HN
Today

Show HN: I built a site that maps the web from a bounty hunter's perspective

Neobotnet is a new web-mapping tool created by a security engineer to streamline reconnaissance for bug bounty hunters, pre-collecting vast amounts of company infrastructure data. It offers a centralized hub for subdomains, DNS records, and exposed URLs from HackerOne and Bugcrowd participants, saving users significant setup time. This Show HN post appeals to the community's appreciation for clever, niche tools that automate tedious technical tasks, enabling more efficient vulnerability discovery.

14
Score
0
Comments
#9
Highest Rank
3h
on Front Page
First Seen
Mar 25, 5:00 PM
Last Seen
Mar 25, 7:00 PM
Rank Over Time
92124

The Lowdown

Neobotnet is a novel platform developed to provide a comprehensive, pre-indexed directory of public companies participating in bug bounty programs, seen from a 'bounty hunter's perspective'. The goal is to centralize and organize publicly accessible infrastructure data, enabling security researchers to bypass the initial, time-consuming reconnaissance phase and jump straight into analysis.

  • Core Functionality: The service aggregates intelligence from major bug bounty platforms like HackerOne and Bugcrowd.
  • Data Points: It collects crucial data such as subdomains, DNS records, web servers (with status codes), indexed/crawled URLs, and will soon include JS files and exposed secrets/paths.
  • Efficiency: By providing pre-collected data, Neobotnet aims to eliminate the repetitive groundwork involved in initial asset discovery, allowing bounty hunters to focus on finding vulnerabilities.
  • Current Scale: The platform currently tracks over 40 companies, encompassing more than 63,000 web servers and 1.8 million URLs.
  • Future Vision: The creator plans to expand Neobotnet's scope to include startups relying on cloud infrastructure, helping them identify their own publicly accessible assets.
  • Accessibility: A free tier allows users to browse public company data and limited URL reconnaissance. A one-time payment option offers full CSV/JSON exports and unlimited URL data. A free sample featuring Capital One's data is available for preview.
  • Underlying Technology: The platform leverages popular open-source tools for its data collection processes.

This "Show HN" submission introduces a pragmatic solution for a common bottleneck in cybersecurity, offering a specialized tool that automates critical data collection to significantly enhance the efficiency of vulnerability assessment.