
Explore recon fundamentals and bug bounty hunting with hands-on tools like Shodan, dirsearch, Gobuster, Amass, crt.sh, and Burp Suite, guided by ethical hacking best practices and platform insights.
Explore ongoing updates to boost recon techniques for bug bounty and pentesting, including new methodologies, automation, tools, CVEs, and ongoing question-and-answer support.
watch this disclaimer to learn ethical guidelines for bug bounty training, including educational use of vulnerabilities, responsible disclosure, and practicing on other live sites rather than those shown.
Develop disciplined note keeping for recon during bug bounties and pentesting, organizing data by target and vulnerability, tracking progress, and leveraging notes for future CVEs.
Learn to organize and document a pentest with notes tools like Cherry Tree, Evernote, and Green Shot, using notes, checklists, tables, reminders, and videos to track vulnerabilities.
Learn to use the Swiftness X note keeping tool to organize targets, folders, checklists, and subdomain enumeration for thorough pentest and bug bounty work.
Capture screenshots across Windows, macOS, and Linux using built-in keys and Greenshot. Annotate the screenshots to highlight sensitive areas, then save to disk for bug bounty reports.
Choose the right bug bounty program with broad scope. Develop your own methodology, perform recon rather than DDoS with scanners, automate tasks with Bash, and report findings promptly.
Follow the master, walk with the master, see through the master, and become the master to excel in bug bounty hunting and pentesting.
Explore web fundamentals, including websites, home pages, and the roles of HTML, CSS, and JavaScript; compare static and dynamic sites and how browsers render pages using the DOM.
Discover how DNS maps a domain name to an IP address, enabling browsers to reach servers through browser and OS caches, resolvers, root, and TLD servers.
Explore how a web server processes requests and serves data, with Apache, Nginx, and IIS, and learn to install, start, and verify ports on Linux.
Clarify the differences between URL, URI, and URN, showing that URI is the superset and URL is a protocol-based locator for a network resource.
Break down the URL components—scheme, authority, path, and query parameters—and learn how unsanitized parameters can expose vulnerabilities such as XSS and SQL injection.
Learn how Shodan, an internet-connected device search engine, indexes devices from refrigerators to servers, and install Shodan using easy install or pip, with Python prerequisites.
Learn how to set up the shodan cli with an api key, use the help command, and perform searches with free credits for ethical hacking and bug bounty workflows.
Explore how to use the Shodan CLI to check account info, manage credits, verify the version, and count results for OpenSSH and Big-IP to identify exposed servers.
Discover how Shodan's download feature exports search results into a file, including IP addresses, banners, ASN, and other server details for ethical hacking, pentesting, and bug bounty workflows.
Discover how to use shodan host to retrieve IP, location, organization, and open ports, with examples like Cloudflare 1.1.1.1 and Google DNS, plus JSON export and limit options.
Learn to use shodan commands to display your internet facing IP and parse downloaded datasets, then format results with the path option to show IP, port, and host name.
Use the Shodan search command to query the Shodan database and view results with IPs, ports, and banners. Tailor output with color, fields, and limits for penetration testing.
Use shodan scan to target an IP or net block, view status and recent scans, and save results to a file in json format while tracking scan credits.
Explore how to use the Shodan stats command to get aggregate data for a search query, like FTP or big IP servers, by country and organization, and CVE 2025-902.
Explore the Shodan GUI to search, filter, and export results, using CSV or JSON formats and filters like org, country, and port, with credits-based downloads.
Generate Shodan reports from search results, visualize target hosts by country, services, and ports, and receive the report via email after processing.
Generate and review a Shodan report, explore 958 results by country and organization, and assess TLS versions and SSL certificate status, including expirations.
Explore Shodan's image search to inspect crawled targets, identify exposed rdp servers on port 3389, and review details such as country, organization, and ssl/tls info to assess potential vulnerabilities.
