Dear Readers,
In the last post we got h1-brain installed and synced. Twelve tools total: five search your personal database, two search the public disclosed reports database, four hit the HackerOne API, and hack() ties everything together.
Your report tools#
All local, no API calls, no rate limits. These query h1_data.db.
search_reports#
search_reports(query, program, weakness, severity, limit)All parameters optional, combined with AND logic.
- query — Searches report titles.
- program — Filter by program handle.
- weakness — Filter by weakness type. “SSRF”, “XSS”, “IDOR”, etc.
- severity — “critical”, “high”, “medium”, “low”.
- limit — Defaults to 20.
“Show me every SSRF I’ve found on high severity or above”
Found 8 reports ($14,200 total):
- **#1847293** [critical] Blind SSRF via webhook URL parameter
— shopify — Server-Side Request Forgery (SSRF) — $5,000
> The application's webhook registration endpoint accepts user-supplied
> URLs without validating the destination. By providing an internal IP...
- **#1623841** [high] SSRF in PDF export functionality allows internal
network scanning — uber — Server-Side Request Forgery (SSRF) — $3,500
> The /api/v2/export/pdf endpoint accepts a URL parameter for header
> image. This URL is fetched server-side without restriction...
- **#1589234** [high] Full-read SSRF via image proxy endpoint
— yahoo — Server-Side Request Forgery (SSRF) — $2,500
> The image proxy at img.yahoo.com/proxy accepts arbitrary URLs...
...
_Use get_report(id) to read the full vulnerability details._search_programs#
search_programs(query, bounty_only, limit)Finds programs by name or handle. Set bounty_only to true to only show programs that pay.
“What bounty programs do I have access to with ‘security’ in the name?”
Found 3 programs:
- security — HackerOne Security [bounty] (open)
- github-security — GitHub Security Lab [bounty] (open)
- tiktok-security — TikTok Security [bounty] (open)search_scopes#
search_scopes(program, asset, bounty_only, limit)Searches assets across programs.
“Show me all bounty-eligible API assets for shopify”
Found 12 assets:
- `*.myshopify.com` (URL) — shopify [bounty] [max: critical]
- `shopify.com/admin/api/*` (URL) — shopify [bounty] [max: critical]
- `partners.shopify.com` (URL) — shopify [bounty] [max: high]
- `apps.shopify.com` (URL) — shopify [bounty] [max: high]
...get_report#
get_report(report_id)Full write-up for a specific report.
“Show me the full details of report 1847293”
# Report #1847293: Blind SSRF via webhook URL parameter
**Program:** shopify
**Severity:** critical (9.1)
**Weakness:** Server-Side Request Forgery (SSRF) (CWE-918)
**Bounty:** $5,000 USD
**State:** resolved
**Created:** 2024-08-15
**Bounty awarded:** 2024-08-22
**Disclosed:** 2024-11-01
## Vulnerability Details
The application's webhook registration endpoint at
`/admin/api/2024-07/webhooks.json` accepts user-supplied URLs
without validating the destination host. By providing an internal
IP address (e.g., `http://169.254.169.254/latest/meta-data/`)
as the webhook target, an attacker can...
[full write-up continues]
## Attachments (2)
- **ssrf-poc.py** (text/x-python, 4 KB) — id: 89234
- **response-metadata.png** (image/png, 128 KB) — id: 89235get_report_summary#
get_report_summary()Your entire history grouped by program:
Total: 147 reports, $87,350 earned
- **shopify**: 23 reports, $18,700
- **github**: 12 reports, $14,200
- **uber**: 8 reports, $11,500
- **yahoo**: 15 reports, $8,900
- **twitter**: 6 reports, $7,200
...Good sanity check after syncing, as I mentioned in the setup post.
Public disclosed reports tools#
These query disclosed_reports.db — bounty-awarded public reports from other researchers. No API calls, ships with the repo.
search_disclosed_reports#
search_disclosed_reports(query, program, weakness, limit)Full-text search across public reports — titles and vulnerability write-ups. All parameters optional, combined with AND.
- query — Full-text search in title and vulnerability details.
