--- name: bug-bounty description: Complete bug bounty workflow category: security risk: offensive source: https://github.com/elementalsouls/Claude-BugHunter source_repo: elementalsouls/Claude-BugHunter source_type: community date_added: '2026-09-20' license: MIT license_source: https://github.com/elementalsouls/Claude-BugHunter/blob/main/LICENSE compatibility: Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled. sources: community, public_research --- > **⚠️ AUTHORIZED USE ONLY** > This skill is for educational purposes or authorized security assessments only. > You must have explicit, written permission from the system owner before using this tool. > Misuse of this tool is illegal and strictly prohibited. > **Mandatory confirmation gate** > Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target: > 1. Ask the user to state the exact target URL, IP, account, or resource. > 2. Ask the user to confirm written authorization and the permitted scope. > 3. Show the exact command(s) and explain their expected effect. > 4. Wait for explicit confirmation in the current conversation. > > Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab. # Bug Bounty Master Workflow Full pipeline: Recon -> Learn -> Hunt -> Validate -> Report. One skill for everything. ## THE ONLY QUESTION THAT MATTERS > **"Can an attacker do this RIGHT NOW against a real user who has taken NO unusual actions -- and does it cause real harm (stolen money, leaked PII, account takeover, code execution)?"** > > If the answer is NO -- **STOP. Do not write. Do not explore further. Move on.** ### Theoretical Bug = Wasted Time. Kill These Immediately: | Pattern | Kill Reason | |---|---| | "Could theoretically allow..." | Not exploitable = not a bug | | "An attacker with X, Y, Z conditions could..." | Too many preconditions | | "Wrong implementation but no practical impact" | Wrong but harmless = not a bug | | Dead code with a bug in it | Not reachable = not a bug | | Source maps without secrets | No impact | | SSRF with DNS-only callback | Need data exfil or internal access | | Open redirect alone | Need ATO or OAuth chain | | "Could be used in a chain if..." | Build the chain first, THEN report | **You must demonstrate actual harm. "Could" is not a bug. Prove it works or drop it.** --- ## CRITICAL RULES 1. **READ FULL SCOPE FIRST** -- verify every asset/domain is owned by the target org 2. **NO THEORETICAL BUGS** -- "Can an attacker steal funds, leak PII, takeover account, or execute code RIGHT NOW?" If no, STOP. 3. **KILL WEAK FINDINGS FAST** -- run the 7-Question Gate BEFORE writing any report 4. **Validate before writing** -- check CHANGELOG, design docs, deployment scripts FIRST 5. **One bug class at a time** -- go deep, don't spray 6. **Verify data isn't already public** -- check web UI in incognito before reporting API "leaks" 7. **5-MINUTE RULE** -- if a target shows nothing after 5 min probing (all 401/403/404), MOVE ON 8. **IMPACT-FIRST HUNTING** -- ask "what's the worst thing if auth was broken?" If nothing valuable, skip target 9. **CREDENTIAL LEAKS need exploitation proof** -- finding keys isn't enough, must PROVE what they access 10. **STOP SHALLOW RECON SPIRALS** -- don't probe 403s, don't grep for analytics keys, don't check staging domains that lead nowhere 11. **BUSINESS IMPACT over vuln class** -- severity depends on CONTEXT, not just vuln type 12. **UNDERSTAND THE TARGET DEEPLY** -- before hunting, learn the app like a real user 13. **DON'T OVER-RELY ON AUTOMATION** -- automated scans hit WAFs, trigger rate limits, find the same bugs everyone else finds 14. **HUNT LESS-SATURATED VULN CLASSES** -- XSS/SSRF/XXE have the most competition. Expand into: cache poisoning, Android/mobile vulns, business logic, race conditions, OAuth/OIDC chains, CI/CD pipeline attacks 15. **ONE-HOUR RULE** -- stuck on one target for an hour with no progress? SWITCH CONTEXT 16. **TWO-EYE APPROACH** -- combine systematic testing (checklist) with anomaly detection (watch for unexpected behavior) 17. **T-SHAPED KNOWLEDGE** -- go DEEP in one area and BROAD across everything else > **For the full hunting methodology** — 5-phase non-linear workflow, developer psychology framework, session discipline, tool routing by phase, and Wide/Deep route selection — see **`skills/bb-methodology/SKILL.md`**. --- ## A->B BUG SIGNAL METHOD (Cluster Hunting) **When you find bug A, systematically hunt for B and C nearby.** This is one of the most powerful methodologies in bug bounty. Single bugs pay. Chains pay 3-10x more. ### Known A->B->C Chains | Bug A (Signal) | Hunt for Bug B | Escalate to C | |----------------|---------------|---------------| | IDOR (read) | PUT/DELETE on same endpoint | Full account data manipulation | | SSRF (any) | Cloud metadata 169.254.169.254 | IAM credential exfil -> RCE | | XSS (stored) | Check if HttpOnly is set on session cookie | Session hijack -> ATO | | Open redirect | OAuth redirect_uri accepts your domain | Auth code theft -> ATO | | S3 bucket listing | Enumerate JS bundles | Grep for OAuth client_secret -> OAuth chain | | Rate limit bypass | OTP brute force | Account takeover | | GraphQL introspection | Missing field-level auth | Mass PII exfil | | Debug endpoint | Leaked environment variables | Cloud credential -> infrastructure access | | CORS reflects origin | Test with credentials: include | Credentialed data theft | | Host header injection | Password reset poisoning | ATO via reset link | ### Cluster Hunt Protocol (6 Steps) ``` 1. CONFIRM A Verify bug A is real with an HTTP request 2. MAP SIBLINGS Find all endpoints in the same controller/module/API group 3. TEST SIBLINGS Apply the same bug pattern to every sibling 4. CHAIN If sibling has different bug class, try combining A + B 5. QUANTIFY "Affects N users" / "exposes $X value" / "N records" 6. REPORT One report per chain (not per bug). Chains pay more. ``` ### Real Examples **Coinbase S3->Bundle->Secret->OAuth chain:** ``` A: S3 bucket publicly listable (Low alone) B: JS bundles contain OAuth client credentials C: OAuth flow missing PKCE enforcement Result: Full auth code interception chain ``` **Vienna Chatbot chain:** ``` A: Debug parameter active in production (Info alone) B: Chatbot renders HTML in response (dangerouslySetInnerHTML) C: Stored XSS via bot response visible to other users Result: P2 finding with real impact ``` --- # TOP 1% HACKER MINDSET ## How Elite Hackers Think Differently **Average hunter**: Runs tools, checks checklist, gives up after 30 min. **Top 1%**: Builds a mental model of the app's internals. Asks "why does this work the way it does?" Not "what does this endpoint do?" but "what business decision led a developer to build it this way, and what shortcut might they have taken?" ## Pre-Hunt Mental Framework ### Step 1: Crown Jewel Thinking Before touching anything, ask: "If I were the attacker and I could do ONE thing to this app, what causes the most damage?" - Financial app -> drain funds, transfer to attacker account - Healthcare -> PII leak, HIPAA violation - SaaS -> tenant data crossing, admin takeover - Auth provider -> full SSO chain compromise ### Step 2: Developer Empathy Think like the developer who built the feature: - What was the simplest implementation? - What shortcut would a tired dev take at 2am? - Where is auth checked -- controller? middleware? DB layer? - What happens when you call endpoint B without going through endpoint A first? ### Step 3: Trust Boundary Mapping ``` Client -> CDN -> Load Balancer -> App Server -> Database ^ ^ ^ Where does app STOP trusting input? Where does it ASSUME input is already validated? ``` ### Step 4: Feature Interaction Thinking - Does this new feature reuse old auth, or does it have its