Discover how Shodan exploits aggregates vulnerabilities from Exploit DB and Metasploit, enabling you to locate and run remote code execution exploits for specific software versions.
Explore live hunting on Kibana with Shodan to identify unauthenticated Kibana log servers and exposed logs, assess potential P1 vulnerabilities.
Learn to use Shodan to find sensitive data exposure, including directory listings, exposed credentials, internal endpoints, private IPs, and API keys such as AWS, SSH, SMTP, or Google Maps keys.
Explore the Cisco ASA arbitrary file read vulnerability CVE-2023-452, showing how crafted Http requests can read files like portal.lua, and demonstrate automated mass hunting with Shodan, subdomain enumeration, and Nmap.
Demonstrates unauthenticated arbitrary file deletion on a Cisco asa ftdi, showing a curl-based POC that deletes logo.gif and risks DoS by deleting config files; highlights a 9.1 CVSS score.
Identify misconfigured Jenkins instances via Shodan and reveal sensitive data such as usernames, passwords, api keys, secret keys, docker and composer keys, internal endpoints, and build logs.
Learn to identify exposed credentials via Shodan in a live Jenkins exploitation scenario, discovering EC2, GitHub, Slack, and Bitbucket credentials, while ethically reporting to elevate severity.
Learn to use Shodan for live hunting of ADB devices on port 5555 and gain remote access with Ghost Framework; inspect system info, apps, and logs.
Explore the Shodan extension to enumerate target websites, view host details and open ports, and install the extension on Chrome or Firefox for quick reconnaissance.
Certificate transparency enables certificate authorities to publish ssl/tls certificates in public logs, letting you audit issued certificates and enumerate subdomains for recon and bug bounty testing with cert dot search.
Identify subdomains with wildcard patterns using certificate transparency searches via crt.sh for mass enumeration of government domains, then report vulnerabilities through formal disclosure channels.
Automate certificate transparency domain discovery with a bash script to collect and filter subdomains from cert databases, export ready-to-use targets, and accelerate bug bounty hunting.
Learn how to use Shodan to identify subdomains of a target by using the Shodan CLI, API key initialization, and domain searches, including DNS records and A/TXT data.
Use the show domain tool to enumerate subdomains from Shodan data, clone the repository, install dependencies, run the script with your API key, and target a domain such as starbucks.com.
Explore census to enumerate subdomains from SSL/TLS certificate data, using certificate filters, dashboards, and data definitions for practical recon in pentesting and bug bounty hunting.
Automate subdomain enumeration using the census python library, export API keys to environment variables, and generate json outputs while filtering results by ssl certificates and html titles.
Use Facebook's certificate transparency tools to search certificates, identify domains and subdomains, and hunt subdomains for bugs.
Leverage Google certificate transparency to identify domains and subdomains for bug bounty hunting and penetration testing. Search certificates by hostname and include subdomains to uncover targets and https exposure.
Utilize pen test tools to scan subdomains, perform DNS enumeration, and identify CMS and web app vulnerabilities, then use targeted scans like WP scan to assess WordPress risks.
Explore how VirusTotal helps ethical hackers hunt subdomains by scanning files and URLs with antivirus engines, revealing phishing domains and live subdomains via DNS and WHOIS data.
Learn to use Sub Lister for subdomain enumeration, gather open source intelligence from search engines, and automate and monitor recon to uncover vulnerable subdomains and misconfigurations for bug bounty.
Learn how to tune subroute to improve subdomain enumeration, using brute force (-B) with specific search engines and verbose output, plus creating custom word lists.
Utilize sublister to enumerate subdomains for bug bounty hunting by combining brute force and data from search engines, tuning threads, and saving results for uber.com or similar targets.
Discover project discovery’s chaos project, with subdomain records for bug bounty programs. Follow updates from Hackerone and Bugcrowd, explore thousands of subdomains and DNS records, and enable vulnerability hunting.
