Pentest & Bug Bounty Resources and Techniques
  • Pentest & Bug Bounty Resources and Techniques
    • Introduction
    • Tests Checklist
    • OSINT
    • Communications Security
      • SSL/TLS
    • Networking
      • Subdomains Discovery
        • DNS & OSINT
        • DNS Brute force
          • Second DNS Brute-Force Round
      • Subdomain Takeover
      • Network Host Scan/Discovery
        • External/Internal
        • Internal only
      • Network Vulnerability Scanning
      • Network Hacking
      • Parsing
      • Reporting
    • Brute Force
      • Wordlists
      • Databases
      • SSH
    • Web
      • Endpoint Discovery
      • Infrastructure & Configuration
        • Headers
        • WAF Detection/ Evasion
      • Injection
        • GraphQL
        • Cross-Site Scripting (XSS)
        • SQL Injection
        • Payloads
      • SSRF & XXE
        • Labs & Resources
        • Tools
        • SVG SSRF Cheatsheet
        • XXE - XEE - XML External Entity
      • JWT Vulnerabilities (Json Web Tokens)
      • HTTP/S DoS
    • Mobile
      • Both
        • SAST
          • MobSF
        • DAST
          • Installing Frida and Objection
      • Android
        • Create a Lab
          • Rooting Android Emulator
          • Rooting Android Emulator Cheat Sheet
        • APK Certificates
        • SAST
          • APKs
            • Get Information from APK
            • GDA (GJoy Dex Analysizer)
            • Scanning APK for URIs, endpoints & secrets
            • Google Maps API Scanner
        • DAST
          • Rooting the Android Studio AVDs
          • non-Rooted devices
            • Bypass SSL Pinning - non-rooted devices
              • Method 1: apk-mitm
              • Instrumentation with Frida and Objection
                • Bypass SSL Pinning - Method 2: With Objection Explore
                • Bypass SSL Pinning - Method 3: With root_bypass.js
          • Rooted Devices
            • Run frida-server in the emulator or device
            • Inject Frida
            • Bypass SSL Pinning - rooted devices
              • Install Burp CA as a system-level CA on the device
      • iOS
        • SAST
          • Building a reverse iOS engineering environment for free
          • Test Vulnerabilities
  • Lets Practice
    • Virtual Machines
    • Vulnerable App
    • Guided Labs
    • CTFs
  • Group 1
    • AI
Powered by GitBook
On this page
  • Recon
  • Endpoint Discovery
  • DNS Discovery
  • Port scan
  • Manual checking
  • Information Gathering
  • Configuration Management
  • Secure Transmission
  • Authentication
  • Session Management
  • Authorization
  • Data Validation
  • Denial of Service
  • Business Logic
  • Cryptography
  • Risky Functionality - File Uploads
  • Risky Functionality - Card Payment
  • HTML 5
  1. Pentest & Bug Bounty Resources and Techniques

Tests Checklist

PreviousIntroductionNextOSINT

Last updated 4 months ago

Recon

Endpoint Discovery

DNS Discovery

This recon process is from

Port scan

Network Discovery - External

Network Discovery - Internal

Network Hacking - Internal

Manual checking

Information Gathering

Configuration Management

Secure Transmission

Authentication

Session Management

Authorization

Data Validation

Denial of Service

Business Logic

Cryptography

Risky Functionality - File Uploads

Risky Functionality - Card Payment

HTML 5

See more in

dirsearch
dirb
Linkfinder
wfuzz
XSStrike Crawler
Wayback machine
0xpatrick subdomain enumeration workflow
Amass
Sublist3r
altdns
massdns
https://bugbountyforum.com/tools/recon/
Nmap
Sn1per
Masscan
Zmap
ARP Scan
NetDiscover
NetBIOS Scanner
Responder
XSSStrike