and as mentioned
“[Link]/{directory}/{directory}", this can be most of the times
PITA but if you want more bugs then let’s do it. You can just modify your
search based on the endpoints which you notice is being used on constant
basis by the company. If you’re lucky then you can nd something which
can help you get ::
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD
She was a nice lady who had that companies endpoint in her blog which when clicked was redirecting to
her own business site. She might be having some extra privileges within her pro le which allowed her to do
this.
Number 4 — Don’t look for Number 4, be creative ;)
Oh My JS FILES ;) I’m Loving you more and more!
There are great tools out there to look for the endpoints in JS les like JS
Parser (from Ben and Brett), Link nder (from Gerben Javado), those are
great tools but nothing can be as great as manual searches, yes those are
again PITA but if you want more bugs you have to ;)
Few Examples from Manual Search:
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD
I Love You JS :)
Yes, you read that ^^ right.
I Love you even more now ;)
JS will most of the time allow you to nd something for sure, recently I was
able to nd an internal host of a company upon visiting it, it was only to be
found that it was not accessible from outside their network. Oh really? No,
let’s re Nmap and see if we can nd any Open Ports. Super, later it was
discovered it had Open Jenkins Instance running on port 8080 wowwww
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD
cool it was time to execute some cmds, aaannnndddddd using Groovy
Scripts I was able to execute a cmd on the server. Woohoo!
There are couple of my reports (about JS) already published on my H1
Pro le too, [Link]/prateek_0490.
I’d like to thank HackerOne and BugCrowd and all other companies who
run a BBP and provide us with an opportunity to make this happen.
Yes, I’ve and I’m doing my bit in making internet a safer place :)
Questions? Hit me up on Twitter > [Link]
Bug Bounty Infosec Information Security Security Hackerone
1.2K claps
WRITTEN BY
Prateek Tiwari Follow
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD
Security Nerd | Someone who adores Information Security!
InfoSec Write-ups Follow
A collection of write-ups from the best hackers in the world on
topics ranging from bug bounties and CTFs to vulnhub
machines, hardware challenges and real life encounters. In a
nutshell, we are the largest InfoSec publication on Medium.
Maintained by Hackrew
See responses (4)
More From Medium
Array and Object De-structuring in Javascript Dockerize Angular application
Samuel Guo in JavaScript In Plain English Yoshevski
React Native: User Authentication Flow Explained NiM Much More than UX Sugar
Ross Bulat 667
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD
Practical data fetching with React Suspense that you can The Art of JavaScript Event Delegation
use today
Alexandra Radevich in The Startup
Andrei Duca
How to Maximize Reusability for Your React Components How to go from idea to URL quickly with [Link] and
Heroku
jsmanifest in Better Programming
Tom Schweers in [Link]
Discover Medium Make Medium yours Become a member
Welcome to a place where words matter. Follow all the topics you care about, and Get unlimited access to the best stories
On Medium, smart voices and original we’ll deliver the best stories for you to on Medium — and support writers while
ideas take center stage - with no ads in your homepage and inbox. Explore you’re at it. Just $5/month. Upgrade
sight. Watch
About Help Legal
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD