recon
Reconnaissance: subdomain enum, live host discovery, URL crawling, parameter discovery.
Quick answer
What is recon?
Reconnaissance: subdomain enum, live host discovery, URL crawling, parameter discovery.
Articles
4
Beginner
4
Intermediate
0
Advanced
0
Beginner level
4Basic recon methodology — from the domain to the vulnerable endpoints
The minimal recon pipeline for bug bounty: subdomain enum, live host discovery, URL collection, parameter discovery. Free tools and execution order.
Client-side JavaScript analysis — endpoints, secrets and source maps
Extracting hidden endpoints from JS bundles, secret detection, source map analysis and dynamic instrumentation with Frida to audit client-side logic.
Complete recon — subdomains, fingerprinting, ASN and origin IPs
A practical recon methodology for bug bounty: passive/active subdomain enumeration, fingerprinting, ASN mapping, origin IPs to bypass the WAF and git history mining.
Information Disclosure — the 12 highest-paying patterns
API keys in HTML, debug endpoints, verbose errors, JS bundles with secrets, exposed .git, header leaks. How to find it and why it's fixed fast and paid.
Practice recon with real labs
Apply the techniques in safe environments based on real bug bounty reports.
hunters training
labs from real hacks
completions
paid out for these bugs
The checklist I run on every new target
47 checks ordered by cost: first what can get you in trouble, then the cheap stuff, and finally the expensive stuff — which is where the big bounties are. I'll send it to your inbox right now.
Unsubscribe in one click, from any email.
Stop reading about bugs and start hunting them
Create your free account and practice on labs based on real hacks that paid out thousands of euros. The Academy is free forever.
No card · free Academy · cancel anytime