[{"content":"I work as a pentester after spending two years teaching myself through CTFs, the PortSwigger Web Security Academy, Hack The Box, and other resources. I know how hard it is to land a pentesting job with nothing professional on your resume.\nI built experience through volunteer pentesting, and it still took an internship to prove I could find real bugs. Looking back, I wish I\u0026rsquo;d started bug bounty hunting sooner. Having a public record of vulnerabilities I’d discovered would have given me evidence to show a hiring manager.\nSo I\u0026rsquo;m creating content for people with little to no experience who want to learn how to hunt vulnerabilities in bug bounty programs. I make videos and written walkthroughs on finding web vulnerabilities, and go through free labs where you can practice finding those bugs before hunting on live targets.\nHope you learn a bunch. Feel free to reach out with blog requests, questions, etc @ discord .\n","permalink":"https://blue-pho3nix.github.io/about/","summary":"\u003cp\u003eI work as a pentester after spending two years teaching myself through CTFs, the PortSwigger Web Security Academy, Hack The Box, and other resources. I know how hard it is to land a pentesting job with nothing professional on your resume.\u003c/p\u003e\n\u003cp\u003eI built experience through volunteer pentesting, and it still took an internship to prove I could find real bugs. Looking back, I wish I\u0026rsquo;d started bug bounty hunting sooner. Having a public record of vulnerabilities I’d discovered would have given me evidence to show a hiring manager.\u003c/p\u003e","title":"About"},{"content":"1. Asset Discovery: Find Apex Domains Whois or DNSChecker Get Your Target\u0026rsquo;s Organization Name\u0026hellip;\nWhois Example: For IBM Whois works: https://www.whois.com/whois/ibm.com DNSChecker Example: For Uber DNSChecker works: https://dnschecker.org/all-dns-records-of-domain.php?query=uber.com\u0026rtype=ALL\u0026dns=google ASNs + IP Ranges Get your target\u0026rsquo;s Autonomous System Numbers (ASNs) and/or IP ranges\u0026hellip;\nYou can use the data scraper chrome extension to copy the IPs and ASNs. https://bgp.he.net/ Search for organization\u0026rsquo;s names. There may be multiple names. Save the ASN numbers. Click on the ASN# -\u0026gt; Prefixes v4 to get the IP ranges and save them to a ips.txt file. Asrank Search for organization names. There may be multiple names. Save the ASN number. Go to https://bgp.he.net/ to get the IPv4 ranges and save them to a ips.txt file. You can use org2ip-asn instead, but you might miss some ASNs or IP ranges. Arin and Ripe Search for organization names. There may be multiple names. Save the IP ranges as CIDR (Example: 66.90.225.72/29) to a ips.txt file. Caduceus Use Caduceus to get subdomains and apex domains\u0026hellip;\nInstall Caduceus sudo apt update \u0026amp;\u0026amp; sudo apt install -y gcc golang CGO_ENABLED=1 go install github.com/g0ldencybersec/Caduceus/cmd/caduceus@latest Add the following path to the end of your .zshrc or .bashrc\nexport PATH=$HOME/go/bin:$PATH Restart your shell: source ~/.zshrc or source ~/.bashrc.\nCat your IP text file and run it to Caduceus\ncat ips.txt | caduceus | tee caduceus.txt Install unfurl go install github.com/tomnomnom/unfurl@latest Get the apex domains from your Caduceus output.