Bug-bounty hunt — attack methodology
Bug-bounty hunt — attack methodology checklist
Do NOT cherry-pick. Run every phase that applies to your target stack. Each phase lists the exact Hugin MCP tool + params. If a tool is blocked (WAF, license, bug), note it and move on — don't skip the phase.
Phase 0: Pre-flight
// Confirm target is loaded and proxy is capturing
hugin_proxy_status action=health
hugin_project action=active // confirm correct project scope
hugin_list_flows host=TARGET limit=5 // confirm flows are being captured
Known accounts? If yes, configure session profiles FIRST:
hugin_session_profiles action=capture flow_id=... // from a logged-in flow
If no accounts, still run every unauth phase — many bugs don't need auth.
Phase 1: Passive intelligence (no outbound reqs)
Run BEFORE any active scan so you know what the target already disclosed.
hugin_intelligence action=analyze // process all captured flows
hugin_intelligence action=gold // high-value aggregated: nerve+client+response
hugin_intelligence action=nerve_findings // all param signals
hugin_intelligence action=response_intel // secrets, internal URLs, JS configs, cookie issues
hugin_intelligence action=client_side // postMessage handlers, DOM sinks, PP
hugin_intelligence action=cspt_scan // client-side path traversal
hugin_intelligence action=paramhunter // all parameter signals (21 categories)
Check every gold finding manually. Don't dismiss — verify. False positives are the norm but the ONE real finding is in there.
Phase 2: API mapping
hugin_api_map action=hosts // which hosts have captured flows
hugin_api_map action=map host=TARGET include_static=false // full API surface
hugin_bundle action=capture host=TARGET mode=host // JS bundles → endpoints + secrets
hugin_bundle action=endpoints session_id=... // extracted API paths
hugin_bundle action=secrets session_id=... // hardcoded creds/API keys
hugin_bundle action=promote session_id=... probe=true // feed endpoints to scanner
Know your stack: what framework, language, auth mechanism? Use:
hugin_fingerprint action=profile project_id=...
Phase 3: CORS + Headers
hugin_cors action=scan url=https://TARGET/api/public-endpoint
// Run on every unique origin (frontend, API, auth)
hugin_intelligence action=response_intel signal=csp_wildcard
If ACAO + ACAC:true + attacker-controlled Origin → critical. Reportable.
Phase 4: Authentication & session
// Even unauth — test auth endpoints
hugin_param_discover action=run url=POST_ENDPOINT method=POST
locations=["query","body_json","header"]
hugin_sqli action=test_param flow_id=... param_name=email param_location=json_body
If login/register/reset_password: brute-force timing, user enumeration, rate-limit bypass, password reset token leakage, 2FA bypass. Use:
hugin_sequencer action=capture flow_id=... token_location="body:token"
// Test CSRF tokens, reset tokens, session IDs for randomness
Phase 5: Injection — every class
Run on EVERY unique endpoint (public + 401/403 — 401 means it exists).
hugin_sqli action=scan host=TARGET limit=50
hugin_xss action=scan host=TARGET limit=50
hugin_pathtraversal action=scan host=TARGET limit=50
For each, check the findings carefully:
sqli: false positives = 302/403 (WAF), same-length responses (parameterized). Real = timing differential, error message with SQL syntax.xss: false positives = reflection only in JSON/JS context (escaped). Real = unescaped in HTML context, no CSP blocking.pathtraversal: false positives = WAF 403. Real = /etc/passwd in response, file download.
Phase 6: WAF-aware scanning
If the target has Imperva/Cloudflare/DataDome:
// Run scanner with WAF-adaptive payloads
hugin_scanner action=start flow_ids=[...] config={"profile":"thorough"}
Check every finding for WAF headers (x-iinfo, x-cdn: Imperva, cf-ray, x-blocked-by). If finding response has WAF headers → false positive.
Manual WAF bypass to find unescaped reflection:
Try: <p onbeforematch=print`1`> // bypasses Imperva
Try: <x test=1> // unknown tag
Try: '"><x> // simple breakout
Test in: URL params, POST body, headers, cookies, User-Agent
If no unescaped reflection → injection attacks are WAF-blocked. Phase is done.
Phase 7: SSRF + Server-side injection
hugin_vurl_cloud // generate cloud metadata SSRF wordlist
// Then: discover or intruder with that wordlist against ANY endpoint that
// takes a URL/host/file parameter
Also check: URL param reflection in error messages (Cloud SSRF leak), Host header-based SSRF on redirect endpoints.
Phase 8: Authorization (BOLA / IDOR / BAC)
Requires accounts. If you have 2+ session profiles:
hugin_bac_audit action=seed_corpus spec=... // from API spec
hugin_bac_audit action=audit profile_ids=["baseline","lowpriv"]
hugin_idor action=extract flow_ids=[...] // preview ID candidates
hugin_idor action=scan flow_ids=[...] // auto IDOR scan
If no accounts, still run:
hugin_authz action=scan host=TARGET
auth_contexts=[{name:"admin",header:"Authorization",value:"Bearer t0ken"}]
// Tests endpoints with SINGLE auth context to see what returns data
Phase 9: GraphQL
hugin_api_spec action=discover url=https://TARGET spec_type=graphql
If GraphQL found:
// Introspection query (standard)
// Test batch/aliasing IDOR
// Test mutation auth bypass
// Test cost analysis / depth DoS
// Test directive injection
Note: GraphQL was NOT vulnerable on CDC hosts. But always check — it's a common hidden surface.
