
HackerOne शोधकर्ताओं के लिए एक पूर्ण बग बाउंटी कार्यक्षेत्र। इसमें स्कोप प्रवर्तन, स्वचालित रिकॉन/वल्न पाइपलाइन (400+ टूल्स), रिपोर्ट टेम्पलेट्स, CVE/CWE वॉचलिस्ट, और एक स्थानीय VM अभ्यास लैब शामिल है। अनुशासित, नैतिक शिकार के लिए निर्मित।
██████╗ ███████╗██╗ ██╗ ██╗ ██████╗ ██╗██╗ ██╗
██╔══██╗██╔════╝██║ ██║███║██╔═████╗███║╚██╗██╔╝
██║ ██║█████╗ ██║ ██║╚██║██║██╔██║╚██║ ╚███╔╝
██║ ██║██╔══╝ ╚██╗ ██╔╝ ██║████╔╝██║ ██║ ██╔██╗
██████╔╝███████╗ ╚████╔╝ ██║╚██████╔╝ ██║██╔╝ ██╗
╚═════╝ ╚══════╝ ╚═══╝ ╚═╝ ╚═════╝ ╚═╝╚═╝ ╚═╝
यह एक वर्कस्पेस है जो HackerOne पर वास्तविक बग बाउंटी वर्कफ़्लो के इर्द-गिर्द बनाया गया है: एक प्रोग्राम चुनें, स्कोप का दस्तावेज़ीकरण करें, सीमाओं के भीतर स्कैन करें, निष्कर्षों को श्रृंखलाबद्ध करें, और ऐसे प्रारूप में रिपोर्ट करें जिसे ट्राइएजर तेज़ी से स्वीकार करते हैं। 400+ सामान्य पेंटेस्टिंग शस्त्रागार और स्थानीय VM लैब सहायता के रूप में उपलब्ध हैं — प्रवेश बिंदु के रूप में नहीं।
┌─────────────────────────────────────────────────────────────────────┐
│ │
│ SCOPE RECON/VULN REPORT │
│ ═════ ══════════ ══════ │
│ │
│ ┌───────────┐ ┌───────────────────┐ ┌───────────────┐ │
│ │programs/ │────▶ bugbounty-hunter ───▶ report.md │ │
│ │*.md │ │ .sh │ │ (H1 template) │ │
│ └───────────┘ └────────┬──────────┘ └───────┬───────┘ │
│ scope check │ │ │
│ (blocks if not ▼ ▼ │
│ documented) ┌─────────────┐ ┌──────────────┐ │
│ │auto-scanner │ │ Hacktivity │ │
│ │ (arsenal) │ │ dedup check │ │
│ └─────────────┘ └──────────────┘ │
│ │
└─────────────────────────────────────────────────────────────────────┘
cd bugbounty-lab101
chmod +x bugbounty/*.sh auto-scanner/*.sh
# If the repository was cloned without submodules:
git submodule update --init --recursive
cd bugbounty
./bugbounty-hunter.sh new program-name
# Edit ../programs/program-name.md with the EXACT scope from the H1 policy
./bugbounty-hunter.sh scope target.com # must say "Scope OK" before proceeding
./bugbounty-hunter.sh full target.com # recon -> vuln -> brute -> secrets -> api -> report
./bugbounty-hunter.sh report target.com
# Complete bugbounty/reports/target.com/report-YYYYMMDD.md with the H1 template
सबमिट करने से पहले, docs/hackerone-workflow.md पढ़ें (Hacktivity डिडुप, रिपोर्ट गुणवत्ता, सबमिशन के बाद के चरण)।
यह लैब T3MP3ST को अपने आक्रामक सुरक्षा इंजन के रूप में एकीकृत करती है — एक मल्टी-एजेंट फ्रेमवर्क जो आपके AI कोडिंग एजेंट को ज़ीरो-डे शिकारी में बदल देता है।
# 1. Clone T3MP3ST into the lab (it's .gitignored, separate repo)
git clone https://github.com/DevCop95/T3MP3ST t3mp3st
cd t3mp3st && npm install && cd ..
