My BugBounty Journal

The journal of a unix geek taking its first steps into the BugBounty world...

View on GitHub

My bugbounty journal day: 8 - insert meaningful title here

Another day… having another go at it. I am really pumped for the day as i plan to try out some new tools that i found.

Unfortunately as you can tell from just the 3 hours that i invested, something went wrong and i had to stop, pack my things and go get some sleep.

Work hours: 00:00 - 03:00 am

Plan for the day

The plan for the day is to continue on with the program i was most familiar with and see if any of the new tools will make it easier to dig something interesting out of it.

Last time i was struggling with HTTP requests so, during the day i practiced some new tools to not waste time during my engagements.

Targets of the day

Again no new targets were added to the list (although i came to regret it later on).

I chose to focus on the program that i had the most familiarity with by now. So after a quick review of my data i jumped into http-prompt and started messing with some interesting endpoints that i had discovered.

My main focus was to try and discover some more implementation specific details, such as application and library names, versions, operating systems etc. With this information i can then check to see if there are any “new” vulnerabilities discovered that the program owners might have missed.

This went quite well and i was able to figure out applications, libraries, versions, as well as identify certain vulnerable components that i could attack later on. I got really really excited with this and i could almost taste victory.

Excitement is good to keep you going (even if no results come out of it).

However, my excitement was short lived, as it turned out the program that i picked to work on for the day got… Suspended :man_facepalming:

That hit harder than i expected… It killed my desire and my interest for the rest of the day and gave up shortly after, spending instead my time in pondering at all those “could have been submissions”… :sob:

Tools of the day

Observations of the day

It could have been nice to have to know the end life of each program before hand. If i knew that the program was to be suspended so soon, i would have picked a different strategy for approaching it.

But thinking about it with a clear head, i can see why announcing it before hand, could have been a bad idea. In the end i realized that i’m on this program for almost a month, it may have been the 8th day for me but its 3 weeks that have passed since i first started.

Although it was disappointing, I didnt consider my time on the program wasted for two main reasons:

Conclusions of the day

Final words

I had the opportunity to test some really awesome tools this day. I dont think its by accident that most of them were from @tomnomnom :smiley: