
Un espace de travail complet pour le bug bounty destiné aux chercheurs HackerOne. Comprend l'application du périmètre, un pipeline automatisé de reconnaissance et de recherche de vulnérabilités (plus de 400 outils), des modèles de rapports, des listes de surveillance CVE/CWE et un laboratoire de pratique sur VM locale. Conçu pour une chasse disciplinée et éthique.
██████╗ ███████╗██╗ ██╗ ██╗ ██████╗ ██╗██╗ ██╗
██╔══██╗██╔════╝██║ ██║███║██╔═████╗███║╚██╗██╔╝
██║ ██║█████╗ ██║ ██║╚██║██║██╔██║╚██║ ╚███╔╝
██║ ██║██╔══╝ ╚██╗ ██╔╝ ██║████╔╝██║ ██║ ██╔██╗
██████╔╝███████╗ ╚████╔╝ ██║╚██████╔╝ ██║██╔╝ ██╗
╚═════╝ ╚══════╝ ╚═══╝ ╚═╝ ╚═════╝ ╚═╝╚═╝ ╚═╝
Un espace de travail construit autour du véritable flux de travail bug bounty sur HackerOne : choisir un programme, documenter le périmètre, scanner dans les limites autorisées, enchaîner les découvertes et rédiger un rapport dans un format que les triagers acceptent rapidement. L'arsenal générique de plus de 400 outils de pentest et le labo de VM local sont disponibles en support — pas comme point d'entrée.
┌─────────────────────────────────────────────────────────────────────┐
│ │
│ SCOPE RECON/VULN REPORT │
│ ═════ ══════════ ══════ │
│ │
│ ┌───────────┐ ┌───────────────────┐ ┌───────────────┐ │
│ │programs/ │────▶ bugbounty-hunter ───▶ report.md │ │
│ │*.md │ │ .sh │ │ (H1 template) │ │
│ └───────────┘ └────────┬──────────┘ └───────┬───────┘ │
│ scope check │ │ │
│ (blocks if not ▼ ▼ │
│ documented) ┌─────────────┐ ┌──────────────┐ │
│ │auto-scanner │ │ Hacktivity │ │
│ │ (arsenal) │ │ dedup check │ │
│ └─────────────┘ └──────────────┘ │
│ │
└─────────────────────────────────────────────────────────────────────┘
cd bugbounty-lab101
chmod +x bugbounty/*.sh auto-scanner/*.sh
# If the repository was cloned without submodules:
git submodule update --init --recursive
cd bugbounty
./bugbounty-hunter.sh new program-name
# Edit ../programs/program-name.md with the EXACT scope from the H1 policy
./bugbounty-hunter.sh scope target.com # must say "Scope OK" before proceeding
./bugbounty-hunter.sh full target.com # recon -> vuln -> brute -> secrets -> api -> report
./bugbounty-hunter.sh report target.com
# Complete bugbounty/reports/target.com/report-YYYYMMDD.md with the H1 template
Avant de soumettre, lisez docs/hackerone-workflow.md (déduplication Hacktivity, qualité du rapport, étapes après soumission).
Ce labo intègre T3MP3ST comme moteur de sécurité offensive — un framework multi-agents qui transforme votre agent de codage IA en chasseur de zero-day.
# 1. Clone T3MP3ST into the lab (it's .gitignored, separate repo)
git clone https://github.com/DevCop95/T3MP3ST t3mp3st
cd t3mp3st && npm install && cd ..