\ncat caduceus.txt | unfurl -u apexes | tee caduceus-apex-domains.txt Check your apex domains with my vibe coded python script , replacing \u0026lt;org\u0026gt; with your target\u0026rsquo;s organization (example: International Business Machines Corporation).\nNote: My script isn\u0026rsquo;t perfect. Feel free to reach out on Discord or create an issue if anything comes up. wget https://raw.githubusercontent.com/blue-pho3nix/scripts/refs/heads/main/whois_check.py python whois_check.py --org \u0026#34;\u0026lt;org\u0026gt;\u0026#34; -l caduceus-apex-domains.txt -o valid-caduceus-apex-domains.txt Whoxy Use Whoxy to get Apex Domains\u0026hellip;\nBuy Reverse Whois API Queries . Note: 1,000 for $10 is fine for now. Get Apex domains, replacing \u0026lt;company with the url encoded Organization (Example: International+Business+Machines+Corporation), and \u0026lt;api-key\u0026gt; with your API key .\nNote: This will get you the first 2,500 results. You can fetch more by page (start after page 25). More details here . If you fetch by page, make sure to keep tee -a whoxy-output to get all the domains in step 3. curl \u0026#34;https://api.whoxy.com/?key=\u0026lt;api-key\u0026gt;\u0026amp;reverse=whois\u0026amp;company=\u0026lt;compay\u0026gt;\u0026amp;mode=micro\u0026#34; | tee -a whoxy-output Cat out your Whoxy output and get your apex domains.\ncat whoxy-output | jq -r \u0026#39;.search_result[].domain_name\u0026#39; | tee whoxy-apex-domains.txt Check your apex domains with my vibe coded python script , replacing \u0026lt;org\u0026gt; with your target\u0026rsquo;s organization (example: International Business Machines Corporation).\nwget https://raw.githubusercontent.com/blue-pho3nix/scripts/refs/heads/main/whois_check.py python whois_check.py --org \u0026#34;\u0026lt;org\u0026gt;\u0026#34; -l whoxy-apex-domains.txt -o valid-whoxy-apex-domains.txt Apex Domains Sorta Done! Combine Your Apex Domain Files\u0026hellip;\ncat valid-whoxy-apex-domains.txt valid-caduceus-apex-domains.txt | sort -u | tee valid-apex-domains.txt 2. Subdomain Scraping 🎉 Subfinder Use Subfinder to get subdomains\u0026hellip;\nMake sure to add you API keys to ~/.config/subfinder/provider-config.yaml Install Subfinder\ngo install -v github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest Run the following command\nsubfinder -dL valid-apex-domains.txt -all -o subfinder-subdomains.txt Assetfinder Use Assetfinder to get subdomains\u0026hellip;\nInstall Assetfinder\ngo install github.com/tomnomnom/assetfinder@latest Run the following loop\nwhile IFS= read -r domain; do [ -n \u0026#34;$domain\u0026#34; ] || continue assetfinder --subs-only \u0026#34;$domain\u0026#34; | tee -a assetfinder-valid-apex-domains.txt done \u0026lt; valid-apex-domains.txt 3. Subdomain Mutations Alterx Use Alterx to create some subdomain mutations\u0026hellip;\nInstall Alterx\ngo install github.com/projectdiscovery/alterx/cmd/alterx@latest Run the following command\nalterx -l subfinder-subdomains.txt -o alterx-subfinder-subdomains.txt 4. Is it active? + Increase Attack Surface Compile everything Get all the domains, subdomains, and IPs into one file\u0026hellip;\ncat all your files into one everything.txt file. Don\u0026rsquo;t include ips.txt if IPs are not in scope. cat