#bug-bounty

1 messages · Page 5 of 1

obtuse fern
#

You don't need to be expert , but you need to be familiar

weary siren
#

Is there a software learning channel you recommend?

weary siren
uneven galeBOT
#

Gave +1 Rep to @obtuse fern (current: #13 - 588)

obtuse fern
weary siren
obtuse fern
humble goblet
#

I'm open for collab 🙂

humble goblet
#

yes after becoming familiar with HTML/CSS/JS/PHP learn bash

lone vessel
late compass
#

hey guys

#

any bounty hunter here

torpid hemlock
#

Hi guys you have any ideas for ai pentesting?

lilac spindle
#

It is directed towards LLMs though.

river sigil
#

there is path bug bounty in tryhackme?

obtuse fern
wide creek
#

(fell into my lap while researching the OWASP top 10 for LLMs)

sonic mountain
#

i have just started myself , i was looking around and found Hackerone maybe you might find some good info there

formal sonnet
late compass
#

hey

#

how leaderboard points works?

#

my points are stuck at 243 for 2 days

obtuse fern
late compass
#

overall is fine. i have figured it out

obtuse fern
late compass
#

my points were 243 and still 243 i have solved like 5 or 6 rooms afterthat

obtuse fern
late compass
obtuse fern
late compass
#

i did sql injection lab, splunk, sql injection, advance sql injection, sql map

obtuse fern
#

They aren't counted 🙂

#

They are counted for overall score only 🙂

late compass
#

ohhh okay

#

only ctfs

#

got it

obtuse fern
ruby skiff
#

Scope?

fallen palm
#

you mean for subdomain enumeration or content discovery?

timber tusk
#

Usually you just have to check your scope. If you are tasked to enumerate on your own, its more a pentest then bug bounty.

ruby skiff
#

No I was asking for you to link the scope you have been given

#

If it's a bug bounty program it will be public

drowsy steeple
#

Im not sure for your particular case but if i remember correctly python had some library that would scrap every element of a page or more accurately to say it would download the html in the same format youd see it in dev tools , if thats what youre looking for

uneven galeBOT
#

Gave +1 Rep to @drowsy steeple (current: #2503 - 1)

fallen palm
#

that SUPPOSED is never feasible. Any resource can be inaccessible at any time but OK. The only way to determine if that resource is available on the server is to actively accessing it (scrapping it).

lilac spindle
#

You will do crawling.

uneven galeBOT
#

Gave +1 Rep to @lilac spindle (current: #22 - 440)

silent fox
fallen palm
#

Hi , I'm new in bug bounty , any advice ?

obtuse fern
jaunty ingot
brave umbra
#

Hi guys, I saw a video about bug bounty hunting and was instantly hooked. Although I'm still a beginner when it comes to coding and cyber security overall, I plan on working towards a skill set that allows me to partake in bug bounty hunting one day.

#

Does somebody have real experience in bug bounty hunting and can say something about the skills necessary and the preparation process?

lilac spindle
#

Portswigger Web Academy is good enough for gaining the required technical skills

#

Other than that, reconnaissance/fuzzing plays a big part in finding vulnerabilities. IMO, this comes from having a methodology and understanding what to find. For example, you have an IIS web server, one methodology is to run a “short scan” which is to do directory bruteforce on short names which is largely due to the IIS shortname file disclosure vulnerability.

#

You can pick up some cool tips and tricks from Youtube of other bug bounty hunters

#

Lastly, you need to understand vulnerabilities well and be able to appropriately score them based on risk and have the necessary writing skills to say what you want to say to the client

brave umbra
#

Thank you very much @lilac spindle

uneven galeBOT
#

Gave +1 Rep to @lilac spindle (current: #21 - 441)

brave umbra
#

I'll look into everything you said

#

My goal is to find a bug in 2025

#

Doesn't even have to be financially rewarded

astral pond
#

After learning a topic on tryhackme for example xss or IDOR you can go to Portswigger lab to test your skills.

zenith bluff
brave umbra
#

Thanks folks, I love this community

#

I started my learning path in cyber security at the beginning of this month and was amazed at how helpful the members of this community are

astral pond
brave umbra
#

I was stuck in multiple instances but there were always people to help me out, I'm blessed

fallen palm
obtuse fern
fallen palm
uneven galeBOT
#

Gave +1 Rep to @obtuse fern (current: #5 - 1506)

tacit yacht
#

I am new to cyber security and i am learning everything I can and i want to get into bug bounty what would is the best way to get started for bug bounty?

tacit yacht
#

ok I will start there thank you

uneven galeBOT
#

Gave +1 Rep to @modest marsh (current: #1663 - 2)

tacit yacht
#

Thank you I will do what I can to learn as much as I i can from what you have shared

uneven galeBOT
#

Gave +1 Rep to @modest marsh (current: #1249 - 3)

hexed pelican
#

heyy

#

anyone wanna team up? I've recently started learning bug bounty, i need someone with intermediate or more than that skills, so that he/she can show me some real time bug hunting and help me...

obtuse fern
#

Burp Scanner / ZAP

thick quartz
#

I suggest Zap since it’s free and has almost the same features

obtuse fern
#

Why would you do that 🙂 ?

uneven galeBOT
#

Gave +1 Rep to @obtuse fern (current: #5 - 1811)

fallen palm
#

I'd use caido if you dont want to pay for burpsuite

neat finch
#

Hey guys I have a goal to earn enough money from bug bounty so I started doing it but failed miserably due to lack of knowledge I did learn some stuff before getting into bug bounty but that's not much of a help so again I made a path for myself that is 1. Reach the max "legend level" (right now: hacker level 8) in tryhackme then solve the hacker101 CTF then do bug bounty on a private program but I'm not sure if it's a good idea or not ?

obtuse fern
neat finch
obtuse fern
neat finch
#

Can you recommend me some site or place to get latest writeups

#

Or disclosed programme 🙏

#

I'm a little confused 😕

obtuse fern
cerulean juniper
#

Google also has a Bug Bounty program and it also shows you the reports that were submitted and there's ton of information out there on their site

neat finch
#

Thanks ❤️

wanton escarp
#

How long did it take for you to find your first bounty? I just started in November, but it still seems unlikely that I will find something others haven't found yet. I feel the disbelief I think all beginners have. I know its not a sprint

obtuse fern
neat finch
uneven galeBOT
#

Gave +1 Rep to @scenic hill (current: #2578 - 1)

scenic hill
#

Wouldn't forming a group for bug bounties be more efficient rather than trying to solo them? I assume the biggest hurdle for a group hunt is splitting the money IF you even get any.

grizzled abyss
ebon tapir
obtuse fern
#

-t - threads . Threads are independent sequences of execution within a program, allowing multiple tasks to run at the same time, which in Gobuster case means making multiple requests at the same time to speed up the proccess 🙂 .

#

Should be 10 but i am not 100% sure

uneven galeBOT
#

Gave +1 Rep to @obtuse fern (current: #4 - 1955)

frail compass
obtuse fern
uneven galeBOT
#

Gave +1 Rep to @frail compass (current: #207 - 35)

frail compass
#

some articles might be a bit dated but was a good resource in my queue

obtuse fern
uneven galeBOT
#

Gave +1 Rep to @frail compass (current: #203 - 36)

pulsar knot
#

Hello

does anyone here use screaming frog SEO spider in ubuntu?

wanton escarp
#

I'm very uncertain about how to best approach learning bug hunting when the field is so broad. What did you do when you were learning? Was it like focusing on one subject or bug per week to study and then moving to another the next week, or was it just a mix of everything?

obtuse fern
steep kraken
#

Ello chat

#

Any tips for beginner bug bounty hunters (<- this guy)

obtuse fern
steep kraken
#

Okayy

#

Feelin overwhelmed, have been training for a while but don't wanna mess it up

obtuse fern
steep kraken
#

V true
I love finding exciting bugs, monetary gain aside

#

I'm assuming you've done bug bounties in the past. I also assume it's 99% research, 0.5% execution and 0.5% retrying

#

How has your experience been if I may ask?

obtuse fern
steep kraken
#

I see, I see

#

Hope your journey goes well too!

obtuse fern
uneven galeBOT
#

Gave +1 Rep to @steep kraken (current: #777 - 6)

steep kraken
uneven galeBOT
#

Gave +1 Rep to @obtuse fern (current: #3 - 2122)

obtuse fern
#

Probably the problem isn't on your side , this Burp's CSRF ( and generally client-side vuln. labs ) can be buggy and won't work on a first try . Wait for a lab to restart and try again , it happend to me multiple times 🙂

#

The problem is that bot "have some problems with clicking on links" 😄 . Also as Portswigger suggests try to use Chrome if possible 🙂

ancient wing
#

Hi, I'm participating in a bug bounty program🙂 . I'm still new to this and haven't had much luck so far. I found my target through the program and performed an ICMP Echo request to get its IP address. I was able to access the target website using the IP address (https: //IP), which is part of a Class B network. During my passive reconnaissance, I also discovered other hosts within the same IP range during passive recon and I want to continue test them because they are running on Windows 10 IIS servers without domain name.
However, the bug bounty program only lists the target domain names and not any specific IP addresses.
Will I be within scope if i continue ?

obtuse fern
ancient wing
uneven galeBOT
#

Gave +1 Rep to @obtuse fern (current: #3 - 2174)

obtuse fern
#

Yeah , client side rooms definitely have some problems with bot . Sometimes it took me 3-4 times doing literally the exact same thing in order for it to work out 😄 . Also try to use Chrome if possible 😄

uneven galeBOT
#

Gave +1 Rep to @obtuse fern (current: #3 - 2183)

meager bane
#

Hi everyone, How we all Doen...?

