
Visual recon with Aquatone and WebScreenshot
A VPS-based workflow chaining Aquatone subdomain discovery, WebScreenshot capture and express-photo-gallery into a browsable wall of screenshots for triaging a large attack surface.
Old posts, 2013 to 2018. They stay up because people still link to them and I would rather not break someone’s citation.
Everything in here was true when I wrote it. The bugs are long fixed and half these vendors have rebuilt the products since. Some of what I wrote back then is advice I would not give today.

A VPS-based workflow chaining Aquatone subdomain discovery, WebScreenshot capture and express-photo-gallery into a browsable wall of screenshots for triaging a large attack surface.

A walkthrough of installing the Burp CA on an Android device, running frida-server and using an SSL re-pinning Frida script to intercept traffic from apps that pin certificates.

Directory brute-forcing a private bug bounty target turned up a world-readable .htpasswd whose descrypt hash, once cracked, opened four staging and development subdomains.

Proxying OS X Spotlight through Burp showed it shipping the user’s latitude and longitude to api.smoot.apple.com on every search, with two ways to block the request.

A duplicated q parameter in PayPal’s merchant directory let an injected payload break out of script context, producing a reflected XSS that PayPal patched within days.

mailroom.prezi.com concatenated the request path onto its own hostname when redirecting, so a request to /.attacker-domain sent victims to a lookalike attacker-controlled host.

Results from two weeks of a Kippo SSH honeypot in November 2014: roughly 4,000 brute-force attempts, 2,500 distinct credential pairs, and a source distribution dominated by hosts in China.

A Firefox-only reflected XSS on wwwb.search.billmelater.com, achieved by closing out of a style attribute and injecting a fresh script element, which the vendor classified as out of scope.

A payload placed in the URL fragment reached a DOM sink on PayPal’s main domain and executed; PayPal closed the report as a duplicate.

WP Live Chat Support, MyLiveChat and Provide Support all accepted stored cross-site scripting during a 2014 customer install.

A path traversal issue on Prezi’s map.prezi.com subdomain, fixed within two days of reporting and rewarded with a $1,000 bounty.

A 2014 run through PayPal’s bug bounty scope: seven confirmed issues across paypal.com, financing.paypal.com, apps.paypal.com and the paypal-*.com family, all closed as duplicate or invalid.

Reflected cross-site scripting across 160 German tax office websites, disclosed via heise.de and forwarded to CERT-Bund for coordinated remediation.

A public PHP 5.3.3-5.3.6 socket_connect exploit carrying a bind-TCP shell payload, dropped as an uploaded PHP file and located with an nmap sweep of ports 4000-4500.

Chaining a login-form SQL injection through sqlmap’s –os-shell into a Linux 2.6.32 local root exploit to go from the ’nobody’ user to full control of the server.

Pivoting from Yahoo’s main A record to its ARIN netblock and sweeping all 260,000 addresses in the /14 for an exposed phpinfo.php.