September 27, 2026
100 Days of Bug Bounty โ Day 6 ๐
Day 6 was mostly about wrapping up the reconnaissance phase and cleaning up the attack surface.

By Zubair Ahmed
I started by checking the different subdomains for TLS/SSL configuration issues, going through certificates and configurations to see if anything interesting stood out. Nothing meaningful came up.
During the process, I came across a Grafana-related subdomain. It initially looked interesting, but the endpoint wasn't actually accessible and was showing a CloudFront-related error. I dug into it a little further and found some historical references through the Wayback Machine, but nothing useful could be reached in the current setup.
I also checked GitHub for the usual things: exposed credentials, secrets, configuration files, API keys, and other potentially sensitive information. Thankfully, nothing interesting turned up there either.
One important part of today was cleaning up my reconnaissance results. I went back through the Nginx subdomains I found earlier and filtered out the ones that appeared to be noise or separate infrastructure. After removing those, I was left with a much cleaner list of subdomains that actually appear to be live and relevant applications.
After several days of reconnaissance, I think I've finally mapped the attack surface well enough.
Recon is done. Now it's time to move on to the actual applications.
Day 6 complete.
94 days to go.