obtuse fern
uneven galeBOT
#

Gave +1 Rep to @meager bane (current: #1293 - 3)

meager bane
#

I Have a question here, I want to focus on Bug bounties so that I will not have to be presenting Resumes and cover letters applying for Jobs, this is because I dont have any years of Experience, And I believe with bug bounties I can still make small income and gain my experience over time, What Resources do you thing I Need to focus on more to successful in this path as Fast as possible. And can I also be participating in the real Bounties while learning or I need to be grounded first. Cos really sometimes I feel like I am doing some irrelevant stuffs that are not in line with that path. @obtuse fern I will need your inputs here please.

obtuse fern
meager bane
uneven galeBOT
#

Gave +1 Rep to @obtuse fern (current: #2 - 2349)

obtuse fern
uneven galeBOT
#

Gave +1 Rep to @obtuse fern (current: #2 - 2350)

meager bane
#

Hi can we use sublister for THM challenges

obtuse fern
meager bane
uneven galeBOT
#

Gave +1 Rep to @obtuse fern (current: #2 - 2356)

arctic acorn
#

Tfw when you find a critical bug which leaks db creds, but it's on some pest control website with no VDP kekw

#

so frustrating

steep kraken
#

Bug booty program

arctic acorn
#

its like "contact x number for pest control services", but the site uses wordpress with a lot of exposed endpoints

steep kraken
#

Of course it's wordpress

#

I enumerated the usernames on one of my ol' clients' website because their plugins were outdated

#

I told them about it, and they said, "We don't have a need to update the plugins."

#

I was like, "ok 😐👍"

arctic acorn
#

Sure, until someone gets RCE with them kekw

#

/j, but still that's wild

steep kraken
#

Whenever I find a wordpress website, I become happy

#

Because I know there's gonna be a ton of bugs

hybrid orchid
#

Does that strike you as likely?

arctic acorn
hybrid orchid
#

... The visuals... Of a server technology?

arctic acorn
#

Yes, I don't know exactly how to explain it

fallen palm
#

Hey guys, I currently can’t upload pictures but I just opened HackerOne where it says gold standard $200-$2M what does that even mean? Please don’t laugh 😆 but is the gold like a type of currency thing on there. No one’s actually getting paid 2million dollars right

ember vigil
#

no one is getting paid $2 for a bug

#

that is collectively cumulative amount

fallen palm
#

No it says $200 to 2 million

#

Oh

ember vigil
#

$200 is most situations

#

95%

fallen palm
#

Okay

#

So 95% of bugs are £200

obtuse fern
ember vigil
#

NahamSec makes >$100,000 but he is full on hunter

ember vigil
fallen palm
obtuse fern
fallen palm
#

In DMs because support haven’t got back to me yet

fallen palm
vocal folio
fallen palm
#

Like 100k a year ?

fallen palm
uneven galeBOT
#

Gave +1 Rep to @vocal folio (current: #3 - 2243)

ember vigil
#

check out his youtube channel and PhDInside, talks on bug bounty

vocal folio
#

For bugs in hackerone itself, this is the schedule by the looks of it

#

(This page was the only reference to "gold standard" I could find)

ember vigil
#

i signed up for intigriti (europe based) but havent done anything with it

vocal folio
#

...I ain't reposting a photograph of a screen, but that's for Coinbase specifically @fallen palm

vocal folio
fallen palm
#

Yeah sorry 😂I’m on discord on a mobile and looking at hacker one on a laptop

vocal folio
#

Gold Standard is the "gold standard safe harbor" policy, so basically they won't prosecute you if you work in good faith and they'll try to defend you if someone else tries to prosecute you for it

vocal folio
fallen palm
#

So it’s like a protection for pentesters

#

Omgg

#

😂

#

Ahhhh autocorrect

obtuse fern
fallen palm
#

I’ve found ten so far

ember vigil
fallen palm
#

Would you like them

#

Or at least 9

ember vigil
#

the one youtuber i watch is part of it and has videos on hacking , CTFs, and bug bounty

fallen palm
#

Is that the YouTuber you mentioned above ?

obtuse fern
# ember vigil yes.

Thanks for info @ember vigil @fallen palm 🙂 . Will check that one out also 😄

uneven galeBOT
#

Gave +1 Rep to @ember vigil (current: #57 - 146)

fallen palm
ember vigil
#

< caution posting links >

obtuse fern
fallen palm
#

Well if anyone else wants it
HackerOne
Bug crowd
Synack
Cobalt
Open bug bounty
Intigriti
Zerodium
Crowdcurity
Yeswehack

fallen palm
#

The bot hates me

ember vigil
#

Zerodium platform pays for 0day exploits regardless of who is offering

uneven galeBOT
#

Gave +1 Rep to @rustic sparrow (current: #178 - 44)

fallen palm
#

😂

#

Third party vendor… seems sussy

ember vigil
#

you should edit it out

fallen palm
#

You said you use intigriti right

#

The bugs look cute 😌

fallen palm
ember vigil
#

i didnt

#

intigriti page was sketchy

#

Bug Crowd has reputation for being legit

#

they have a youtube channel hah

fallen palm
#

Ohh okay

#

Well thanks everyone 🙂

steep kraken
fallen palm
steep kraken
arctic acorn
#

Bugcrowd and openbugbounty are nice

scenic hill
#

What's the census on hackerone?