# 2. Configure API keys
cp t3mp3st/.env.example t3mp3st/.env
# Edit t3mp3st/.env with your LLM provider key(s)
# 3. Start the server
./start-server.sh
# War Room → http://127.0.0.1:3333/ui/
| Fonctionnalité | Description |
|---|---|
| Interface War Room | Interface web pour la planification et l'exécution des missions |
| Moteur de reconnaissance | nmap, DNS, empreinte HTTP — 90,1 % pass@1 sur XBEN |
| Boucle d'exploitation | Chaîne de destruction à 8 opérateurs (Recon → Scanner → Exploiter → ...) |
| Base de données de payloads | Plus de 200 payloads (SQLi, XSS, SSTI, LFI, SSRF, CMDi, XXE) |
| Serveur MCP | node t3mp3st/dist/mcp-server.js pour l'intégration d'agents |
| Coffre de preuves | Suivi persistant des découvertes, preuves et retests |
T3MP3ST fonctionne sans clés API en connectant votre agent IA local (Claude Code, Codex, Hermes). Dans l'interface War Room, ouvrez Settings et connectez votre agent — puis décrivez les cibles en langage naturel.
| Commande | Description | Exemple |
|---|---|---|
bugbounty-hunter.sh new <prog> | Créer un suivi de périmètre pour un programme | ./bugbounty-hunter.sh new acme-corp |
bugbounty-hunter.sh scope <target> | Vérifier que la cible est dans le périmètre | ./bugbounty-hunter.sh scope target.com |
bugbounty-hunter.sh full <target> | Pipeline complet (de la reconnaissance au rapport) | ./bugbounty-hunter.sh full target.com |
bugbounty-hunter.sh recon <target> | Reconnaissance uniquement, incluant l'enrichissement passif Shodan CTL | ./bugbounty-hunter.sh recon target.com |
bugbounty-hunter.sh report <target> | Générer un rapport avec le modèle H1 | ./bugbounty-hunter.sh report target.com |
pentest.sh <url> | Arsenal générique (plus de 400 outils) | pentest.sh https://target.com |
pentest.sh matrix | Matrice complète d'outils | pentest.sh matrix |
pentest.sh search <function> | Rechercher un outil | pentest.sh search sql_injection |
pentest.sh express <url> | Scan express | pentest.sh express https://target.com |
pentest.sh install | Installer les outils manquants | pentest.sh install |
./start-server.sh | Démarrer la War Room T3MP3ST (assistée par IA) | ./start-server.sh |
npm run server | Démarrer T3MP3ST depuis le répertoire t3mp3st/ | cd t3mp3st && npm run server |
Toutes les commandes de scan actif dans bugbounty-hunter.sh vérifient le périmètre par rapport à programs/*.md avant de toucher la cible. L'intégration passive Shodan CTL est optionnelle et utilise le sous-module épinglé vendor/shodan_reconsx lorsque recons101x n'est pas installé. Ses noms d'hôtes sont filtrés par périmètre avant tout sondage HTTP.
╔═════════════════════════════════════════════════════════════════════════╗
║ ║
║ PHASE 1 PHASE 2 PHASE 3 PHASE 4 ║
║ RECON SCANNING ENUMERATION EXPLOITATION ║
║ ║
║ ┌───────────┐ ┌───────────┐ ┌───────────┐ ┌───────────┐ ║
║ │ nmap │─▶ nikto ──▶ enum4l ──▶ sqlmap
║ │ amass │ │ gobuster │ │ smbclnt │ │metasploit │ ║
║ │ dig │ │ whatweb │ │ ldapsrc │ │ xsser │ ║
║ │ whois │ │ wfuzz │ │ rpcclnt │ │ wpscan │ ║
║ └───────────┘ └───────────┘ └───────────┘ └───────────┘ ║
║ │ │ │ │ ║
║ ▼ ▼ ▼ ▼ ║
║ ┌───────────┐ ┌───────────┐ ┌───────────┐ ┌───────────┐ ║
║ │ theHarv │ │ dirb │ │ snmpwalk │ │ msfvenom │ ║
║ │ recon-ng │ │ ffuf │ │ nbtscan │ │ searchsp │ ║
║ └───────────┘ └───────────┘ └───────────┘ └───────────┘ ║
