Random Notes on Bug Bounty Tools That Actually Work
A few tools I reach for every day in my bug bounty workflow: httpx, notify, anew, Param Miner, hakrawler, jq/cut/awk, Logger++ and GitHub recon, with the exact flags I use.
Personal blog on offensive security: Bug Bounty, Penetration Test, write-ups, tooling notes, and curated cyber news.
A few tools I reach for every day in my bug bounty workflow: httpx, notify, anew, Param Miner, hakrawler, jq/cut/awk, Logger++ and GitHub recon, with the exact flags I use.
Two simple but high-impact findings, and the lessons that led me to them.
Crawling a target I thought I knew — with Katana, hakrawler, waybackurls, and unfurl — surfaced a hidden /HelpApi/ endpoint and an IDOR leaking users' PII.