Visual recon with Aquatone and WebScreenshot
A VPS-based workflow chaining Aquatone subdomain discovery, WebScreenshot capture and express-photo-gallery into a browsable wall of screenshots for triaging a large attack surface.
Finding hosts, mapping attack surfaces, and observing exposed services.
A VPS-based workflow chaining Aquatone subdomain discovery, WebScreenshot capture and express-photo-gallery into a browsable wall of screenshots for triaging a large attack surface.
Directory brute-forcing a private bug bounty target turned up a world-readable .htpasswd whose descrypt hash, once cracked, opened four staging and development subdomains.
Results from two weeks of a Kippo SSH honeypot in November 2014: roughly 4,000 brute-force attempts, 2,500 distinct credential pairs, and a source distribution dominated by hosts in China.
A 2014 run through PayPal's bug bounty scope: seven confirmed issues across paypal.com, financing.paypal.com, apps.paypal.com and the paypal-*.com family, all closed as duplicate or invalid.
A public PHP 5.3.3-5.3.6 socket_connect exploit carrying a bind-TCP shell payload, dropped as an uploaded PHP file and located with an nmap sweep of ports 4000-4500.
Pivoting from Yahoo's main A record to its ARIN netblock and sweeping all 260,000 addresses in the /14 for an exposed phpinfo.php.