mild juniper
wary beacon
#

Guys do u've paid subscriptions ?

obtuse fern
tacit yacht
#

I am trying to start to do bug bounties but i am worried that if i just start on a bounty i would get in trouble for anyone who uses hacker one for bug bounties be able to help me on getting started with them and if so would anyone be willing to help me get started in private messages? (i am still learning as much as I can before getting to into it)

mild juniper
#

What's the best way of bug bounty hunting on my phone.
Would this be through duel booting my OS with a Linux distro?

#

Kali nethunter and Tmux are alright but I want more control without compromising my devices security

#

I am a bit of a noob with phones so it would be good to get some advice

unborn ice
#

Alot of stuff that would be most useful for a phone would require rooting, which I don't suggest.

mild juniper
#

If you duel boot into a custom Linux environment that is completely segmented from you main phone storage with FUD and encryption in transit

#

Then you might be able to control that, no?

obtuse fern
mild juniper
#

Does it look like I'm missing something though?

obtuse fern
mild juniper
#

Somehow monitor both sections of the phone. Might need another device to that though

obtuse fern
obtuse fern
mild juniper
uneven galeBOT
#

Gave +1 Rep to @obtuse fern (current: #2 - 2627)

mild juniper
#

I'm sure it still has good information

obtuse fern
summer tangle
#

where is god sites to try bug-bounty???

obtuse fern
mild juniper
#

Does anyone know any attack vectors that are unique to mobile phones and are targeted in emulators which could be useful for bug bounty hunting?

hexed pelican
#

hii, anyone who can help me ?
I found a weak TCP Sequence, and I wanna test that out.. it says TCP SEQUENCE PREDICTION: DIFFICULTY=261, all i found out is that, this difficulty ranges from 0 to 2³², and lower than 300 means that the target is vulnerable to TCP Session Hijacking. i found this while i was running an NMAP scan on a bug bounty program

hexed pelican
#

on a website

#

i have to check the nmap scan result for target ip

unborn ice
#

Which website?

Are you doing a bug bounty?

hexed pelican
#

yes I'm

unborn ice
#

Can you please share the scope. 🙂

hexed pelican
#

can u pls share the details or article that might help me create a POC

unborn ice
#

Not until you share the scope of the website you're targeting. 🙂

hexed pelican
#

I'm not wasting my time here anymore, i got my answer... GL

unborn ice
hexed pelican
#

i told you I'm done here

unborn ice
hexed pelican
#

u haven't seen my aggressive tone yet sir.

scenic hill
#

interesting

obtuse fern
arctic lintel
arctic acorn
#

Tfw you have self XSS on 20 different sites (with VDPs) but no idea what to do with it

worthy roost
arctic acorn
#

Personally, I recommend Bugcrowd.

steep kraken
#

Personally, I recommend websites from 2001

#

They're the most vulnerable and even I have some hope of finding bugs there ;-;

arctic acorn
#

They have VDPs?

lilac spindle
arctic acorn
#

Yeah, things like W3 probably do

hollow dock
#

lol

obtuse fern
hollow dock
#

with*

hybrid orchid
#

Makes you feel better instantly 🤷‍♂️

#

... Just don't do it to their face if you're being professional

unborn ice
#

I'm not too worried, they left shortly after talking to me.

pastel tartan
#

Are there any creators doing live bug bounties? At least the basic stuff, that you guys recommend?

wanton escarp
#

Anyone got a repo of File Upload bypass files?

obtuse fern
obtuse fern
wanton escarp
#

maybe a repo with, .img, .php, .php.jpg and so on 🙂

obtuse fern
wanton escarp
arctic acorn
#

upload a php file and see

#

typically it'll display an error message telling you what kinds of extensions are allowed

#

even if its limited to image files, you can try a bunch of stuff 👀

obtuse fern
arctic acorn
#

Uploading an empty php file would probably be ideal, to confirm a vector for RCE

#

it would depend on whether or not the backend sanitizes it though, you can try including a command like whoami or echo test in the file to see if it isn't

uneven galeBOT
#

Gave +1 Rep to @arctic acorn (current: #257 - 27)

uneven galeBOT
#

Gave +1 Rep to @obtuse fern (current: #2 - 2933)

fallen palm
arctic acorn
fallen palm
#

Ok but why ?

arctic acorn
#

idk I guess it's just a personal preference. The UI is nicer and the way that its structured is better

fallen palm
#

is there something in specific or just personal preference?

obtuse fern
fallen palm
#

in h1 i have some exp but not in bugcrowd. made the account years ago but never took a look at it

arctic acorn
#

Yeah I think both are good, just whatever you find works for you better like kgb said