# 2. Configure API keys
cp t3mp3st/.env.example t3mp3st/.env
# Edit t3mp3st/.env with your LLM provider key(s)
# 3. Start the server
./start-server.sh
# War Room → http://127.0.0.1:3333/ui/
T3MP3ST आपके स्थानीय AI एजेंट (Claude Code, Codex, Hermes) को कनेक्ट करके API कुंजियों के बिना काम करता है। War Room UI में, Settings खोलें और अपना एजेंट कनेक्ट करें — फिर सादे अंग्रेज़ी में लक्ष्यों का वर्णन करें।
bugbounty-hunter.sh में सभी सक्रिय स्कैनिंग कमांड लक्ष्य को छूने से पहले programs/*.md के विरुद्ध स्कोप सत्यापित करते हैं। पैसिव Shodan CTL एकीकरण वैकल्पिक है और जब recons101x इंस्टॉल नहीं है तो पिन किए गए vendor/shodan_reconsx सबमॉड्यूल का उपयोग करता है। किसी भी HTTP प्रोबिंग से पहले इसके होस्टनाम स्कोप-फ़िल्टर किए जाते हैं।
╔═════════════════════════════════════════════════════════════════════════╗
║ ║
║ PHASE 1 PHASE 2 PHASE 3 PHASE 4 ║
║ RECON SCANNING ENUMERATION EXPLOITATION ║
║ ║
║ ┌───────────┐ ┌───────────┐ ┌───────────┐ ┌───────────┐ ║
║ │ nmap │─▶ nikto ──▶ enum4l ──▶ sqlmap
║ │ amass │ │ gobuster │ │ smbclnt │ │metasploit │ ║
║ │ dig │ │ whatweb │ │ ldapsrc │ │ xsser │ ║
║ │ whois │ │ wfuzz │ │ rpcclnt │ │ wpscan │ ║
║ └───────────┘ └───────────┘ └───────────┘ └───────────┘ ║
║ │ │ │ │ ║
║ ▼ ▼ ▼ ▼ ║
║ ┌───────────┐ ┌───────────┐ ┌───────────┐ ┌───────────┐ ║
║ │ theHarv │ │ dirb │ │ snmpwalk │ │ msfvenom │ ║
║ │ recon-ng │ │ ffuf │ │ nbtscan │ │ searchsp │ ║
║ └───────────┘ └───────────┘ └───────────┘ └───────────┘ ║
║ ║
╠═════════════════════════════════════════════════════════════════════════╣
║ ║
║ PHASE 5 PHASE 6 PHASE 7 PHASE 8 ║
║ BUSINESS LOGIC API TESTING CHAIN ATTACKS REPORT ║
║ ║
║ ┌───────────┐ ┌───────────┐ ┌───────────┐ ┌───────────┐ ║
║ │auth flow │ │ swagger │ │CORS+CSRF │ │ H1 │ ║
║ │race cond │ │ graphql │ │SSRF+RCE │ │ REPORT │ ║
║ │mass assn │ │ nuclei │ │IDOR+priv │ │ .md │ ║
║ └───────────┘ └───────────┘ └───────────┘ └───────────┘ ║
║ ║
╚═════════════════════════════════════════════════════════════════════════╝
┌────────────────────────────────────────────────────────────────┐
│ NETWORK SCANNING: │
│ nmap masscan zmap unicornscan │
│ netdiscover │
│ │
│ DNS ENUMERATION: │
│ dnsrecon dig host dnsenum │
│ dnsmap sublist3r subfinder subbrute │
│ dnsgen gotator fierce dnspoodle │
│ │
│ HTTP RECON: │
│ httpx httprobe gau waybackurls │
│ katana gospider hakrawler linkfinder │
│ jsfinder secretfinder paramspider arjun │
│ │
│ CLOUD RECON: │
│ s3scanner cloud_enum lazys3 bucket_finder │
│ │
│ SUBDOMAIN TAKEOVER: │
│ subjack subover nuclei canari │
└────────────────────────────────────────────────────────────────┘
# Bug Bounty Report
## Platform
HackerOne
## Program
[program name]
## Researcher
[your-handle]
## Target
prime.example.com
## Weakness (H1 taxonomy)
CWE-538: Insertion of Sensitive Information into Externally-Accessible File
## Executive Summary
S3 bucket with listing enabled exposes N files without authentication,
including internal HR documents.
## Steps to Reproduce
1. curl -k https://prime.example.com/file-service/static/
2. ...
