Company
Date Published
Author
streaak
Word count
2167
Language
-
Hacker News points
None

Summary

Akhil George, known as streaak, is a student and ethical hacker who shares insights from his bug bounty hunting experience, particularly focusing on reconnaissance techniques. In his guest blog, streaak outlines his methodology for expanding the attack surface of targets, which includes subdomain reconnaissance, passive endpoint gathering, subdomain takeovers, and directory brute-forcing. He uses various tools like Subfinder, Amass, and Massdns to identify subdomains and potential vulnerabilities, and he emphasizes the importance of managing data effectively throughout the process. Streaak also highlights the risks of sensitive data exposure, such as Slack webhook and Firebase API tokens, and explains how these can be leveraged if improperly secured. His approach combines automated tools and custom scripts to enhance efficiency, although he notes the limitations and challenges he encountered, such as avoiding cloud service bans during brute-forcing and managing large datasets.