Learn to enumerate subdomains and datasets with Chaos Pie via the terminal, including cloning, installing requirements, and using CLI flags to list and download programs on HackerOne and Bugcrowd.
Use the project discovery data sets CLI to search programs with grep and download individual datasets like Zomato or Bugcrowd via the -d flag, then unzip and view the listing.
Nmmapper enables comprehensive subdomain enumeration and tool comparison, highlighting subdomains from sublister, anubis, amass, and nmap to identify the most subdomains and assess live versus dead results.
Explore the wayback url workflow on hacker1.com, review captures by mimetype—html, image, svg, and javascript—and enumerate new and existing urls to identify parameter-based vulnerabilities.
Enumerate target URLs with the wayback URLs tool to extract crawl data, install go, clone the tool, and output domain and subdomain URLs for bug bounty and pentesting.
Utilize the Wayback Machine via an iframe to reveal historical endpoints and parameters across years on a target site like hackerone.com, expanding vulnerability testing scope.
discover how to harvest all urls from the Wayback archive using Burp Suite, iframe, and graphical interface methods, then capture requests and export lists for bug bounties and pentesting.
Enumerate and recon targets with wayback urls, then automate bug bounty oriented vulnerability testing using a bash pipeline that replaces injection points, sends payloads via curl, and verifies xss results.
Automate vulnerability hunting by using Wayback archive data with Param Spider to enumerate URLs, mine parameters, and identify nested parameters, exclusions, and quick XSS checks.
Automate Wayback URL collection with param spider, using exclude and replace features. Explore placeholder fuzzing, Python Param Spyder, and curl loops to identify vulnerabilities.
Demonstrate live vulnerability hunting on Bugcrowd programs using Wayback URLs, a bash script, and curl to identify vulnerable parameters, including XSS and open redirects on optimizely.com.
Leverage Wayback archive and Param Spider to map target URLs, identify a csrf token vulnerability from unsanitized inputs, and explore Baron Spider tools for automation.
Expand your scanning scope with get all URLs from Alien Vaults, Wayback, and Common Crawl. Set up the tool, crawl targets and subdomains, grep parameters, replace payloads, identify injection points.
Explore DNS Dumpster for DNS reconnaissance by revealing A records, TXT records, MX records, and subdomains. Export results to Excel and view the graph to map targets and assess vulnerabilities.
Explore how to retrieve DNS records, whois data, and DNS query lookups for a target, using DNS goodies to check reverse DNS, open relay, spam databases, IP discovery, and traceroutes.
Discover how to identify a site's CMS and underlying technologies using Verbalizer, and why identifying the CMS helps spot exploitable versions and security risks.
Identify a website's technologies with builtwith, including cms, analytics, and frameworks, to assess versions and vulnerabilities. Use builtwith and its browser extension to profile targets for ethical pentesting.
Identify web technologies with whatweb, an open source web scanner that detects CMS, frameworks, and JavaScript libraries like jQuery for pen testing and bug bounty work.
Identify outdated JavaScript in web applications using retire.js, via the Chrome extension, Burp, or OWASP ZAP plugins, and assess vulnerabilities like outdated jQuery versions with CVE details.
Install the Retire.js extension for Burp Suite, via the Retire.js site or Burp store, then run a passive scan to identify outdated JavaScript and related vulnerabilities.
Discover fuzzing as an automated method to rapidly uncover web vulnerabilities. Use word lists and injection points to elicit crashes, memory leaks, and exploitable bugs for pentesting and bug bounty.
Fuzzing expands web application scope by exposing hidden endpoints and misconfigurations, revealing default credentials, env files, and hardcoded tokens to uncover cves and sensitive data.
Master fuzzing to boost enumeration, content discovery, and vulnerability detection for bug bounty and penetration testing, identifying XSS, SQL injection, and sensitive data exposure with automated payloads.