## Impact
[Concrete business impact, not generic]
पूरा टेम्पलेट bugbounty/templates/report-template.md पर।
┌─────────────────────┐
│ Choose H1 Program │
└──────────┬──────────┘
▼
┌─────────────────────┐
│ bugbounty-hunter.sh │
│ new <program> │
└──────────┬──────────┘
▼
┌─────────────────────┐
│ Document scope in │
│ programs/*.md │
└──────────┬──────────┘
▼
┌────────────────────────────────┐
│ bugbounty-hunter.sh full <t> │
└────────────────┬───────────────┘
│
┌──────────────────┼──────────────────┐
▼ ▼ ▼
┌──────────────┐ ┌──────────────┐ ┌──────────────┐
│ RECON/VULN │ │ MANUAL VERIF │ │ CHAIN ATTACK │
│ (scripts) │ │ (manual) │ │ (manual) │
└──────┬───────┘ └──────┬───────┘ └──────┬───────┘
└──────────────────┼──────────────────┘
▼
┌─────────────────────┐
│ Dedup in Hacktivity│
└──────────┬──────────┘
▼
┌─────────────────────┐
│ Submit H1 Report │
└─────────────────────┘
पूरी कार्यप्रणाली docs/hackerone-workflow.md पर।
legacy-vm-practice/ आपका है: निजी IP जिन्हें आप स्पिन अप करते हैं, सम्मान करने के लिए कोई तृतीय-पक्ष स्कोप नहीं। किसी वास्तविक प्रोग्राम पर लागू करने से पहले नई तकनीकें सीखने के लिए इसका उपयोग करें।
cd legacy-vm-practice
./scripts/setup_network.sh # requires sudo
./scripts/download_vms.sh
./scripts/start_lab.sh
./scripts/verify_lab.sh
देखें legacy-vm-practice/README.md और legacy-vm-practice/docs/quickstart.md।
bugbounty-lab/
│
├── README.md # This file — overview + usage guide
│
├── programs/ # Scope tracker: one .md per H1 program
│ ├── README.md
│ └── _template.md
│
├── bugbounty/ # Core bug bounty engine
│ ├── bugbounty-hunter.sh # scope/new/recon/vuln/brute/secrets/api/report
│ ├── QUICK-REFERENCE.md # Commands, payloads, bounty by severity
│ ├── templates/report-template.md
│ └── reports/<target>/ # Output per phase + final report
│
├── auto-scanner/ # Generic arsenal (400+ tools, not H1-specific)
│ ├── pentest.sh # Unified command (incl. `pentest.sh bounty ...`)
│ ├── tools/registry.sh
│ ├── burp-integration/
│ └── reports/
│
├── docs/
│ ├── hackerone-workflow.md # H1 methodology: choose program, dedup, quality
│ ├── ai-assisted-code-review.md # AI-assisted code/JS review
│ ├── known-cve-watchlist.md # Most reported CVEs in Hacktivity
│ ├── known-cwe-watchlist.md # Most reported vuln classes in Hacktivity
│ └── recursos/learning-resources.md
│
└── legacy-vm-practice/ # Classic VM lab (DVWA, Metasploitable...)
programs/<program>.md में In Scope के रूप में प्रलेखित न हो। सभी सक्रिय स्कैनर इसे ब्लॉक करते हैं, और कोई FORCE बायपास नहीं है।bugbounty/templates/report-template.md में चेकलिस्ट देखें।legacy-vm-practice/ आपका है: निजी IP जिन्हें आप स्पिन अप करते हैं, कोई तृतीय-पक्ष स्कोप नहीं। नई तकनीकें सीखने के लिए इसका उपयोग करें।bugbounty-hunter.sh कहता है "No scope file"
./bugbounty-hunter.sh new <program> चलाएँ और programs/ में जनरेट की गई फ़ाइल के ## In Scope अनुभाग में डोमेन जोड़ें।
अनुपलब्ध टूल (subfinder, nuclei, httpx, आदि)
./auto-scanner/pentest.sh install
VM लैब शुरू नहीं हो रही
legacy-vm-practice/README.md में समस्या निवारण देखें (Host-Only Adapter, NAT, फ़ायरवॉल)।
पूरी सूची docs/recursos/learning-resources.md पर।
╔══════════════════════════════════════════════════════════════════════════════╗
║ ║
║ WARNING ║
║ ║
║ This lab is designed for AUTHORIZED bug bounty via HackerOne. ║
║ ║
║ Only test assets within the program's published scope ║
