Book Image

Bug Bounty Hunting Essentials

By : Carlos A. Lozano, Shahmeer Amir
Book Image

Bug Bounty Hunting Essentials

By: Carlos A. Lozano, Shahmeer Amir

Overview of this book

Bug bounty programs are the deals offered by prominent companies where-in any white-hat hacker can find bugs in the applications and they will have a recognition for the same. The number of prominent organizations having this program has increased gradually leading to a lot of opportunity for Ethical Hackers. This book will initially start with introducing you to the concept of Bug Bounty hunting. Then we will dig deeper into concepts of vulnerabilities and analysis such as HTML injection, CRLF injection and so on. Towards the end of the book, we will get hands-on experience working with different tools used for bug hunting and various blogs and communities to be followed. This book will get you started with bug bounty hunting and its fundamentals.
Table of Contents (20 chapters)
Title Page
Copyright and Credits
About Packt
Contributors
Preface
Index

Detecting and exploiting open redirections


There are some redirections that are easy to detect – most redirections use a GET request. Others are a little more difficult to detect in simple view and need the use of the HTTP proxy to confirm them. Let's view another example:

www.testsite.com/process.php?r=otherplace.com (moidifcar por una real) 

In this kind of redirection, it is obvious that the variable is acting as flow control. Now, let's get Burp Suite to confirm the redirection and analyze it using the following steps:

  1. Open the website that you think is using redirections.
  2. Stop the request using the Burp Suite's Proxy, by clicking on the Intercept is on button:
  1. Use the secondary click to display the options menu, and click on Send to Spider.
  2. Spider is a tool included in all the HTTP proxies that works to map the applications. Spider follows all the links and redirections detected in the HTTP requests and responses to find the website's structure.
  3. Go to the Spider section, clicking on the Spider...