valid-apex-domains.txt alterx-subfinder-subdomains.txt assetfinder-valid-apex-domains.txt subfinder-subdomains.txt ips.txt | sort -u | tee everything.txt Dnsx + Naabu + Httpx Get the active assets\u0026hellip; get open ports and increase your attack surface\u0026hellip; find out what\u0026rsquo;s serving web content\u0026hellip;\nInstall Dnsx + Naabu + Httpx If this is your first time installing, you\u0026rsquo;ll want to delete which httpx first. go install -v github.com/projectdiscovery/dnsx/cmd/dnsx@latest go install -v github.com/projectdiscovery/naabu/v2/cmd/naabu@latest go install -v github.com/projectdiscovery/httpx/cmd/httpx@latest Get the valid subdomains + ports + web content\nFor naabu, this just gets the top 100 ports. If you want more ports run --top-ports full or --top-ports 1000. In addition, you can add / remove flags and even screenshot with httpx (if you don\u0026rsquo;t want to screenshot with gowitness). dnsx -l everything.txt -r ./resolvers.txt | naabu -silent | httpx -title -sc -cl -location -fr -o httpx_naabu_dnsx_everything.txt 5. Screenshots Gowitness Make it easier to see / of each (sub)domain/IP\u0026hellip;\nI use gowitness, but feel free to use whatever you want ( Eyewitness , Eyeballer ) Install gowitness go install github.com/sensepost/gowitness@latest Get screenshots\ngowitness scan file -f input --write-db --screenshot-fullpage Open the server\ngowitness report server Navigate to http://127.0.0.1:7171\nNote You can also get subdomains via bruteforcing, GitHub , etc. And, feel free to pipe commands and/or make a script, etc\u0026hellip; You may also like using Karma v2 \u0026hellip; This is only the beginning of recon\u0026hellip; References This is where I learned a bunch of this\u0026hellip;\nModern Recon for Red Teamers and Pentestrs: Slides hackinghub: Project Discovery Tools ","permalink":"https://blue-pho3nix.github.io/blog/recon/","summary":"\u003ch1 id=\"1-asset-discovery-find-apex-domains\"\u003e1. Asset Discovery: Find Apex Domains\u003c/h1\u003e\n\u003chr\u003e\n\u003ch2 id=\"whois-or-dnschecker\"\u003eWhois or DNSChecker\u003c/h2\u003e\n\u003cp\u003eGet Your Target\u0026rsquo;s Organization Name\u0026hellip;\u003c/p\u003e\n\u003chr\u003e\n\u003ch3 id=\"whois\"\u003e\u003ca href=\"https://www.whois.com/whois\"\n   \n    target=\"_blank\" rel=\"noopener noreferrer\"\u003e\n   Whois\n\u003c/a\u003e\u003c/h3\u003e\n\u003ch4 id=\"example-for-ibm\"\u003eExample: For IBM\u003c/h4\u003e\n\u003cp\u003eWhois works: \u003ca href=\"https://www.whois.com/whois/ibm.com\"\n   \n    target=\"_blank\" rel=\"noopener noreferrer\"\u003e\n   https://www.whois.com/whois/ibm.com\n\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cimg alt=\"alt text\" loading=\"lazy\" src=\"/blog/recon/image.png\"\u003e\u003c/p\u003e\n\u003ch3 id=\"dnschecker\"\u003e\u003ca href=\"https://dnschecker.org/all-dns-records-of-domain.php\"\n   \n    target=\"_blank\" rel=\"noopener noreferrer\"\u003e\n   DNSChecker\n\u003c/a\u003e\u003c/h3\u003e\n\u003ch4 id=\"example-for-uber\"\u003eExample: For Uber\u003c/h4\u003e\n\u003cp\u003eDNSChecker works: \u003ca href=\"https://dnschecker.org/all-dns-records-of-domain.php?query=uber.com\u0026amp;rtype=ALL\u0026amp;dns=google\"\n   \n    target=\"_blank\" rel=\"noopener noreferrer\"\u003e\n   