Have you ever wondered if collaborating on bounties is right when you are a beginner? If yes then there's a good article by zseano. He interviewed 4 hackers from his BugBountyHunt3r platform that started collaborating together. They were able to find 25...
Bug Bounty
Thoughts about a triage
There has been a lot of talk about triagers lately on Twitter. As much as I like Twitter, I don't think it's a good place to form out an idea about this situation. In my opinion, it's better to see a blogpost of a respected hacker to see what are his...
Is bug bounty good as a full-time job?
Bug bounty can be considered by many a dream job - you have no boss, you hack whenever you want and wherever you want and, of course, you make tons of money. This is a reality for some, but for many, it's not that simple. In the article "THE SHOCKING TRUTH...
How zseano approaches a new target?
There are many tips on the Internet about specific types of vulnerabilities. However, before actually exploiting anything you must first pick a target, discover the specific asset and then a specific functionality. There's little information about how to actually...
How to get started in bug bounty? feat. STÖK and NahamSec
During DEFCON, there were some nice Red Team Village livestreams on Twitch. I found one particularly interesting where NahamSec talked with STÖK about starting in bug bounty. STÖK was a guest and NahamSec was a host but he still added some valuable tips. There were...
Mistakes pentesters do in bug bounty
One more article from hakluke today: "HOW TO SUCCEED IN BUG BOUNTIES AS A PENTESTER". I like this one in particular. Why? Because I was in the exact same spot in 2019 as hakluke mentions in the article. I had 1 year of experience in pentesting, I could do a...
10 tips for beginner bug bounty hunters
Here are 10 tips from hakluke for crushing bug bounty in your first year. Watch the video here or read my notes here if you prefer. First, starting from nothing is hard. Even if you are coming from a security background, eg you were a pentester. Unlike in the video,...
Strategy for a year of bug bounties
A few issues ago I promised to cover the presentation from zseano named PUTTING YOUR MIND TO IT: BUG BOUNTIES FOR 12 MONTHS and here it is. In this talk, he gives a very concrete strategy for the whole year of bug bounty. Here are my notes: First things first You must...
5-year bug bounty journey
I really like talks like this where someone presents their whole journey. There's much more to learn from it than from 'I scored $XX,XXX bounty'. Today we will take a look at the 5-year bounty journey of shubs who made $850,000 in that period. Not doing it full-time....
Million from bug bounty in 4 Years
Ozgur Alp lately passed $1 mln earned from bounties. That's a huge achievement. Thankfully for us, he decided to write a blogpost with a few tips about how to follow in his footsteps. I do encourage you to read the whole article but here are my most important...