#

plus the triagers are p quick at responding on business days

fallen palm
#

what's some ways to get private programs with bugcrowd?

lilac spindle
fallen palm
#

how? by participating to public programs or is there another way?

unborn ice
#

Participation mostly.

winged basalt
#

hello everyone im really new im barely starting all this sadly but i want this more than ever im studying tryhackme under drwDWN if you want to see what i've completed so far ... im looking for a mentor to get me to self sufficient bug bounty hunter if possible

obtuse fern
plucky storm
#

Hi guys
I have founded a button in a site, thats is a href what indicates the / directory of the site
Manipulating the content of the href to "javascript:alert():" and clicking the button, the alert console pop-up for me
My doubt is if is a XSS or no, why not modify anything in the url
I founded a XSS? Whats type of XSS is?

fast fable
#

self-XSS

#

does it reflect in the URL?

plucky storm
#

Nop

#

But open the alert popup

fast fable
#

self-xss then

plucky storm
#

Understanding
Have possibility of i leverage this for a DOM based?

arctic acorn
#

or if it persists after refreshing

#

if nothing is reflected in the URL, like absolutely no parameters or anything, then its most likely self XSS, which most programs don't allow

#

(I found this out the hard way)

plucky storm
#

Undestanding, thank you man

turbid badge
#

i am new to bug bounty

#

what to do in this situation

obtuse fern
turbid badge
#

I don't know how to do that NotLikeThis

obtuse fern
uneven galeBOT
#

Gave +1 Rep to @obtuse fern (current: #2 - 3295)

arctic acorn
#

I can probably think of a way to bypass that

#

It depends on what the condition is of course

tight oar
#

maybe he got this when he tried to do a potentially dangerous operation like a attack payload

fallen palm
#

Holy! Tons of resources for beginner bug hunters in here. Thank you guys.

lavish hollow
#

Hey! Did you know that TryHackMe has its own bug bounty programme? Well you do now!

As with a bug bounty programme for any company - you must read & adhere to their rules and policies. Here is TryHackMe's: https://help.tryhackme.com/en/articles/6495946-the-bug-bounty-program

Ensure you understand what you can and cannot do before attempting anything and adhere to the disclosure policy

fallen palm
#

Thanks @lavish hollow

uneven galeBOT
#

Gave +1 Rep to @lavish hollow (current: #6 - 1483)

ebon tapir
arctic acorn
#

real

#

omagah i got admin access!!! /j

misty spade
#

Gave myself a lifetime subscription and a job in thm

hushed sky
plucky storm
#

Hi guys. Why the "value" is not closed?

lilac spindle
plucky storm
lilac spindle
plucky storm
#

Ok man, thank you

#

Thanks @lilac spindle

uneven galeBOT
#

Gave +1 Rep to @lilac spindle (current: #22 - 447)

lavish hollow
#

Yes we have given out bounty rewards

#

Users with the bug hunter role on the platform and Discord are recipients - they have found three security vulnerabilities

#

I'm not sure, support usually hand the bug bounty queries 😓

arctic acorn
#

My submission on NASA got triaged and accepted blobfingerguns

obtuse fern
obtuse fern
arctic acorn
uneven galeBOT
#

Gave +1 Rep to @arctic acorn (current: #236 - 32)

obtuse fern
unborn ice
#

You've already emailed Support, don't release any information until they've got back to you please.

jolly ledgeBOT
#

Done!

jolly ledgeBOT
plucky storm
#

Hi guys. If anywhere like to search for XSS in bug bounty programs, call me in dm
I am starting in bug bounty now

spiral phoenix
#

HI! I have found a vulnerability on a web site for an organisation, that uses a certain security product. Should you contact both or the organisation and the security product vendor? At this time I am not 100% sure if the organisation has made custom changes that has introduced this vulnerability or if it is inherent in the product. I cannot see any product version, just response header indicating what security product is used.

arctic acorn
#

If its a vulnerability in the product, it might have been documented in NVD, if you search for <vulnerability name> in <product name> <version number if you find it>

#

If not, it'll likely be a misconfiguration by the site owners, although it depends on the product. If you find the same issue consistently in other sites using the same product, there's a chance you might have a future CVE on your hands.

spiral phoenix
#

Thank @arctic acorn! After doing some more research it looks like a misconfiguration by the site owners. I will check with them. Thanks again for your response!

uneven galeBOT
#

Gave +1 Rep to @arctic acorn (current: #226 - 34)

frail compass
#

👋

#

i got bounties, can confirm what Jabba is saying

old shell
arctic acorn
#

Sometimes bugs are very easy to find, sometimes they're very hard

old umbra
#

Got. I'll do a writeup soon.

arctic acorn
#

Did you actually get a shell for proof of concept, or stop at the LFI?

old umbra
arctic acorn
#

Do you mind if I DM you about something? Related to the same program

old umbra
arctic acorn
#

Not related to the vuln itself, dw

old umbra
arctic acorn
ancient wing
#

Hello, I'm starting my bug bounty journey and would like to test my hunting skills. As a beginner, how can I choose my targets effectively? 🙂

#

I've seen so many targets. I'm finding it confusing to choose the right ones for my skill level.