- program — Filter by program handle.
- weakness — Filter by weakness type.
- limit — Defaults to 20.
“Search disclosed reports for SSRF on shopify”
Found 14 disclosed reports:
- **#1628745** Full-read SSRF via webhook callback — shopify
— Server-Side Request Forgery (SSRF)
Asset: `*.myshopify.com` (URL)
> The webhook registration endpoint at /admin/api/webhooks.json...
- **#1534982** Blind SSRF in PDF export — shopify
— Server-Side Request Forgery (SSRF) — $3,000
Asset: `shopify.com/admin/*` (URL)
> The export endpoint fetches a user-supplied URL for the header image...
...
_Use get_disclosed_report(id) for full details._The difference between this and search_reports: search_reports queries your personal rewarded reports. search_disclosed_reports queries what other researchers found and got paid for. hack() uses both.
get_disclosed_report#
get_disclosed_report(report_id)Full details of a public disclosed report — title, program, weakness type, asset, CVEs, bounty amount, and the full vulnerability write-up.
The sync tools#
These hit the HackerOne API.
fetch_rewarded_reports#
Pulls all your bounty-awarded reports. Covered in the setup post. Run once to populate, periodically to pick up new reports.
fetch_programs#
Pulls all programs you have access to. Run once, rerun when you want fresh data.
fetch_program_scopes#
fetch_program_scopes(handle)Fetches the current scope for a specific program directly from the API. Hits HackerOne every time because scope changes frequently. You usually don’t need to call this directly because hack() calls it for you.
fetch_attachment#
fetch_attachment(report_id, attachment_id?)Gets fresh S3 download URLs for report attachments. URLs expire after about an hour.
“Get the attachments for report 1847293”
## Attachments for Report #1847293
### ssrf-poc.py (text/x-python, 4 KB)
**Download URL** (expires in ~1 hour):
https://hackerone-us-west-2-production-attachments.s3.us-west-2...
### response-metadata.png (image/png, 128 KB)
**Download URL** (expires in ~1 hour):
https://hackerone-us-west-2-production-attachments.s3.us-west-2...hack()#
hack(handle)Give it a program handle, get a complete briefing combining live API data with your local history.
flowchart TD
A["hack(handle)"] --> B["Fetch fresh scope from HackerOne API"]
B --> C["Pull your reports on this program from SQLite"]
C --> D["Analyze weakness patterns across ALL programs"]
D --> E["Identify untouched bounty-eligible assets"]
E --> F["Cross-reference public disclosed reports for this program"]
F --> G["Generate attack briefing with instructions"]
style A fill:#ff5c5c,stroke:#ff5c5c,color:#fff
style G fill:#ff5c5c,stroke:#ff5c5c,color:#fff
style B fill:#1a1d27,stroke:#555,color:#fff
style C fill:#1a1d27,stroke:#555,color:#fff
style D fill:#1a1d27,stroke:#555,color:#fff
style E fill:#1a1d27,stroke:#555,color:#fff
style F fill:#1a1d27,stroke:#555,color:#fff
What it does: fetches fresh scope from the API, pulls your history on this program, analyzes your weakness patterns across all programs, identifies untouched assets, cross-references public disclosed reports for the target program (what other researchers found and got paid for), and suggests attack vectors based on what paid elsewhere but is absent here. The instructions are loaded from hack_instructions.md and put the AI in offensive mode.
“hack shopify”
# Hacking Session: shopify
## Scope
### In-Scope (Bounty Eligible)
- `*.myshopify.com` (URL) [max: critical]
- `shopify.com/admin/api/*` (URL) [max: critical]
- `partners.shopify.com` (URL) [max: high]
- `apps.shopify.com` (URL) [max: high]
- `Shopify Android` (Google Play) [max: critical]
- `Shopify iOS` (App Store) [max: critical]
...
