↓ Skip to main content

Reconnaissance

Finding hosts, mapping attack surfaces, and observing exposed services.

2018

patrik.re Archive

Visual recon with Aquatone and WebScreenshot

A VPS-based workflow chaining Aquatone subdomain discovery, WebScreenshot capture and express-photo-gallery into a browsable wall of screenshots for triaging a large attack surface.

2016

patrik.re Archive

.htpasswd exposed, DES hash cracked

Directory brute-forcing a private bug bounty target turned up a world-readable .htpasswd whose descrypt hash, once cracked, opened four staging and development subdomains.

2014

patrik.re Archive

Two Weeks of a Kippo SSH Honeypot

Results from two weeks of a Kippo SSH honeypot in November 2014: roughly 4,000 brute-force attempts, 2,500 distinct credential pairs, and a source distribution dominated by hosts in China.

patrik.re Archive

Seven PayPal Bugs, Zero Bounties

A 2014 run through PayPal's bug bounty scope: seven confirmed issues across paypal.com, financing.paypal.com, apps.paypal.com and the paypal-*.com family, all closed as duplicate or invalid.

2013

patrik.re Archive

PHP 5.3.3–5.3.6 socket_connect Bind Shell

A public PHP 5.3.3-5.3.6 socket_connect exploit carrying a bind-TCP shell payload, dropped as an uploaded PHP file and located with an nmap sweep of ports 4000-4500.

patrik.re Archive

Yahoo's /14 and an exposed phpinfo.php

Pivoting from Yahoo's main A record to its ARIN netblock and sweeping all 260,000 addresses in the /14 for an exposed phpinfo.php.