https://dnschecker.org/all-dns-records-of-domain.php?query=uber.com\u0026rtype=ALL\u0026dns=google\n\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cimg alt=\"alt text\" loading=\"lazy\" src=\"/blog/recon/image-3.png\"\u003e\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"asns--ip-ranges\"\u003eASNs + IP Ranges\u003c/h2\u003e\n\u003cp\u003eGet your target\u0026rsquo;s Autonomous System Numbers (ASNs) and/or IP ranges\u0026hellip;\u003c/p\u003e\n\u003cdiv class=\"callout callout-info\"\u003e\n  \u003cdiv class=\"callout-content\"\u003e\n    You can use the \u003ca href=\"https://chromewebstore.google.com/detail/instant-data-scraper/ofaokhiedipichpaobibbnahnkdoiiah?hl=en-US\"\n   \n    target=\"_blank\" rel=\"noopener noreferrer\"\u003e\n   data scraper chrome extension\n\u003c/a\u003e to copy the IPs and ASNs.\n  \u003c/div\u003e\n\u003c/div\u003e\n\u003chr\u003e\n\u003ch3\u003e\u003ca href=\"https://bgp.he.net/\"\n   \n    target=\"_blank\" rel=\"noopener noreferrer\"\u003e\n   https://bgp.he.net/\n\u003c/a\u003e\u003c/h3\u003e\n\u003col\u003e\n\u003cli\u003eSearch for organization\u0026rsquo;s names. There may be multiple names.\u003c/li\u003e\n\u003cli\u003eSave the ASN numbers.\n\u003cimg alt=\"alt text\" loading=\"lazy\" src=\"/blog/recon/image-1.png\"\u003e\u003c/li\u003e\n\u003cli\u003eClick on the ASN# -\u0026gt; Prefixes v4 to get the IP ranges and save them to a \u003ccode\u003eips.txt\u003c/code\u003e file.\n\u003cimg alt=\"alt text\" loading=\"lazy\" src=\"/blog/recon/image-2.png\"\u003e\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch3 id=\"asrank\"\u003e\u003ca href=\"https://asrank.caida.org/asns/by-name/\"\n   \n    target=\"_blank\" rel=\"noopener noreferrer\"\u003e\n   Asrank\n\u003c/a\u003e\u003c/h3\u003e\n\u003col\u003e\n\u003cli\u003eSearch for organization names. There may be multiple names.\u003c/li\u003e\n\u003cli\u003eSave the ASN number.\u003c/li\u003e\n\u003cli\u003eGo to \u003ca href=\"https://bgp.he.net/\"\n   \n    target=\"_blank\" rel=\"noopener noreferrer\"\u003e\n   https://bgp.he.net/\n\u003c/a\u003e to get the IPv4 ranges and save them to a \u003ccode\u003eips.txt\u003c/code\u003e file.\u003c/li\u003e\n\u003c/ol\u003e\n\u003cdiv class=\"callout callout-info\"\u003e\n  \u003cdiv class=\"callout-content\"\u003e\n    You can use \u003ca href=\"https://github.com/blue-pho3nix/org2ip-asn\"\n   \n    target=\"_blank\" rel=\"noopener noreferrer\"\u003e\n   org2ip-asn\n\u003c/a\u003e instead, but you might miss some ASNs or IP ranges.\n  \u003c/div\u003e\n\u003c/div\u003e\n\u003ch3 id=\"arin-and-ripe\"\u003e\u003ca href=\"https://whois.arin.net/ui/\"\n   \n    target=\"_blank\" rel=\"noopener noreferrer\"\u003e\n   Arin\n\u003c/a\u003e and \u003ca href=\"https://apps.db.ripe.net/db-web-ui/fulltextsearch\"\n   \n    target=\"_blank\" rel=\"noopener noreferrer\"\u003e\n   Ripe\n\u003c/a\u003e\u003c/h3\u003e\n\u003col\u003e\n\u003cli\u003eSearch for organization names. There may be multiple names.\u003c/li\u003e\n\u003cli\u003eSave the IP ranges as CIDR (Example: 66.90.225.72/29) to a \u003ccode\u003eips.txt\u003c/code\u003e file.\u003c/li\u003e\n\u003c/ol\u003e\n\u003chr\u003e\n\u003ch2 id=\"caduceus\"\u003eCaduceus\u003c/h2\u003e\n\u003cp\u003eUse Caduceus to get subdomains and apex domains\u0026hellip;\u003c/p\u003e","title":"Recon"}]