### In-Scope (No Bounty)
- `community.shopify.com` (URL)
## Your Past Findings Here (23 reports, $18,700 total)
- [critical] Blind SSRF via webhook URL parameter
— Server-Side Request Forgery (SSRF) (CWE-918) — $5,000
- [high] Stored XSS in product description via Liquid template
— Cross-site Scripting (XSS) - Stored (CWE-79) — $2,500
- [high] IDOR allows reading other merchants' draft orders
— Insecure Direct Object Reference (IDOR) (CWE-639) — $2,000
...
## Weakness Types That Worked Here
- Cross-site Scripting (XSS) - Stored: 7x
- Server-Side Request Forgery (SSRF): 4x
- Insecure Direct Object Reference (IDOR): 3x
- Information Disclosure: 3x
- Improper Authentication: 2x
...
## Untouched Scope
Assets with zero findings from you:
- `partners.shopify.com` (URL, bounty eligible)
- `apps.shopify.com` (URL, bounty eligible)
- `Shopify Android` (Google Play, bounty eligible)
- `Shopify iOS` (App Store, bounty eligible)
- `shopify.dev` (URL, bounty eligible)
...
## Suggested Attack Vectors
Based on your global track record, these weakness types have
paid off on other programs but haven't been found here yet:
- SQL Injection (rewarded 5x on: uber, twitter, yahoo)
- Race Condition (rewarded 3x on: github, twitter)
- Business Logic Errors (rewarded 4x on: uber, yahoo, paypal)
- Path Traversal (rewarded 2x on: github, yahoo)
## Public Disclosed Reports (47 total for this program)
What other researchers found here (bounty-awarded, publicly disclosed):
- #1892341 Stored XSS in liquid template engine — Cross-site Scripting (XSS) on `*.myshopify.com`
- #1845123 IDOR on draft order API endpoint — IDOR on `shopify.com/admin/api/*`
- #1798456 Race condition in discount code redemption — Race Condition on `*.myshopify.com`
...
### Weakness patterns from public disclosures
- Cross-site Scripting (XSS): 14x
- Information Disclosure: 8x
- Insecure Direct Object Reference (IDOR): 7x
- Server-Side Request Forgery (SSRF): 5x
- Race Condition: 3x
## Instructions
[loaded from hack_instructions.md — directs the AI to start recon,
study disclosed reports, adapt techniques to untested assets,
and write exploit PoCs]The Public Disclosed Reports section is new. It shows what other researchers found on this specific program and the weakness patterns from those disclosures. Combined with the Suggested Attack Vectors section (your own cross-program data), you get two angles: what worked for you elsewhere, and what worked for others here.
Some useful follow-ups after running hack():
“Based on the untouched scope, which assets are most likely to have SSRF based on their type?”
“I found SQLi on uber’s export endpoint. The shopify admin API has similar export functionality. Walk me through how to test it.”
“Compare my past XSS findings here with the current scope. Are there new assets since my last report?”
How the tools fit together#
flowchart LR
subgraph Sync["Sync (API)"]
FR["fetch_rewarded_reports"]
FP["fetch_programs"]
FS["fetch_program_scopes"]
end
subgraph Personal["Your Reports (h1_data.db)"]
SR["search_reports"]
SP["search_programs"]
SS["search_scopes"]
GR["get_report"]
GS["get_report_summary"]
end
subgraph Public["Public Reports (disclosed_reports.db)"]
SD["search_disclosed_reports"]
GD["get_disclosed_report"]
end
subgraph Files["Attachments (API)"]
FA["fetch_attachment"]
end
H["hack()"] --> FS
H --> SR
H --> GS
H --> SD
GR --> FA
style H fill:#ff5c5c,stroke:#ff5c5c,color:#fff
style Sync fill:#1a1d27,stroke:#555,color:#fff
style Personal fill:#1a1d27,stroke:#555,color:#fff
style Public fill:#1a1d27,stroke:#555,color:#fff
style Files fill:#1a1d27,stroke:#555,color:#fff
Typical flow:
hack(handle)— Get the briefing.- Read untouched assets and suggested vectors — Pick a focus.
search_reports(weakness="...")— Pull past reports for that weakness type.get_report(id)— Read the full write-up.fetch_attachment(report_id)— Grab the PoC.
In the next post I’ll walk through this flow on a real target.
Until next time 🙂