║ ║
╠═════════════════════════════════════════════════════════════════════════╣
║ ║
║ PHASE 5 PHASE 6 PHASE 7 PHASE 8 ║
║ BUSINESS LOGIC API TESTING CHAIN ATTACKS REPORT ║
║ ║
║ ┌───────────┐ ┌───────────┐ ┌───────────┐ ┌───────────┐ ║
║ │auth flow │ │ swagger │ │CORS+CSRF │ │ H1 │ ║
║ │race cond │ │ graphql │ │SSRF+RCE │ │ REPORT │ ║
║ │mass assn │ │ nuclei │ │IDOR+priv │ │ .md │ ║
║ └───────────┘ └───────────┘ └───────────┘ └───────────┘ ║
║ ║
╚═════════════════════════════════════════════════════════════════════════╝
┌────────────────────────────────────────────────────────────────┐
│ NETWORK SCANNING: │
│ nmap masscan zmap unicornscan │
│ netdiscover │
│ │
│ DNS ENUMERATION: │
│ dnsrecon dig host dnsenum │
│ dnsmap sublist3r subfinder subbrute │
│ dnsgen gotator fierce dnspoodle │
│ │
│ HTTP RECON: │
│ httpx httprobe gau waybackurls │
│ katana gospider hakrawler linkfinder │
│ jsfinder secretfinder paramspider arjun │
│ │
│ CLOUD RECON: │
│ s3scanner cloud_enum lazys3 bucket_finder │
│ │
│ SUBDOMAIN TAKEOVER: │
│ subjack subover nuclei canari │
└────────────────────────────────────────────────────────────────┘
┌─────────────────────────────────────────────────────────────────┐
│ SCANNERS: nikto whatweb wapiti arachni skipfish │
│ DIRECTORY BRUTE: gobuster dirb feroxbuster dirsearch │
│ FUZZING: wfuzz ffuf arjun x8 paramspider │
│ VULNERABILITIES: sqlmap xsser dalfox commix xsstrike │
│ CMS: wpscan joomscan droopescan cmseek cariddi │
└─────────────────────────────────────────────────────────────────┘
# Bug Bounty Report
## Platform
HackerOne
## Program
[program name]
## Researcher
[your-handle]
## Target
prime.example.com
## Weakness (H1 taxonomy)
CWE-538: Insertion of Sensitive Information into Externally-Accessible File
## Executive Summary
S3 bucket with listing enabled exposes N files without authentication,
including internal HR documents.
## Steps to Reproduce
1. curl -k https://prime.example.com/file-service/static/
2. ...
## Impact
[Concrete business impact, not generic]
Modèle complet dans bugbounty/templates/report-template.md.
┌─────────────────────┐
│ Choose H1 Program │
└──────────┬──────────┘
▼
┌─────────────────────┐
│ bugbounty-hunter.sh │
│ new <program> │
└──────────┬──────────┘
▼
┌─────────────────────┐
│ Document scope in │
│ programs/*.md │
└──────────┬──────────┘
▼
┌────────────────────────────────┐
│ bugbounty-hunter.sh full <t> │
└────────────────┬───────────────┘
│
┌──────────────────┼──────────────────┐
▼ ▼ ▼
┌──────────────┐ ┌──────────────┐ ┌──────────────┐
│ RECON/VULN │ │ MANUAL VERIF │ │ CHAIN ATTACK │
│ (scripts) │ │ (manual) │ │ (manual) │
└──────┬───────┘ └──────┬───────┘ └──────┬───────┘
└──────────────────┼──────────────────┘
▼
┌─────────────────────┐
│ Dedup in Hacktivity│
└──────────┬──────────┘
▼
┌─────────────────────┐
│ Submit H1 Report │
└─────────────────────┘
Méthodologie complète dans docs/hackerone-workflow.md.
legacy-vm-practice/ est à vous : des IP privées que vous lancez, aucun périmètre tiers à respecter. Utilisez-le pour apprendre de nouvelles techniques avant de les appliquer à un vrai programme.
cd legacy-vm-practice
./scripts/setup_network.sh # requires sudo
./scripts/download_vms.sh
./scripts/start_lab.sh
./scripts/verify_lab.sh
Voir legacy-vm-practice/README.md et legacy-vm-practice/docs/quickstart.md.
