blmqt / bug-bounty

My personal bug bounty toolkit.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Environment

My basic testing environment includes:

  • Docker container (see Dockerfile)
  • Standard config (see my config repo)
  • BurpSuite
  • Firefox
  • Terminal

Methodology

Bug Classes

Polyglots

Notes

Recon Workflow

Below is a summary of my reconnaissance workflow. More details about the workflow and example commands can be found on the recon page.

Recon Workflow

Tips

  • Create a separate Chrome profile / Google account for Bug Bounty. Create dedicated BB accounts for YouTube etc. so you can get only relevant recommended content.
  • However you do it, set up an environment that has all the tools you use, all the time.
  • Use aliases and bash scripts to simplify commands you use all the time.

Resources

Guides

Lists

Methodology

Tooling

About

My personal bug bounty toolkit.


Languages

Language:JavaScript 69.3%Language:Dockerfile 30.7%