Chuyển đến nội dung chính

Lesson 24: Bug Bounty Methodologies

Bug bounty platforms, reconnaissance workflow, high-impact vulnerability hunting, responsible disclosure, bounty optimization.

🔒 DevSecOps — Lesson 24 Lesson 24: Bug Bounty Methodologies

Performance Testing & Pentest: Enterprise Standard Process 2026

Part 5: Red/Blue/Purple Team & Compliance

xdev.asia

1. Bug Bounty — Overview

Bug Bounty Ecosystem 2026:

Platforms:
  ├── HackerOne    : Largest, enterprise focus
  ├── Bugcrowd     : Crowdsourced security
  ├── Intigriti    : European focus
  ├── YesWeHack    : EU-based, growing
  └── Synack       : Vetted researcher network

Program Types:
  ├── Public: Anyone can participate
  ├── Private: Invitation only
  └── VDP (Vulnerability Disclosure Program): No bounty

Bounty Ranges (2026):
  ├── Critical: $5,000 - $100,000+
  ├── High:     $1,000 - $20,000
  ├── Medium:   $500 - $5,000
  ├── Low:      $100 - $1,000
  └── Info:     $0 - $100

Top Earning Categories:
  1. SSRF + Cloud metadata → Account takeover
  2. Authentication bypass → Admin access
  3. IDOR → Mass data exposure
  4. RCE (Remote Code Execution)
  5. Stored XSS → Session hijacking

2. Bug Bounty Recon Workflow

# --- Phase 1: Scope Analysis ---

# Read program scope carefully
# In-scope: *.example.com, api.example.com
# Out-of-scope: blog.example.com, support.example.com

# --- Phase 2: Asset Discovery ---

# Subdomain enumeration
subfinder -d example.com -all -recursive -o subs.txt
amass enum -passive -d example.com >> subs.txt
sort -u subs.txt -o subs.txt

# Find alive hosts with tech detection
cat subs.txt | httpx -silent -status-code -title \
  -tech-detect -follow-redirects -o alive.txt

# Screenshot all alive hosts
cat alive.txt | awk '{print $1}' | gowitness file -f - \
  --screenshot-path ./screenshots

# --- Phase 3: Content Discovery ---

# Directory/file bruteforce
ffuf -u "https://FUZZ.example.com" -w subs.txt \
  -H "Host: FUZZ.example.com" -fs 0

# Path discovery on each alive host
cat alive.txt | awk '{print $1}' | while read url; do
  ffuf -u "$url/FUZZ" \
    -w /usr/share/seclists/Discovery/Web-Content/raft-medium-words.txt \
    -mc 200,301,302,403 -fc 404 \
    -o "ffuf_$(echo $url | sed 's|https://||;s|/|_|g').json"
done

# --- Phase 4: JavaScript Analysis ---

# Extract JavaScript files
cat alive.txt | awk '{print $1}' | getallurls | grep "\.js$" | sort -u > js_files.txt

# Find endpoints in JS
cat js_files.txt | while read js; do
  curl -s "$js" | grep -oP '["'"'"']/api/[^"'"'"'\s]+' 
done | sort -u > api_endpoints.txt

# Find secrets in JS
cat js_files.txt | while read js; do
  curl -s "$js" | grep -iE "(api[_-]?key|secret|token|password|firebase|aws)" 
done > js_secrets.txt

3. High-Impact Vulnerability Hunting

# --- IDOR Hunting ---

# 1. Create two test accounts
# 2. Capture all API requests from Account A
# 3. Replay with Account B's token, changing IDs

# Automation with Burp Suite Autorize extension:
# - Set Account B's cookie in Autorize
# - Browse as Account A
# - Autorize replays each request with Account B's session
# - Color-coded: Red = IDOR, Green = properly authorized