Contrast fuzzing with static analysis by testing runtime behavior with targets, word lists, and payloads, using Burp Suite, wfuzz, and Wayback archive to uncover endpoints and monitor anomalies.
Perform live fuzzing on a website using Burp Suite, selecting an injection point, applying a word list, and filtering responses by status code and grep results to identify sensitive files.
Explore fuzzing a web app with burp suite intruder using a dictionary.txt word list to uncover sensitive files, including composer.json data, phpMyAdmin pages, and an admin directory listing.
Execute a multi-layer fuzzing workflow on a live web app using Burp Suite Intruder and payloads to uncover hidden endpoints and sensitive data like env details and credentials.
Install wfuzz via pip after installing Python 3, then use wfuzz -w wordlist to fuzz a target endpoint starting from a path such as /backup/administrator/secure.
Install and run wfuzz, the web fuzzer, using Python and pip; verify the installation and explore basics of fuzzing URLs, parameters, headers, and authentication with wordlists.
Practice basic wfuzz fuzzing on a target url, using a word list and color output, then filter results to expose 200 responses and admin paths.
Explore using WFuzz for login authentication brute force, extract login payloads from the browser, and validate credentials such as admin and Tomcat with a supplied wordlist.
Demonstrate brute-forcing http basic authentication with wfuzz, using the built-in basic module, a usernames list, and options like -Z and -c to reveal a successful login (admin).
Learn to install ffuf, a fast go-based web fuzzer, by installing go, fetching ffuf from GitHub, and preparing a word list, then run ffuf with -u and -w options.
Demonstrates using ffuf for web fuzzing: supply -u url, -w word list, and the firs keyword to inject words, revealing endpoints like secret.txt and api keys.
Learn how FFUF directory fuzzing with extensions reveals sensitive files by appending extensions from a word list; practice recursive fuzzing to uncover config files and credentials on web targets.
Learn to use ffuf for fuzzing and brute forcing login pages, choosing cluster bomb or pitchfork modes with two wordlists and crafting requests from Burp with a post file.
Welcome to Recon for Bug Bounty Pentesting and Ethical Hacking
This course starts with the Basics of Recon and Bug Bounty Hunting Fundamentals to Advance Exploitation
This course starts with basics with Web and Web Server Works and how it can be used in our day to day life We will also learn about DNS URL vs URN vs URI and Recon for Bug Bounties to make our base stronger and then further move on to Target Expansion Content Discovery Fuzzing CMS Identification Certificate Transparency Visual Recon GitHub Recon Custom Wordlists Mind Maps Bug Bounty Automation Bug Bounty Platforms with practicals
This course covers All the Tools and Techniques for Penetration Testing and Bug Bounties for a better understanding of what is happening behind the hood
The course also includes an in depth approach towards any target and increases the scope for mass hunting and success
With this course we will learn Target Selection Techniques for Host Subnet Scans and Host Discovery Content Discovery Subdomain Enumeration Horizontal and Vertical CMS Identification Fuzzing the target for finding web vulnerabilities like XSS Open Redirect SSRF SQL Injection etc How to increase the scope and take screenshots for a large number of hosts for better visualization We will also learn How to use Shodan for Bug Bounties to find critical vulnerabilities in targets We will also see GitHub Recon to find sensitive information for targets like API keys from GitHub Repositories Next we will see How to perform Automation for daily day to day tasks and easier ways to run tools We will also see How to write Bug Bounty and Pentesting Reports We will also cover mind maps by other hackers for a better approach toward any target and also we will see a mind map created by us We will also see Bug Bounty Platforms and how to kick start our journey on them
Here is a more detailed breakdown of the course content
In all the sections we will start with the fundamental principle of How the scan works and How can we perform Exploitation
In Introduction We will cover What is Web What are Web Servers DNS and We will also learn about DNS and How DNS works and also How DNS is important in our day to day life We will also see the difference between URL URN and URI We will also see the complete breakdown of the URL to understand better We will also learn about Bug Bounty Hunting and Understand the Importance of Recon in Bug Bounty Hunting and Pentesting