bugbounty-lab/
│
├── README.md # This file — overview + usage guide
│
├── programs/ # Scope tracker: one .md per H1 program
│ ├── README.md
│ └── _template.md
│
├── bugbounty/ # Core bug bounty engine
│ ├── bugbounty-hunter.sh # scope/new/recon/vuln/brute/secrets/api/report
│ ├── QUICK-REFERENCE.md # Commands, payloads, bounty by severity
│ ├── templates/report-template.md
│ └── reports/<target>/ # Output per phase + final report
│
├── auto-scanner/ # Generic arsenal (400+ tools, not H1-specific)
│ ├── pentest.sh # Unified command (incl. `pentest.sh bounty ...`)
│ ├── tools/registry.sh
│ ├── burp-integration/
│ └── reports/
│
├── docs/
│ ├── hackerone-workflow.md # H1 methodology: choose program, dedup, quality
│ ├── ai-assisted-code-review.md # AI-assisted code/JS review
│ ├── known-cve-watchlist.md # Most reported CVEs in Hacktivity
│ ├── known-cwe-watchlist.md # Most reported vuln classes in Hacktivity
│ └── recursos/learning-resources.md
│
└── legacy-vm-practice/ # Classic VM lab (DVWA, Metasploitable...)
programs/<program>.md. Tous les scanners actifs le bloquent, et il n'existe aucun contournement FORCE.bugbounty/templates/report-template.md.legacy-vm-practice/ est à vous : des IP privées que vous lancez, aucun périmètre tiers. Utilisez-le pour apprendre de nouvelles techniques.bugbounty-hunter.sh indique "No scope file"
Exécutez ./bugbounty-hunter.sh new <program> et ajoutez le domaine à la section ## In Scope du fichier généré dans programs/.
Outils manquants (subfinder, nuclei, httpx, etc.)
./auto-scanner/pentest.sh install
Le labo de VM ne démarre pas
Voir le dépannage dans legacy-vm-practice/README.md (Host-Only Adapter, NAT, pare-feu).
| Ressource | Focus |
|---|---|
| Hacker101 | CTFs + vidéos HackerOne, badges pour les programmes privés |
| HackerOne Hacktivity | Rapports publics — étudiez la qualité et évitez les doublons |
| HackerOne Directory | Choisissez un programme selon le périmètre et les statistiques de réponse |
| PortSwigger Web Security Academy | Fondamentaux techniques des vulnérabilités web |
Liste complète dans docs/recursos/learning-resources.md.
╔══════════════════════════════════════════════════════════════════════════════╗
║ ║
║ WARNING ║
║ ║
║ This lab is designed for AUTHORIZED bug bounty via HackerOne. ║
║ ║
║ Only test assets within the program's published scope ║
║ bugbounty-hunter.sh blocks targets without documented scope in programs/ ║
║ Unauthorized use of these tools is ILLEGAL ║
║ Respect each program's exclusions and special rules ║
║ Always use these tools ETHICALLY and RESPONSIBLY ║
║ ║
╚══════════════════════════════════════════════════════════════════════════════╝
┌─────────────────────────────────────────────────────────────────┐
│ │
│ RECON 200+ tools ████████████████ 100% │
│ ENUMERATION 60+ tools ██████████░░░░░░ 60% │
│ WEB 20+ tools ████░░░░░░░░░░░░ 20% │
│ EXPLOITATION 80+ tools ████████████████ 80% │
│ POST-EXPLOIT 50+ tools ████████████░░░░ 60% │
│ │
│ TOTAL: 400+ categorized tools │
│ │
└─────────────────────────────────────────────────────────────────┘
Voir CHANGELOG.md pour la liste complète des modifications.
+=============================================================+
| |
| Bug Bounty Lab • HackerOne • 400+ Tools |
| |
+=============================================================+
Bonne chasse.