own? - Does the mobile API share auth logic with the web app? - Was this feature built by the same team or a third-party? ## The Top 1% Mental Checklist - [ ] I know the app's core business model - [ ] I've used the app as a real user for 15+ minutes - [ ] I know the tech stack (language, framework, auth system, caching) - [ ] I've read at least 3 disclosed reports for this program - [ ] I have 2 test accounts ready (attacker + victim) - [ ] I've defined my primary target: ONE crown jewel I'm hunting for today ## Mindset Rules from Top Hunters **"Hunt the feature, not the endpoint"** -- Find all endpoints that serve a feature, then test the INTERACTION between them. **"Authorization inconsistency is your friend"** -- If the app checks auth in 9 places but not the 10th, that's your bug. **"New == unreviewed"** -- Features launched in the last 30 days have lowest security maturity. **"Think second-order"** -- Second-order SSRF: URL saved in DB, fetched by cron job. Second-order XSS: stored clean, rendered unsafely in admin panel. **"Follow the money"** -- Any feature touching payments, billing, credits, refunds is where developers make the most security shortcuts. **"The API the mobile app uses"** -- Mobile apps often call older/different API versions. Same company, different attack surface, lower maturity. **"Diffs find bugs"** -- Compare old API docs vs new. Compare mobile API vs web API. Compare what a free user can request vs what a paid user gets in response. --- # TOOLS ## Go Binaries | Tool | Use | |------|-----| | subfinder | Passive subdomain enum | | httpx | Probe live hosts | | dnsx | DNS resolution | | nuclei | Template scanner | | katana | Crawl | | waybackurls | Archive URLs | | gau | Known URLs | | dalfox | XSS scanner | | ffuf | Fuzzer | | anew | Dedup append | | qsreplace | Replace param values | | assetfinder | Subdomain enum | | gf | Grep patterns (xss, sqli, ssrf, redirect) | | interactsh-client | OOB callbacks | ## Tools to Install When Needed | Tool | Use | Install | |------|-----|---------| | arjun | Hidden parameter discovery | `pip3 install arjun` | | paramspider | URL parameter mining | `pip3 install paramspider` | | kiterunner | API endpoint brute | `go install github.com/assetnote/kiterunner/cmd/kr@latest` | | cloudenum | Cloud asset enumeration | `pip3 install cloud_enum` | | trufflehog | Secret scanning | `brew install trufflehog` | | gitleaks | Secret scanning | `brew install gitleaks` | | XSStrike | Advanced XSS scanner | `pip3 install xsstrike` | | SecretFinder | JS secret extraction | `pip3 install secretfinder` | | sqlmap | SQL injection | `pip3 install sqlmap` | | subzy | Subdomain takeover | `go install github.com/LukaSikic/subzy@latest` | ## Static Analysis (Semgrep Quick Audit) ```bash # Install: pip3 install semgrep # Broad security audit semgrep --config=p/security-audit ./ semgrep --config=p/owasp-top-ten ./ # Language-specific rulesets semgrep --config=p/javascript ./src/ semgrep --config=p/python ./ semgrep --config=p/golang ./ semgrep --config=p/php ./ semgrep --config=p/nodejs ./ # Targeted rules semgrep --config=p/sql-injection ./ semgrep --config=p/jwt ./ # Custom pattern (example: find SQL concat in Python) semgrep --pattern 'cursor.execute("..." + $X)' --lang python . # Output to file for analysis semgrep --config=p/security-audit ./ --json -o semgrep-results.json 2>/dev/null cat semgrep-results.json | jq '.results[] | select(.extra.severity == "ERROR") | {path:.path, check:.check_id, msg:.extra.message}' ``` ## FFUF Advanced Techniques ```bash # THE ONE RULE: Always use -ac (auto-calibrate filters noise automatically) ffuf -w wordlist.txt -u https://target.com/FUZZ -ac # Authenticated raw request file — IDOR testing (save Burp request to req.txt, replace ID with FUZZ) seq 1 10000 | ffuf --request req.txt -w - -ac # Authenticated API endpoint brute ffuf -u https://TARGET/api/FUZZ -w wordlist.txt -H "Cookie: session=TOKEN" -ac # Parameter discovery ffuf -w ~/wordlists/burp-parameter-names.txt -u "https://target.com/api/endpoint?FUZZ=test" -ac -mc 200 # Hidden POST parameters ffuf -w ~/wordlists/burp-parameter-names.txt -X POST -d "FUZZ=test" -u "https://target.com/api/endpoint" -ac # Subdomain scan ffuf -w subs.txt -u https://FUZZ.target.com -ac # Filter strategies: # -fc 404,403 Filter status codes # -fs 1234 Filter by response size # -fw 50 Filter by word count # -fr "not found" Filter regex in response body # -rate 5 -t 10 Rate limit + fewer threads for stealth # -e .php,.bak,.old Add extensions # -o results.json Save output ``` ## AI-Assisted Tools - **strix** (usestrix.com) -- open-source AI scanner for automated initial sweep --- # PHASE 1: RECON ## Standard Recon Pipeline ```bash # Step 1: Subdomains subfinder -d TARGET -silent | anew /tmp/subs.txt assetfinder --subs-only TARGET | anew /tmp/subs.txt # Step 2: Resolve + live hosts cat /tmp/subs.txt | dnsx -silent | httpx -silent -status-code -title -tech-detect -o /tmp/live.txt # Step 3: URL collection cat /tmp/live.txt | awk '{print $1}' | katana -d 3 -silent | anew /tmp/urls.txt echo TARGET | waybackurls | anew /tmp/urls.txt gau TARGET | anew /tmp/urls.txt # Step 4: Nuclei scan nuclei -l /tmp/live.txt -severity critical,high,medium -silent -o /tmp/nuclei.txt # Step 5: JS secrets cat /tmp/urls.txt | grep "\.js$" | sort -u > /tmp/jsfiles.txt # Run SecretFinder on each JS file # Step 6: GitHub dorking (if target has public repos) # GitDorker -org TARGET_ORG -d dorks/alldorksv3 ``` ## Cloud Asset Enumeration ```bash # Manual S3 brute for suffix in dev staging test backup api data assets static cdn; do code=$(curl -s -o /dev/null -w "%{http_code}" "https://${TARGET}-${suffix}.s3.amazonaws.com/") [ "$code" != "404" ] && echo "$code ${TARGET}-${suffix}.s3.amazonaws.com" done ``` ## API Endpoint Discovery ```bash # ffuf API endpoint brute ffuf -u https://TARGET/api/FUZZ -w /usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt -mc 200,201,301,302,403 -ac ``` ## HackerOne Scope Retrieval ```bash curl -s "https://hackerone.com/graphql" \ -H "Content-Type: application/json" \ -d '{"query":"query { team(handle: \"PROGRAM_HANDLE\") { name url policy_scopes(archived: false) { edges { node { asset_type asset_identifier eligible_for_bounty instruction } } } } }"}' \ | jq '.data.team.policy_scopes.edges[].node' ``` ## Quick Wins Checklist - [ ] Subdomain takeover (`subjack`, `subzy`) - [ ] Exposed `.git` (`/.git/config`) - [ ] Exposed env files (`/.env`, `/.env.local`) - [ ] Default credentials on admin panels - [ ] JS secrets (SecretFinder, jsluice) - [ ] Open redirects (`?redirect=`, `?next=`, `?url=`) - [ ] CORS misconfig (test `Origin: https://evil.com` + credentials) - [ ] S3/cloud buckets - [ ] GraphQL introspection enabled - [ ] Spring actuators (`/actuator/env`, `/actuator/heapdump`) - [ ] Firebase open read (`https://TARGET.firebaseio.com/.json`) ## Technology Fingerprinting | Signal | Technology | |---|---| | Cookie: `XSRF-TOKEN` + `*_session` | Laravel | | Cookie: `PHPSESSID` | PHP | | Header: `X-Powered-By: Express` | Node.js/Express | | Response: `wp-json`/`wp-content` | WordPress | | Response: `{"errors":[{"message":` | GraphQL | | Header: `X-Powered-By: Next.js` | Next.js | ## Framework Quick Wins **Laravel**: `/horizon`, `/telescope`, `/.env`, `/storage/logs/laravel.log` **WordPress**: `/wp-json/wp/v2/users`, `/xmlrpc.php`, `/?author=1` **Node.js**: `/.env`, `/graphql` (introspection), `/_debug` **AWS Cognito**: `/oauth2/userInfo` (leaks Pool ID), CORS reflects arbitrary origins ## Contents - [Source Code Recon](references/details.md) - [Read Disclosed Reports](references/details.md) - ["What Changed" Method](references/details.md) - [Threat Model Template](references/details.md) - [6 Key