How I Found a $5,500 Bug Using Just Reconnaissance
Most bug hunters rush straight to exploitation techniques. Flashy payloads, complex attacks, advanced tools. But my biggest bug bounty payout came from something much simpler: patient observation. Photo by Fotis Fotopoulos on Unsplash Let me show you how reconnaissance — often seen as the boring first step — became the entire game. Defining the Battlefield The program was for a large tech company (let’s call them “TechFlow Inc.”). Their scope was clear: *.techflow-example.com. Bounties ranged from $500 to $10,000. My goal wasn’t to attack anything. It was to understand their digital footprint completely. This is where passive recon and subdomain enumeration always begin. My Reconnaissance Methodology Walkthrough Phase 1 — Discovery: Mapping the Territory My toolkit for this phase is straightforward: Amass and Subfinder for subdomain discovery crt.sh for certificate transparency logs waybackurls for historical data One command to start: subfinder -d techflow-example.com -silent | httpx -silent > subs.txt Over 800 subdomains were gathered. Most were typical: www, blog, api, staging. But one stood out like a quiet signal in the noise: internal-dashboard.techflow-example.com Why would an “internal” dashboard be publicly accessible? Curiosity was officially piqued. Phase 2 — Probing & Validation: First, life check: echo "internal-dashboard.techflow-example.com" | httpx -title -status-code Result: 200 OK with title “TechFlow Internal Panel”. Next, DNS check: dig A internal-dashboard.techflow-example.com No CDN detected. This was hitting their origin server directly — already a questionable find. Phase 3 — Content Discovery Time for light directory checking with ffuf: ffuf -u https://internal-dashboard.techflow-example.com/FUZZ -w ~/wordlists/common.txt -t 50 Within seconds: /admin-config.json [Status: 200, Size: 512] My heartbeat might have skipped. Configuration files in an admin Directives are rarely good news. A Critical Configuration Exposure Navigating to that URL revealed a JSON file left wide open: { "database": { "host": "prod-db.techflow-internal.net", "username": "admin_prod", "password": "T3chFl0w2023!Secure?" }, "aws_keys": { "access_key": "AKIAEXAMPLEKEY", "secret": "wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY" }, "environment": "production" } This wasn’t just information disclosure — this was exposed secrets in their most dangerous form. Why was a critical vulnerability: Production credentials were publicly accessible Database root access was potentially compromised AWS keys could lead to cloud resource takeover Compliance violation for data protection standards The impact was immediate and severe. And I hadn’t run a single exploit — just observation. The Reporting & Reward I stopped all testing immediately. Ethical disclosure means finding, not exploiting. My report structure: Clear title: “Public Exposure of Production Credentials via Internal Dashboard.” Affected asset: https://internal-dashboard.techflow-example.com/admin-config.json Evidence: Masked screenshots and code blocks Impact analysis: Business risk assessment Recommendation: Rotate all exposed secrets immediately 48 hours later, the triage team responded: “ Confirmed as a critical security misconfiguration. The file has been removed, and all affected credentials have been rotated. Thank you for your responsible disclosure. ” Award: $5,500. The earnings were substantial, but the validation was better: Methodical reconnaissance works. Lessons Learned (The Real Treasure) Reconnaissance > Exploitation for early-stage bug hunting The quiet phase often reveals the loudest findings. Forgotten assets are low-hanging fruit Old subdomains, backup files, and “internal” systems are routinely overlooked. You don’t need to exploit to earn Finding and responsibly reporting is enough — and it’s safer for everyone. Documentation is part of the methodology Clear reports with business impact get faster triage and better rewards. My Go-To Reconnaissance Toolkit Subfinder/Amass — Subdomain discovery httpx — HTTP probing and validation ffuf — Directory and content discovery crt.sh — Certificate transparency searches waybackurls — Historical endpoint gathering Each tool has one job. Together, they build a complete picture. The Quiet Truth About Bug Hunting Reconnaissance is often skipped because it feels passive. No immediate gratification. No complex techniques. But here’s the secret: The most valuable findings are often just waiting to be discovered. That “boring” first step? It’s where the real bug bounty gems are hidden. What’s your favorite recon tool or method? Share in the comments — let’s learn from each other’s quiet discoveries. How I Found a $5,500 Bug Using Just Reconnaissance was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.