#

they have also confusing policies

obtuse fern
ancient wing
obtuse fern
# ancient wing Okey, ill try to find a less known target on bugcrowd now.

Well newer/less known program means that not as much as many people engaged in it thus means less chance of duplicates/wider attack surface but it doesn't necessarily mean that it's going to be easy , I forgot to add that 🤣 . Burp's Academy is a great resource for web vulns. I would definitely recommend you to check it out if you haven't done so already .

ancient wing
ancient wing
#

they have too much restrictive policies

arctic acorn
#

Its sort of infeasible to expect a researcher to find vulnerabilities without using tools

arctic acorn
#

Depends on how you use the tools, though

ancient wing
lilac spindle
#

But it all depends on the scope and RoE of the program.

shy flint
#

anyone wanna do bug bounty

#

dm me

ancient wing
shy flint
#

Ok

ancient wing
# shy flint Ok

I'm a beginner hunter in bug bounty. But I have foundation skills to use various tools

shy flint
ancient wing
# shy flint Yes

and I'm motivated to find RCE, SQL, Directory traversal and CVEs

ancient wing
shy flint
#

Any

#

That I can do

shy flint
#

Add me friend

ancient wing
shy flint
#

Add me friend

#

We can't talk here bro

#

We need to send all data

#

Don't be insecure

ancient wing
shy flint
#

Ok I was just worried that some one else will see this the bugs that we found and report himself but no problem if you want

#

Bro you are so slow at typing

#

Can tell me fast

shy flint
ancient wing
#

Sorry, Ill back after some time 👍

shy flint
arctic acorn
#

I've got directory traversal at least two or three times lol

hoary heart
#

Anyone open for some discussion? am stuck with a bounty program

river dirge
#

Hi everyone, I’d like to ask those who have done pentesting or bug bounty: If you discover a blind SQLi, what would your PoC be? Would out-of-band interaction or different response errors from escaped input be enough? And if you have PoC for both of these, how certain can you be that the vulnerability is present?

lilac spindle
#

Fairly certain as OOB to either of the domains under Collaborator or interactsh are an anomaly.

#

You can also use a netcat listener and use their IP address as an identifier that it did reach out.

cunning storm
#

Is there Metasploit that works in Windows 11? not patched

jagged cargo
#

This comment was @jagged cargo

#

And also untrue

sudden musk
#

I'm surprised it's still possible

#

im not arguing im just surprised

hybrid orchid
sudden musk
#

this will show how much i know but i just thought it would be patched by web servers by now.

hybrid orchid
sudden musk
#

interesting

jagged cargo
late flare
#

hey guys, how experienced should you be before delving into bug bounties?

#

and how would I know when im ready enough

obtuse fern
late flare
#

when im done with them, do you think i would be ready to atleast dip my toes into real bug bounties?

obtuse fern
late flare
#

alright tyty

obtuse fern
#

@unborn ice

jolly ledgeBOT
#

Done!

obtuse fern
uneven galeBOT
#

Gave +1 Rep to @arctic acorn (current: #207 - 38)

cold path
#

Hello everyone! I'm slowly picking up skills from THM, but I'm going try to start working in bug bounties soon. Any tips/advice on how to get started?

obtuse fern
lapis junco
ancient wing
#

I'm doing a bug bounty. I found some pages to upload a file. Can I upload any type of a file to them ? Is it allowed ?

#

I need some guidance please @obtuse fern

obtuse fern
ancient wing
#

but the domain is in the scope

sullen nova
ancient wing
ancient wing
#

maybe, ill try to contact them to ask permission

winged basalt
#

got it now i didn't see this before thank you kgb

long dagger
#

Hello guys, i struggle with finding my first bug, im a beginner, how can i do it?

#

i just read the past messages and the Web App Pentester path in thm will do great

#

thanks @obtuse fern

uneven galeBOT
#

Gave +1 Rep to @obtuse fern (current: #1 - 4270)

ancient wing
#

I've found a target. It has got 9000 ports and they are open from port 1 to 9000 port. Is it honeypot or not ? How can I know it ?

#

I used nmap to identify those ports. I used tcp-syn scan.

ancient wing
#

I also see common services running on usual ports too

#

ssh,ftp,smb and others

#

but still wondering if they might be honeypots

#

It is my first time in a bug bounty and I havn't got experience at all in bug bounty.