Patterns from Top Reports](references/details.md) - [Note-Taking System (Never Hunt Without This)](references/details.md) - [Interesting Leads (not confirmed bugs yet)](references/details.md) - [Dead Ends (don't revisit)](references/details.md) - [Anomalies](references/details.md) - [Rabbit Holes (time-boxed, max 15 min each)](references/details.md) - [Confirmed Bugs](references/details.md) - [Subdomain Type -> Hunt Strategy](references/details.md) - [CVE-Seeded Audit Approach](references/details.md) - [Rust/Blockchain Source Code (Hard-Won Lessons)](references/details.md) - [IDOR -- Insecure Direct Object Reference](references/details.md) - [SSRF -- Server-Side Request Forgery](references/details.md) - [OAuth / OIDC](references/details.md) - [File Upload](references/details.md) - [Race Conditions](references/details.md) - [Business Logic](references/details.md) - [XSS -- Cross-Site Scripting](references/details.md) - [SQL Injection](references/details.md) - [GraphQL](references/details.md) - [LLM / AI Features](references/details.md) - [Cache Poisoning / Web Cache Deception](references/details.md) - [HTTP Request Smuggling](references/details.md) - [Android / Mobile Hunting](references/details.md) - [CI/CD Pipeline — GitHub Actions Security](references/details.md) - [SSTI -- Server-Side Template Injection](references/details.md) - [Subdomain Takeover](references/details.md) - [ATO -- Account Takeover (Complete Taxonomy)](references/details.md) - [Cloud / Infra Misconfigs](references/details.md) - [The 7-Question Gate (Run BEFORE Writing ANY Report)](references/details.md) - [4 Pre-Submission Gates](references/details.md) - [CVSS 3.1 Quick Guide](references/details.md) - [Conditionally Valid With Chain](references/details.md) - [HackerOne Report Template](references/details.md) - [Summary](references/details.md) - [Steps To Reproduce](references/details.md) - [Supporting Material](references/details.md) - [Impact](references/details.md) - [Severity Assessment](references/details.md) - [Bugcrowd Report Template](references/details.md) - [Human Tone Rules (Avoid AI-Sounding Writing)](references/details.md) - [Report Title Formula](references/details.md) - [Impact Statement Formula (First Paragraph)](references/details.md) - [The 60-Second Pre-Submit Checklist](references/details.md) - [Severity Escalation Language](references/details.md) - [Bug Bounty Platforms](references/details.md) - [Learning](references/details.md) - [Wordlists](references/details.md) - [Payload Databases](references/details.md) - [Related Skills & Chains](references/details.md) - [Operator Notes (Claude-BugHunter)](references/details.md) ## When to Use - You have explicit, written authorization to assess the target in scope, and the task matches this skill's vulnerability class or technique within a bug-bounty or penetration-test engagement. - You need the recon, exploitation, or validation workflow described below — executed strictly inside the approved scope. ## Limitations - Authorized scope only: the confirmation gate above is mandatory before any probing, exploitation, or credential-access command. - Docs-only import: upstream helper scripts, commands, engine, and research assets are not bundled; reinstall tooling from the source repo when needed. - Validate every finding (see `triage-validation`) before reporting; report via `report-writing`. Prefer a sandbox, disposable VM, or controlled lab. ### Example ```bash # Read-only first step; confirm scope before anything active. cat scope.txt # target list from the authorized engagement brief ``` > Adapted from [elementalsouls/Claude-BugHunter](https://github.com/elementalsouls/Claude-BugHunter) (MIT); frontmatter, When to Use/Limitations, and safety boundaries added for upstream compliance. Docs-only import: executable helpers, commands, engine, and research assets not bundled.