Skip to content

Latest commit

 

History

History
46 lines (37 loc) · 1.85 KB

README.md

File metadata and controls

46 lines (37 loc) · 1.85 KB

Note:

Steps:

  • 1: Recon
    • 1.1: Features
    • 1.2: Domains, Ips
    • 1.3: Apps (Android, ios)
  • 2: plz be optimistic 😢

Techniques:

Android

Tips:

  • Recon for company info (slack/any platform invitation leak, opensource github API key leak, etc)
  • Recon for DNS stuff
  • Check for DOS issues: https://cpdos.org/
  • Use money
  • Recon for public assets (like hackathon-related assets): sometimes companies run hackathons and give attendees special access to certain API endpoints and/or temporary credentials
  • CSRF change body to querystring because may uses @RequestParam
  • Look for XSLeaks like window.length
  • Look for clickjacking on sensitive content