Bug Bounty Patterns 2024-2026 — network-pentest
Overview
Network-layer implications of post-2023 bug-bounty discoveries: HTTP/2 CONNECT tunneling
used for internal port-scanning, TE.0 request-smuggling as a recon primitive, and
Kubernetes SA token theft feeding classic lateral movement. Sources: PortSwigger Top 10
2024/2025, cloud-security threat data 2025. Last validated: 2026-04.
Emit findings via ../schemas/finding.json.
Pattern Index
| # | Pattern | Severity | Primary Source |
|---|---|---|---|
| P22 | HTTP/2 CONNECT-method internal port scanning | High | PortSwigger Top 10 2025 |
| P21 | TE.0 / 0.CL request smuggling as network recon primitive | Critical | PortSwigger Top 10 2024 |
| P19 | Service-Account token theft feeding lateral movement / pivoting | High | Cloud Security Threat Data 2025 |
Patterns
P22. HTTP/2 CONNECT Internal Port Scanning (Network Perspective)
- CVE / Source: PortSwigger "Top 10 2025" — "Playing with HTTP/2 CONNECT".
- Summary: HTTP/2 CONNECT requests against public LBs/gateways create raw tunnels to
authority:port, enabling internal port scanning and service discovery from outside the perimeter. Where DAST sees a single endpoint, a network-pentest lens sees an on-net pivot. - Affected surface: Perimeter load balancers (HAProxy, nginx w/ experimental H2, Envoy) with CONNECT enabled; reverse proxies exposing WebSocket-over-H2 endpoints; AWS ALB with HTTP/2 client.
- Detection (automated):
# Probe each unique public endpoint with nghttp2: nghttp -v -m 1 --header=':method: CONNECT' --header=':authority: 127.0.0.1:22' "https://$T" # Script a sweep of private ranges + common service ports: for ip in 10.0.0.{1..254}; do for port in 22 80 443 2375 5984 6379 8500 9200 11211; do nghttp -qv --header=':method: CONNECT' --header=":authority: ${ip}:${port}" "https://$T" done done - Exploitation / PoC: Successful 200 + DATA frames = tunnel open; pivot with
chisel-style forwarders or raw TCP through the H2 tunnel. - Indicators: Edge logs with CONNECT method against
:authority:in RFC1918 / loopback / metadata ranges. - Mitigation: Disable CONNECT at edge unless explicitly required; explicitly deny
:authorityto private ranges; egress filtering on LB nodes. - Cross-refs: DAST P22; cloud-security P15; CWE-441.
P21. TE.0 / 0.CL Smuggling as Network Recon Primitive
- CVE / Source: PortSwigger "Top 10 2024" — TE.0 smuggling family.
- Summary: Beyond credential theft, smuggling a request into a shared backend connection reveals internal routing behaviour (hostname-stripping proxies, internal-only routes, staging hosts). For network-pentest scope, this functions as a blackbox route enumerator.
- Affected surface: Shared front-end/back-end pairs; perimeter Cloud LBs; multi-tenant reverse proxies; internal-only hosts reachable via
X-Forwarded-Hostmanipulation. - Detection (automated):
- Run Burp's HTTP Request Smuggler against each (front-end, back-end) pair reached from your external vantage.
- Interpret findings as network-topology disclosure: smuggled
GET /with an internalHost:reveals vhost existence.
- Exploitation / PoC: See DAST P21; network recon use-case = enumerating
Host: internal-admin.corpthat front-end would not expose via its public vhost table. - Indicators: Smuggled responses carrying internal
Server:banners, error pages from services not publicly routed. - Mitigation: As DAST P21.
- Cross-refs: DAST P21; CWE-444.
P19. Service-Account Token Theft Fuelling Lateral Movement
- CVE / Source: Cloud Security Threat Data 2025 — 22% of observed cloud environments showed SA-token theft pivoting prod → financial systems.
- Summary: Once a foothold pod is achieved (via exposed service / known CVE / CI compromise), the pod's mounted SA token is stolen and reused against the K8s API from an external host — effectively turning the token into an on-net credential for the post-exploitation phase. Network pentest must include API-server reachability + TLS-SNI / IP allow-list checks.
- Affected surface: Self-hosted K8s with public API server; managed K8s with broad
master-authorized-networks/control plane CIDRallow-list; bastion hosts with static egress IPs present in allow-list. - Detection (automated):
# Network reachability of kube-apiserver from attacker vantage curl -sk "https://${APISERVER}:6443/version" # If reachable, attempt token-based read: curl -sk -H "Authorization: Bearer ${STOLEN_TOKEN}" "https://${APISERVER}:6443/api/v1/namespaces" - Exploitation / PoC: Use stolen token from compromised CI runner to drive cluster actions from attacker laptop; lateral movement from that external vantage.
- Indicators: API-server access logs with unusual source IP using existing SA token; DNS lookup of
kubernetes.default.svcfrom outside pod network. - Mitigation: Private API-server endpoint; authorized-network allow-list limited to bastion /32s; short-lived projected tokens (bound audience + exp); egress filtering on pods to block
kubernetes.default.svccalls not needed by workload. - Cross-refs: Container P19; Cloud P13; CWE-522, CWE-200.
Cross-skill links
- DAST: primary treatments of P21 and P22 —
../../dast-automation/references/bounty_patterns_2024_2026.md. - Container / Cloud: P19 originating surface —
../../container-security/references/bounty_patterns_2024_2026.md,../../cloud-security/references/bounty_patterns_2024_2026.md.