docs

Bug-bounty hunt — attack methodology

Bug-bounty hunt — attack methodology checklist

Do NOT cherry-pick. Run every phase that applies to your target stack. Each phase lists the exact Hugin MCP tool + params. If a tool is blocked (WAF, license, bug), note it and move on — don't skip the phase.

Phase 0: Pre-flight

// Confirm target is loaded and proxy is capturing
hugin_proxy_status action=health
hugin_project action=active       // confirm correct project scope
hugin_list_flows host=TARGET limit=5  // confirm flows are being captured

Known accounts? If yes, configure session profiles FIRST:

hugin_session_profiles action=capture  flow_id=...  // from a logged-in flow

If no accounts, still run every unauth phase — many bugs don't need auth.

Phase 1: Passive intelligence (no outbound reqs)

Run BEFORE any active scan so you know what the target already disclosed.

hugin_intelligence action=analyze     // process all captured flows
hugin_intelligence action=gold        // high-value aggregated: nerve+client+response
hugin_intelligence action=nerve_findings   // all param signals
hugin_intelligence action=response_intel   // secrets, internal URLs, JS configs, cookie issues
hugin_intelligence action=client_side       // postMessage handlers, DOM sinks, PP
hugin_intelligence action=cspt_scan         // client-side path traversal
hugin_intelligence action=paramhunter  // all parameter signals (21 categories)

Check every gold finding manually. Don't dismiss — verify. False positives are the norm but the ONE real finding is in there.

Phase 2: API mapping

hugin_api_map action=hosts                             // which hosts have captured flows
hugin_api_map action=map  host=TARGET include_static=false  // full API surface
hugin_bundle action=capture  host=TARGET mode=host          // JS bundles → endpoints + secrets
hugin_bundle action=endpoints  session_id=...               // extracted API paths
hugin_bundle action=secrets   session_id=...                // hardcoded creds/API keys
hugin_bundle action=promote   session_id=... probe=true     // feed endpoints to scanner

Know your stack: what framework, language, auth mechanism? Use:

hugin_fingerprint action=profile  project_id=...

Phase 3: CORS + Headers

hugin_cors action=scan  url=https://TARGET/api/public-endpoint
// Run on every unique origin (frontend, API, auth)
hugin_intelligence action=response_intel  signal=csp_wildcard

If ACAO + ACAC:true + attacker-controlled Origin → critical. Reportable.

Phase 4: Authentication & session

// Even unauth — test auth endpoints
hugin_param_discover action=run  url=POST_ENDPOINT method=POST
  locations=["query","body_json","header"]
hugin_sqli   action=test_param  flow_id=... param_name=email param_location=json_body

If login/register/reset_password: brute-force timing, user enumeration, rate-limit bypass, password reset token leakage, 2FA bypass. Use:

hugin_sequencer action=capture  flow_id=... token_location="body:token"  
  // Test CSRF tokens, reset tokens, session IDs for randomness

Phase 5: Injection — every class

Run on EVERY unique endpoint (public + 401/403 — 401 means it exists).

hugin_sqli        action=scan  host=TARGET limit=50
hugin_xss         action=scan  host=TARGET limit=50
hugin_pathtraversal action=scan  host=TARGET limit=50

For each, check the findings carefully:

  • sqli: false positives = 302/403 (WAF), same-length responses (parameterized). Real = timing differential, error message with SQL syntax.
  • xss: false positives = reflection only in JSON/JS context (escaped). Real = unescaped in HTML context, no CSP blocking.
  • pathtraversal: false positives = WAF 403. Real = /etc/passwd in response, file download.

Phase 6: WAF-aware scanning

If the target has Imperva/Cloudflare/DataDome:

// Run scanner with WAF-adaptive payloads
hugin_scanner action=start  flow_ids=[...]  config={"profile":"thorough"}

Check every finding for WAF headers (x-iinfo, x-cdn: Imperva, cf-ray, x-blocked-by). If finding response has WAF headers → false positive.

Manual WAF bypass to find unescaped reflection:

Try: <p onbeforematch=print`1`>        // bypasses Imperva
Try: <x test=1>                           // unknown tag
Try: '"><x>                               // simple breakout
Test in: URL params, POST body, headers, cookies, User-Agent

If no unescaped reflection → injection attacks are WAF-blocked. Phase is done.

Phase 7: SSRF + Server-side injection

hugin_vurl_cloud  // generate cloud metadata SSRF wordlist
// Then: discover or intruder with that wordlist against ANY endpoint that
// takes a URL/host/file parameter

Also check: URL param reflection in error messages (Cloud SSRF leak), Host header-based SSRF on redirect endpoints.

Phase 8: Authorization (BOLA / IDOR / BAC)

Requires accounts. If you have 2+ session profiles:

hugin_bac_audit action=seed_corpus  spec=...  // from API spec
hugin_bac_audit action=audit  profile_ids=["baseline","lowpriv"]
hugin_idor action=extract  flow_ids=[...]        // preview ID candidates
hugin_idor action=scan     flow_ids=[...]         // auto IDOR scan

If no accounts, still run:

hugin_authz action=scan  host=TARGET
  auth_contexts=[{name:"admin",header:"Authorization",value:"Bearer t0ken"}]
  // Tests endpoints with SINGLE auth context to see what returns data

Phase 9: GraphQL

hugin_api_spec action=discover  url=https://TARGET  spec_type=graphql

If GraphQL found:

// Introspection query (standard)
// Test batch/aliasing IDOR
// Test mutation auth bypass
// Test cost analysis / depth DoS
// Test directive injection

Note: GraphQL was NOT vulnerable on CDC hosts. But always check — it's a common hidden surface.