#

😶

ancient wing
#

@unborn ice

unborn ice
ancient wing
unborn ice
ancient wing
#

yes

#

and used tcp-syn scan

unborn ice
#

You may well have a honey pot, you may well not, how long it take syou to figre it out, if you do

ancient wing
#

I've heard that honeypots show unusual ports

#

if it is 445, it may show 9222

arctic acorn
#

I mean, it's no biggie as long as its in scope

#

They might even reward you if you establish a certain level of access inside their honeypot

#

But do make sure that it's in scope first, because a commercial website likely wouldn't allow you to test their entire non-public facing infrastructure like a typical formal penetration test

obtuse fern
ancient wing
#

It seems to me like I learn faster by cooperating with a someone experienced

ancient wing
#

🙂 And, I don't want bounties but I just want to get experience and learn

arctic acorn
ancient wing
uneven galeBOT
#

Gave +1 Rep to @arctic acorn (current: #200 - 40)

ancient wing
#

'''
subfinder -d target.com -all -o subdomains1.txt
assetfinder --subs-only target.com > subdomains2.txt
sort -u subdomains.txt subdomains2.txt -o uniqsubs.txt
cat uniqsubs.txt | httpx-toolkit -o finallist.txt

cat finallist.txt | gau --o urls1.txt
cat finallist.txt | katana -d 2 -o urls2.txt
cat finallist.txt | urlfinder -o urls3.txt
cat finallist.txt | hakrawler > urls4.txt
'''

#

I'm using these commands to find redirect params

arctic acorn
#

I prefer manual hunting, but sure that works

winged basalt
#

how long did it take you guys to find your fist bug and what was that vuln if you don't mind me asking this is just a huge goal for me but im kind of new to everything

long dagger
#

thanks @obtuse fern

uneven galeBOT
#

Gave +1 Rep to @obtuse fern (current: #1 - 4306)

long dagger
#

amazing dude

sullen nova
#

Please how do I start bug bounty hunting on websites like hackerone or bug crowd?
Do I just pick a target ans start hunting or do I need to let them know I want to hack them to hunt for bugs?
Like is there any registration that needs to be done before going to test a target?
Please somebody, make it clear

obtuse fern
uneven galeBOT
#

Gave +1 Rep to @obtuse fern (current: #1 - 4321)

lapis junco
uneven galeBOT
#

Gave +1 Rep to @lapis junco (current: #747 - 7)

long dagger
#

can this be a vuln?, thank you

obtuse fern
long dagger
#

hmm

long dagger
#

or it just cant lol

obtuse fern
long dagger
obtuse fern
arctic acorn
#

but yeah, bypassing it is considered

obsidian prism
#

I just got an invitation to hacking a bug bounty program in intigriti but I don't know what to do beside some scanning and enumeration

#

I don't know what to exploit in domains beside some basic injection like xss or brute-force attack

#

The hard things that domain server will block me if I'm trying to exploit it by command payloads

#

Anyone have some strategies to handle bug bounty programs can help me pls

sullen nova
#

I just want to ask, what is considered a bug in bug bounty programs?
Is it an exploitable vulnerability that will be reported as bugs or is it a vulnerability that can be exploited but not yet exploited?
Like a vulnerability that is not hacked yet or do I need to hack it before reporting?
Somebody please make it clear

ancient wing
sullen nova
ancient wing
sullen nova
ancient wing
uneven galeBOT
#

Gave +1 Rep to @ancient wing (current: #542 - 11)

arctic acorn
#

WAFs are just regex anyway

obsidian prism
#

But idk how to track those regex from firewall too

arctic acorn
#

you can try different payloads to see what the regex does and doesn't allow

#

Assuming it's in scope of course

obsidian prism
#

btw is it ok if I'm using burpsuite scanner to find vuln in domains?

#

Or manual scanning still better than?

arctic acorn
#

whichever you prefer

long dagger
long dagger
#

hi guys, i was doing a bug bounty program and i found something interesting, basically i tried to add ?debug to the end of the url and it got me to this, idk if its a vuln or not

#

i tried to add admin to the url and it worked?

#

but idk how to exploit it

#

ai has no idea lol

hybrid orchid
#

For what it's worth:

  1. You have left more than enough information on that page to find the target.
  2. Not sure what you did, but adding ?debug to the end of the home page doesn't do anything for me (FireFox Mobile), so worth double checking with a clean browser.
  3. It looks like that's just nuking the stylesheets. If so, where's the impact?
arctic acorn
#

I didn't get anything by adding ?debug in the URL either. Same page

#

And yes, it doesn't matter that you scribbled out the URL in the screenshot. Its still easy to find the site lol

gaunt dew
gaunt dew
#

ok 👍

long dagger
#
  • i got access to an admin panel
arctic acorn
#

because atp people can find out what the target is and exploit it, so that wouldn't align with responsible disclosure

#

their site doesn't have a bug bounty or vdp as far as I can see, but maybe there's some internal program idk. If so, report it

long dagger
#

and i told them

#

its legit , they just dont have a puplic bug bounty program

arctic acorn
#

sounds good then, go ahead and send them a report

long dagger
#

its actually my first bug

hybrid orchid
hybrid orchid
# long dagger yes, they contacted me

I'm going to take this to mean that they asked you to test them.