Before starting the journey We will see Top 10 rules for Bug Bounty Hunting and we will understand the psychology of the Hackers
In Shodan for Bug Bounties we will start with the installation of Shodan and we will learn about Shodan Queries such as Info Count downloads and many more and will run them from our command line We will also learn Host Enumeration Parse dataset Search Queries and Scan commands using Shodan The section cannot be completed without learning about Shodan GUI which is very simple and easily understandable We will also see Shodan Images Exploits Report generation and a lot more
In the end we will see the summary and revision of the section to remember the important queries and key points
We will see live hunting with Shodan and understand the latest CVEs and perform exploits We will see Jenkins Exploitation Logs Jenkins Exploitation Credentials ADB under Shodan LIVE Hunting
In Certificate Transparency for Subdomain Enumeration we will learn about crt dot sh wildcards of crt dot sh and We will learn automation for crt dot sh to enumerate subdomains for a target We will also learn about Shodan Censys for Subdomain Enumeration We will learn about Google and Facebook Certificate Transparency We will also learn to find out Subdomains using DNS Dumpster and enumerate all the DNS records as well as save the hosts in an XLSX format We will also see the workflow for dnsdumpster to know about the whole target server from its DNS records like A CNAME MX TXT etc
In Scope Expansion we will learn about ASN Lookup Pentest tools VirusTotal We will also learn about some awesome tools like Sublister Subfinder Knockpy Asset Finder Amass Findomain Sublert Project Discovery Nmmapper and a lot more We will also understand how to use them effectively for expanding the scope to walk on a less traveled road and achieve success in bug bounties
In DNS Enumeration for Bug Bounties we will learn and understand about DNS Dumpster DNS Goodies Altdns Massdns Vertical and Horizontal Correlation Viewdns info and enumerate the subdomains from the recursive DNS
We will start with Introduction to Fuzzing Its importance and Step by Step process We will see fuzzing practically on LAB and LIVE websites to understand better We will Learn Understand and Use tools like Wfuzz and FFUF and also see how we can perform recursive fuzzing on the target We will also perform HTTP Basic Auth Fuzz to crack the login of the dashboards and also do Login Authentication Cracking with the help of useful wordlists
We will utilize some of the wordlists like SecLists FuzzDB Jhaddix All txt and will also see how to make our own custom wordlists for the targets
Content Discovery covers tools like Dirsearch Gobuster which will be helpful for finding out sensitive endpoints of the targets like db conf or env files which may contain the DB username and passwords Also sensitive information like periodic backups or source code and can also be identified which can lead to the compromise of the whole server
In CMS Identification we will learn and understand about Wappalyzer Builtwith Netcraft WhatWeb Retire js
As Banner Grabbing and identifying information about the target is the foremost step we will identify the underlying technologies which will enable us to narrow down the approach which will lead to success
In WAF Identification we will see WAF Detection with Nmap WAF Fingerprinting with Nmap WafW00f vs Nmap
We will know if there are any firewalls running on the target and accordingly send our payloads to the targets and throttle our requests so we can evade them successfully
The Mindmaps for Recon and Bug Bounty section will cover the approach and methodology towards the target for pentesting and bug bounty A strong and clear visual representation will help in performing the attack process with more clarity and will help in knowing the next steps
The Bug Bounty Platforms section contains a Roadmap of How to start your Bug Bounty Journey on different Platforms like HackerOne Bugcrowd Integrity Synack It also covers how to Report Private RVDP Programs
With this course you get 24 7 support so if you have any questions you can post them in the Q and A section and we will respond to you as soon as possible
Notes
This course is created for educational purposes only and all the websites I have performed attacks on are ethically reported and fixed
Testing any website that does not have a Responsible Disclosure Policy is unethical and against the law The author does not hold any responsibility