Phase 10: Prototype Pollution
hugin_dom_invader action=scan_pp host=TARGET limit=500
hugin_dom_invader action=clobber host=TARGET limit=500
If AngularJS SPA → high priority. Angular's $scope and ng-bind-html are classic PP/DOM XSS vectors. Even if scanner finds nothing, the static patterns may not catch runtime gadgets.
Phase 11: postMessage + DOM XSS
hugin_postmessage action=scan host=TARGET limit=500
hugin_taint action=analyze_flow flow_id=... // for SPA HTML pages
If SPA (Angular/React/Vue): launch browser, navigate to SPA root, then run taint analysis. Static scanning won't find DOM XSS — you need real JS execution.
Phase 12: Race conditions
hugin_ratrace action=quick url=POST_ENDPOINT method=POST
concurrency=20 rounds=5
// Test: auth bypass, captcha reuse, token reuse, double-spend
High-value targets: reset_password/init (multiple emails), captcha solve + use (race token expiry), coupon/redeem codes, account activation, voting/rating endpoints.
Phase 13: Request smuggling
hugin_vurl_smuggle internal_target=169.254.169.254 path=/latest/meta-data/
public_host=TARGET
// Test CL.TE, TE.CL, TE.TE variants
// Test with different Host headers, X-Forwarded-Host, absolute-URI
If behind WAF/reverse proxy (Imperva, Cloudflare, Akamai, AWS WAF) → smuggling is possible. The WAF and backend may parse Content-Length vs Transfer-Encoding differently.
Phase 14: Open redirect
hugin_open_redirect action=scan // passive — checks captured redirect flows
hugin_open_redirect action=scan_active // active — probes redirect parameters
Also test with:
//evil.comscheme-relative@evil.comuserinfo confusionhttps://trusted.com.evil.comdomain confusionjavascript:alert(1)in redirect paramdata:text/html,...in redirect param
Phase 15: JWT attacks
// Find JWT tokens in captured flows
hugin_intelligence action=nerve_findings category=auth
hugin_intelligence action=response_intel finding_type=resp_body signal=jwt
// If JWT found:
hugin_decoder action=jwt_decode token=eyJ...
hugin_decoder action=jwt_crack token=eyJ... // HS256 dictionary attack
// Then test: alg:none, kid injection, jku injection, RS256→HS256 confusion
Phase 16: CSRF
Check state-changing endpoints for:
- No CSRF token (double-submit cookie or header)
- SameSite cookies missing on auth cookie
- Misconfigured CORS that allows CSRF via fetch
- Referer/Origin header not validated
// The scanner CSRF check covers this passively.
// For active: use intruder to replay a state-changing POST
// from a cross-origin request (no auth headers, no SameSite)
hugin_cookie_jar action=policies_list // check SameSite config
Phase 17: Sequencer (token randomness)
hugin_sequencer action=candidates body=RESPONSE_BODY // auto-detect tokens
hugin_sequencer action=capture flow_id=... token_location="body:token"
// Then: check entropy analysis
// Test: session IDs, CSRF tokens, captcha UUIDs, reset tokens, OTP codes
Predictable tokens = account takeover.
Phase 18: Upload endpoints
If file upload endpoints exist:
hugin_upload action=scan url=POST_ENDPOINT
// Tests: extension bypass, content-type mismatch, double extension,
// null-byte injection, zip-slip, polyglot generation
Phase 19: Business logic
Hugin has NO tool for this. You MUST think like the application.
Specific patterns to check manually:
- Step bypass: Jump directly to step N of an N-step workflow (register→payment→confirmation)
- Price/quantity tampering: Change numeric values in POST body
- Replay: Same request twice → double charge, duplicate action
- Mass assignment: Add extra fields
["admin":true]to POST body - Race condition on state: Concurrent checkout with same cart
- IDOR via UUID enumeration: Sequential UUIDs in booking IDs, invoice IDs
- Email/phone verification skip: Change
"verified":truein profile update - Coupon/discount abuse: Stack coupons, negative quantities, reuse single-use coupons
Phase 20: Sourcemap mining
hugin_sourcemap action=scan_with_fetch host=TARGET limit=200
// Fetches each discovered .map URL and extracts:
// - Hardcoded secrets from sourcesContent
// - API endpoint paths
// - Chunk names for predictable-name probing
Phase 21: Parameter discovery on known API endpoints
After bundle analysis gives you endpoint paths, discover hidden params:
hugin_param_discover action=run url=https://TARGET/api/endpoint
locations=["query","body_json","body_form","header"]
js_mine_url=https://TARGET/bundle.js // mine app-specific param names
This finds undocumented params (admin, debug, bypass, internal, internalUserId, testMode, dryRun).
Phase 22: Headless SPA crawl (Angular/React/Vue)
hugin_browser action=crawl url=https://SPA_URL
wait_ms=5000 max_pages=100
wait_for_angular="appName" // if Angular SPA
// Captures XHR calls the SPA makes — reveals hidden API endpoints
When to stop
Stop when ALL of these are true:
- All 22 phases have been attempted (yes, including the manual ones)
- No confirmed findings that meet the program's qualifying criteria
- Target is behind WAF that blocks every injection attempt AND no unescaped reflection point exists
- All API endpoints are parameterized AND return no data without auth
- No accounts can be created / self-registration is blocked by a precondition you can't meet
Don't stop at "scanner found nothing." The scanner covers ~55 active + ~48 passive checks. Manual thinking (Phase 19) and SPA-specific corners (Phase 11, 22) find what scanners miss.