Bug Bounty Checklist for Web App
Reconnaissance:
Recon on wildcard domain
Single Domain Scanning:
Manual Checking:
Configuration Management:
- Check for commonly used application and administrative URLs
- Check for old, backup, and unreferenced files
- Check HTTP methods supported and Cross-Site Tracing (XST)
- Test file extensions handling
- Test for security HTTP headers (e.g., CSP, X-Frame-Options, HSTS)
- Test for policies (e.g., Flash, Silverlight, robots)
- Test for non-production data in a live environment, and vice-versa
- Check for sensitive data in client-side code (e.g., API keys, credentials)
Secure Transmission:
Authentication:
OAuth Test Cases:
Session Management:
Authorization:
Data Validation:
Denial of Service:
Business Logic:
Cryptography:
Risky Functionality - File Uploads:
Risky Functionality - Card Payment:
HTML 5:
Happy Hacking :)