Giter Club home page Giter Club logo

bbscope's Introduction

bbscope

The ultimate scope gathering tool for HackerOne, Bugcrowd, Intigriti, Immunefi and YesWeHack by sw33tLie.

Need to grep all the large scope domains that you've got on your bug bounty platforms? This is the right tool for the job.
What about getting a list of android apps that you are allowed to test? We've got you covered as well.

Reverse engineering god? No worries, you can get a list of binaries to analyze too :)

Installation

Make sure you've a recent version of the Go compiler installed on your system. Then just run:

GO111MODULE=on go install github.com/sw33tLie/bbscope@latest

Usage

bbscope (h1|bc|it|ywh|immunefi) -t <YOUR_TOKEN> <other-flags>

How to get the session token:

  • HackerOne: login, then grab your API token here
  • Bugcrowd: login, then grab the _bugcrowd_session cookie. NOTE: This has changed, it's not the _crowdcontrol_session cookie anymore.
  • Intigriti: Get your researcher API token here
  • YesWeHack: login, then intercept a request to api.yeswehack.com and look for the Authorization: Bearer XXX header. XXX is your token
  • Immunefi: no token required

When using bbscope for HackerOne, the username flag (-u) is mandatory.

Remember that you can use the --help flag to get a description for all flags.

Examples

Below you'll find some example commands. Keep in mind that all of them work with Bugcrowd, Intigriti and YesWeHack subcommands (bc, it and ywh) as well, not just with h1.

Print all in-scope targets from all your HackerOne programs that offer rewards

bbscope h1 -t <YOUR_TOKEN> -u <YOUR_H1_USERNAME> -b -o t

The output will look like this:

app.example.com
*.user.example.com
*.demo.com
www.something.com

Print all in-scope targets from all your private Bugcrowd programs that offer rewards

bbscope bc -t <YOUR_TOKEN> -b -p -o t

Print all in-scope targets+program page URL from all Intigriti programs, including OOS elements

bbscope it -t <YOUR_TOKEN> -o tu --oos

Print all in-scope Android APKs from all your HackerOne programs

bbscope h1 -t <YOUR_TOKEN> -u <YOUR_H1_USERNAME> -o t -c android

Print all in-scope targets from all your HackerOne programs with extra data

bbscope h1 -t <YOUR_TOKEN> -u <YOUR_H1_USERNAME> -o tdu -d ", "

This will print a list of in-scope targets from all your HackerOne programs (including public ones and VDPs) but, on the same line, it will also print the target description (when available) and the program's URL. It might look like this:

something.com, Something's main website, https://hackerone.com/something
*.demo.com, All assets owned by Demo are in scope, https://hackerone.com/demo

Get program URLs for your HackerOne private programs

bbscope h1 -t <YOUR_TOKEN> -u <YOUR_H1_USERNAME> -o u -p | sort -u

You'll get a list like this:

https://hackerone.com/demo
https://hackerone.com/something

Get all immunefi scope

bbscope immunefi

Beware of scope oddities

In an ideal world, all programs use the in-scope table in the same way to clearly show what's in scope, and make parsing easy. Unfortunately, that's not always the case.

Sometimes assets are assigned the wrong category. For example, if you're going after URLs using the -c url, double checking using -c all is often a good idea.

Thanks

bbscope's People

Contributors

sw33tlie avatar pradeepch99 avatar 0xjeti avatar dee-see avatar unstabl3 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.