# --- SSRF Hunting ---

# Look for URL input parameters
# ?url=, ?redirect=, ?next=, ?dest=, ?img=, ?src=, ?ref=

# Test with webhook.site or Burp Collaborator
curl "https://api.example.com/fetch?url=https://YOURBURPCOLLABORATOR.net"

# Test cloud metadata
curl "https://api.example.com/fetch?url=http://169.254.169.254/latest/meta-data/"

# DNS rebinding
# Use services like rebind.it to bypass IP whitelist checks

# --- Authentication Bypass ---

# Password reset flow:
# 1. Request reset for victim
# 2. Check if token is predictable
# 3. Check if token is reusable
# 4. Check Host header injection
curl -X POST https://example.com/api/reset-password \
  -H "Host: evil.com" \
  -d '{"email":"[email protected]"}'
# If reset link uses Host header → account takeover

# OAuth vulnerabilities:
# 1. Missing state parameter → CSRF
# 2. Open redirect in redirect_uri
# 3. Token leaking via Referer header

4. Bug Bounty Report Writing

# Bug Bounty Report Template

## Title
IDOR in /api/v1/users/{id}/documents allows accessing
any user's private documents

## Severity
Critical (CVSS 9.1)

## Description
The /api/v1/users/{id}/documents endpoint does not verify
that the authenticated user owns the requested documents.
Any authenticated user can access documents belonging to
any other user by changing the user ID in the URL.

## Steps to Reproduce
1. Login as User A ([email protected] / TestPass123!)
2. Navigate to "My Documents" page
3. Observe API request:
   GET /api/v1/users/123/documents
4. Change user ID 123 to 456:
   GET /api/v1/users/456/documents
5. Response contains User B's private documents

## Impact
- Any authenticated user can access ALL users' documents
- Estimated affected users: ~50,000
- Documents include: ID cards, contracts, financial records
- Potential regulatory violation (GDPR, PDPA Vietnam)

## Proof of Concept

Request:
___CODEBLOCK_0___

Response (200 OK):
___CODEBLOCK_1___

## Remediation
Add server-side authorization check:
___CODEBLOCK_2___

## References
- OWASP API1:2023 — Broken Object Level Authorization
- CWE-639 — Authorization Bypass Through User-Controlled Key

5. Bug Bounty Tips & Best Practices

Bug Bounty Success Tips:

Beginner:
  ├── Start with VDP programs (no pressure)
  ├── Focus on one target at a time
  ├── Read all previous disclosures
  ├── Learn from public reports (HackerOne Hacktivity)
  └── Master ONE vulnerability class first (e.g., IDOR)

Intermediate:
  ├── Automate recon (custom pipelines)
  ├── Hunt during scope changes (new assets)
  ├── Focus on less-tested areas (mobile, APIs)
  ├── Chain low-severity bugs → high impact
  └── Build custom tools/wordlists

Advanced:
  ├── Target private programs (higher bounties)
  ├── Develop novel attack chains
  ├── Research 0-day in target's tech stack
  ├── Contribute to open-source security tools
  └── Share knowledge (blog, talks)

Common Mistakes:
  ❌ Submitting duplicates (search first)
  ❌ Poor report quality (no PoC, unclear steps)
  ❌ Testing out of scope
  ❌ Automated scanning without manual validation
  ❌ Mass reporting low-severity issues
  ❌ Not reading program policy carefully

Responsible Disclosure:
  ✅ Report to program, not publicly
  ✅ Follow program's disclosure timeline
  ✅ Don't access more data than needed for PoC
  ✅ Don't modify or delete data
  ✅ Don't attack other users

6. Summary

  • Platforms: HackerOne, Bugcrowd, Intigriti — choose based on program
  • Recon: Subdomain enum → alive check → content discovery → JS analysis
  • High-impact bugs: IDOR, SSRF, auth bypass, RCE
  • Report quality: Clear title, steps to reproduce, PoC, impact, remediation
  • Growth: Focus on one vuln class, automate recon, learn from public reports

The next article will learn Compliance Frameworks — PCI DSS, SOC 2, ISO 27001.