║ bugbounty-hunter.sh blocks targets without documented scope in programs/ ║
║ Unauthorized use of these tools is ILLEGAL ║
║ Respect each program's exclusions and special rules ║
║ Always use these tools ETHICALLY and RESPONSIBLY ║
║ ║
╚══════════════════════════════════════════════════════════════════════════════╝
┌─────────────────────────────────────────────────────────────────┐
│ │
│ RECON 200+ tools ████████████████ 100% │
│ ENUMERATION 60+ tools ██████████░░░░░░ 60% │
│ WEB 20+ tools ████░░░░░░░░░░░░ 20% │
│ EXPLOITATION 80+ tools ████████████████ 80% │
│ POST-EXPLOIT 50+ tools ████████████░░░░ 60% │
│ │
│ TOTAL: 400+ categorized tools │
│ │
└─────────────────────────────────────────────────────────────────┘
परिवर्तनों की पूरी सूची के लिए CHANGELOG.md देखें।
+=============================================================+
| |
| Bug Bounty Lab • HackerOne • 400+ Tools |
| |
+=============================================================+
शुभ शिकार।
| विशेषता | विवरण |
|---|
| War Room UI | मिशन योजना और निष्पादन के लिए वेब इंटरफ़ेस |
| Recon Engine | nmap, DNS, HTTP फिंगरप्रिंटिंग — XBEN पर 90.1% pass@1 |
| Exploit Loop | 8-ऑपरेटर किल चेन (Recon → Scanner → Exploiter → ...) |
| Payload DB | 200+ पेलोड (SQLi, XSS, SSTI, LFI, SSRF, CMDi, XXE) |
| MCP Server | एजेंट एकीकरण के लिए node t3mp3st/dist/mcp-server.js |
| Evidence Vault | स्थायी निष्कर्ष, साक्ष्य, और रीटेस्ट ट्रैकिंग |
| कमांड | विवरण | उदाहरण |
|---|
bugbounty-hunter.sh new <prog> | प्रोग्राम के लिए स्कोप ट्रैकर बनाएं | ./bugbounty-hunter.sh new acme-corp |
bugbounty-hunter.sh scope <target> | सत्यापित करें कि लक्ष्य स्कोप में है | ./bugbounty-hunter.sh scope target.com |
bugbounty-hunter.sh full <target> | पूर्ण पाइपलाइन (रिकॉन से रिपोर्ट तक) | ./bugbounty-hunter.sh full target.com |
bugbounty-hunter.sh recon <target> | केवल रिकॉन, पैसिव Shodan CTL संवर्धन सहित | ./bugbounty-hunter.sh recon target.com |
bugbounty-hunter.sh report <target> | H1 टेम्पलेट के साथ रिपोर्ट जनरेट करें | ./bugbounty-hunter.sh report target.com |
pentest.sh <url> | सामान्य शस्त्रागार (400+ टूल) | pentest.sh https://target.com |
pentest.sh matrix | पूर्ण टूल मैट्रिक्स | pentest.sh matrix |
pentest.sh search <function> | टूल खोजें | pentest.sh search sql_injection |
pentest.sh express <url> | एक्सप्रेस स्कैन | pentest.sh express https://target.com |
pentest.sh install | अनुपलब्ध टूल इंस्टॉल करें | pentest.sh install |
./start-server.sh | T3MP3ST War Room शुरू करें (AI-संचालित) | ./start-server.sh |
npm run server | t3mp3st/ डायरेक्टरी से T3MP3ST शुरू करें | cd t3mp3st && npm run server |
┌─────────────────────────────────────────────────────────────────┐
│ SCANNERS: nikto whatweb wapiti arachni skipfish │
│ DIRECTORY BRUTE: gobuster dirb feroxbuster dirsearch │
│ FUZZING: wfuzz ffuf arjun x8 paramspider │
│ VULNERABILITIES: sqlmap xsser dalfox commix xsstrike │
│ CMS: wpscan joomscan droopescan cmseek cariddi │
└─────────────────────────────────────────────────────────────────┘
| संसाधन | फोकस |
|---|
| Hacker101 | CTF + HackerOne वीडियो, निजी प्रोग्राम के लिए बैज |
| HackerOne Hacktivity | सार्वजनिक रिपोर्ट — गुणवत्ता का अध्ययन करें और डुप्लिकेट से बचें |
| HackerOne Directory | स्कोप और प्रतिक्रिया आँकड़ों के अनुसार प्रोग्राम चुनें |
| PortSwigger Web Security Academy | वेब भेद्यताओं की तकनीकी मूल बातें |