Phase 10: Prototype Pollution

hugin_dom_invader action=scan_pp  host=TARGET limit=500
hugin_dom_invader action=clobber  host=TARGET limit=500

If AngularJS SPA → high priority. Angular's $scope and ng-bind-html are classic PP/DOM XSS vectors. Even if scanner finds nothing, the static patterns may not catch runtime gadgets.

Phase 11: postMessage + DOM XSS

hugin_postmessage action=scan  host=TARGET limit=500
hugin_taint action=analyze_flow  flow_id=...   // for SPA HTML pages

If SPA (Angular/React/Vue): launch browser, navigate to SPA root, then run taint analysis. Static scanning won't find DOM XSS — you need real JS execution.

Phase 12: Race conditions

hugin_ratrace action=quick  url=POST_ENDPOINT method=POST
  concurrency=20 rounds=5
// Test: auth bypass, captcha reuse, token reuse, double-spend

High-value targets: reset_password/init (multiple emails), captcha solve + use (race token expiry), coupon/redeem codes, account activation, voting/rating endpoints.

Phase 13: Request smuggling

hugin_vurl_smuggle  internal_target=169.254.169.254 path=/latest/meta-data/
  public_host=TARGET
// Test CL.TE, TE.CL, TE.TE variants
// Test with different Host headers, X-Forwarded-Host, absolute-URI

If behind WAF/reverse proxy (Imperva, Cloudflare, Akamai, AWS WAF) → smuggling is possible. The WAF and backend may parse Content-Length vs Transfer-Encoding differently.

Phase 14: Open redirect

hugin_open_redirect action=scan       // passive — checks captured redirect flows
hugin_open_redirect action=scan_active  // active — probes redirect parameters

Also test with:

  • //evil.com scheme-relative
  • @evil.com userinfo confusion
  • https://trusted.com.evil.com domain confusion
  • javascript:alert(1) in redirect param
  • data:text/html,... in redirect param

Phase 15: JWT attacks

// Find JWT tokens in captured flows
hugin_intelligence action=nerve_findings  category=auth
hugin_intelligence action=response_intel  finding_type=resp_body  signal=jwt

// If JWT found:
hugin_decoder action=jwt_decode  token=eyJ...
hugin_decoder action=jwt_crack   token=eyJ...   // HS256 dictionary attack
// Then test: alg:none, kid injection, jku injection, RS256→HS256 confusion

Phase 16: CSRF

Check state-changing endpoints for:

  • No CSRF token (double-submit cookie or header)
  • SameSite cookies missing on auth cookie
  • Misconfigured CORS that allows CSRF via fetch
  • Referer/Origin header not validated
// The scanner CSRF check covers this passively.
// For active: use intruder to replay a state-changing POST
// from a cross-origin request (no auth headers, no SameSite)
hugin_cookie_jar action=policies_list  // check SameSite config

Phase 17: Sequencer (token randomness)

hugin_sequencer action=candidates  body=RESPONSE_BODY  // auto-detect tokens
hugin_sequencer action=capture  flow_id=... token_location="body:token"  
// Then: check entropy analysis

// Test: session IDs, CSRF tokens, captcha UUIDs, reset tokens, OTP codes

Predictable tokens = account takeover.

Phase 18: Upload endpoints

If file upload endpoints exist:

hugin_upload action=scan  url=POST_ENDPOINT
// Tests: extension bypass, content-type mismatch, double extension,
// null-byte injection, zip-slip, polyglot generation

Phase 19: Business logic

Hugin has NO tool for this. You MUST think like the application.

Specific patterns to check manually:

  • Step bypass: Jump directly to step N of an N-step workflow (register→payment→confirmation)
  • Price/quantity tampering: Change numeric values in POST body
  • Replay: Same request twice → double charge, duplicate action
  • Mass assignment: Add extra fields ["admin":true] to POST body
  • Race condition on state: Concurrent checkout with same cart
  • IDOR via UUID enumeration: Sequential UUIDs in booking IDs, invoice IDs
  • Email/phone verification skip: Change "verified":true in profile update
  • Coupon/discount abuse: Stack coupons, negative quantities, reuse single-use coupons

Phase 20: Sourcemap mining

hugin_sourcemap action=scan_with_fetch  host=TARGET limit=200
// Fetches each discovered .map URL and extracts:
// - Hardcoded secrets from sourcesContent
// - API endpoint paths
// - Chunk names for predictable-name probing

Phase 21: Parameter discovery on known API endpoints

After bundle analysis gives you endpoint paths, discover hidden params:

hugin_param_discover action=run  url=https://TARGET/api/endpoint
  locations=["query","body_json","body_form","header"]  
  js_mine_url=https://TARGET/bundle.js  // mine app-specific param names

This finds undocumented params (admin, debug, bypass, internal, internalUserId, testMode, dryRun).

Phase 22: Headless SPA crawl (Angular/React/Vue)

hugin_browser action=crawl  url=https://SPA_URL
  wait_ms=5000  max_pages=100
  wait_for_angular="appName"  // if Angular SPA
// Captures XHR calls the SPA makes — reveals hidden API endpoints

When to stop

Stop when ALL of these are true:

  1. All 22 phases have been attempted (yes, including the manual ones)
  2. No confirmed findings that meet the program's qualifying criteria
  3. Target is behind WAF that blocks every injection attempt AND no unescaped reflection point exists
  4. All API endpoints are parameterized AND return no data without auth
  5. No accounts can be created / self-registration is blocked by a precondition you can't meet

Don't stop at "scanner found nothing." The scanner covers ~55 active + ~48 passive checks. Manual thinking (Phase 19) and SPA-specific corners (Phase 11, 22) find what scanners miss.

Last updated 2026-07-10.