In which case, I assume you've had a lawyer approve a contract of work and scope of testing?
I assume you also have insurance to cover any damages you might cause to the target (e.g., by posting screenshots of potential vulnerabilities on hacking forums and public AI).

If those things aren't the case then you have opened yourself up to some deep shit. Depending on your jurisdiction, it might be possible for the state to prosecute you under computer misuse, and that's without taking into account any civil cases the company would be within their rights to bring against you if you've caused any damage.

If you've got the legal requirements in place, awesome. If not, do not attack anything.
When you work on a registered bug bounty programme, the facilitator (HackerOne, Bugcrowd, etc), generally provide the legal agreement with their clients, passed on to you in an abstracted form via ToS and programme rules.
If you're not going through a bug bounty company then all of that falls on you 🤷‍♂️

ancient wing
ancient wing
undone verge
#

Hey I have a question. I found a Boolean-based Blind SQLi on a prestigious target but I couldn't extract any data because of the tough WAF. sqlmap constantly failed and none of both intermediate and advanced payloads worked. The web page crashes on true condition after 6-7 seconds delay but it loads normally on false condition. Do you think reporting this would get me recognition? I don't even care about money, I just need an LOR or something like that for reputation. What are my chances? Should I keep trying exploiting?

zenith wren
arctic acorn
#

Even otherwise, reporting it as is would be great

#

wait I just read the message fully, my bad. It'll be great IF you can manage to extract any data

#

but I'm sure it can be bypassed if you try more. (Assuming, once more, that it's in scope)

arctic acorn
zenith wren
uneven galeBOT
#

Gave +1 Rep to @arctic acorn (current: #186 - 45)

arctic acorn
#

memory overwriting etc

zenith wren
#

no knowledge abt it

arctic acorn
#

You can learn about binary exploitation if you want

#

There are rooms about it here iirc

zenith wren
arctic acorn
#

Sure

zenith wren
undone verge
ancient wing
#

This group is not gift store

#

@lavish hollow

arctic acorn
long dagger
#

and they actually know me very well, they have a couple of websites that they gave me authority to hack (pentest)

#

sure you are right , i dont have a contract from a lawyer

hybrid orchid
#

You're treading on thin ice

long dagger
long dagger
#

a question real quick

if i have a specific code that redeems something in a website, and i managed to redeem this same code with another account without accessing this account (logging into it), what is the severity of this vuln? and is it even a vuln?

arctic acorn
#

Yyyyeah but it could depend on the context

#

That might be some form of ATO. Unless it's intended functionality, which may be likely

#

Because of how sometimes, gift codes can be gifted etc

long dagger
#

on the website im working on

arctic acorn
#

Might be worth reporting and see what they say 🤷‍♂️

long dagger
#

Is This a Vulnerability?
Yes. The ability to redeem the same code across multiple accounts without proper authentication or authorization indicates a flaw in how the website validates and tracks code usage. Codes intended for single-use or account-specific redemption should be securely enforced by the backend.

#

Wohoo!

half hare
#

Oh ok so I'm not the only one thinking the reply was extremely weird lol.

long dagger
#

But I didn’t use it to find the vuln

#

I used it to just name it

hybrid orchid
#

You know there's a reason most enterprises ban public chat bots, right?

hybrid orchid
#

It's because they are completely unsuitable for handling any sensitive information.
Even aside from the fact your chat history is accessible to employees of the company, you also have no idea how they're using the data you provide.

I would consider uploading any kind of vulnerability data into a public model a security breach.
Which in this case is really not a good look for a freelance bounty hunter.

long dagger
#

But you are definitely right

hybrid orchid
#

I mean, last time you said you'd redacted project details it took all of 10 seconds to figure out the target 😆

long dagger
#

I use ai just to help me

long dagger
#

To give info to ai chatbots ?

arctic acorn
#

not illegal but also not the best idea I would say

#

when I say "not illegal", I mean that the company you're testing have no way of finding out that you've fed the vulnerability data to AI, because they wouldn't have access to the chat history

#

so if you do, the chances of them finding out are slim. But the fact is that someone at OpenAI (or the company managing whichever LLM you're using), could theoretically find out about the vulnerability. And only you and the company is supposed to know, because you need to keep information confidential in CVD programs etc

#

and yeah, you don't know how they're using the data, like Muiri said

analog glen
# long dagger But is it illegal to do this?

Some places do have laws about resposnible disclosure - if you live in one of those places, it's very likely that disclosing a vulnerability to the ai is not definitionally responsible and you would be liable, certainly civilly and possibly criminally.

gilded meteor
#

Where can I find genuine bug bounty reports? Yes genuine... Medium is full of sh** atm. People talking about how they got 20k bounty with sql, xss or how they turned simple xss to rce... Can't get much knowledge from there.

gilded meteor
arctic acorn
#

Abhirup Konwar specifically posts some really useful blogs on recon

ancient wing
#

Hello, I have a question. Is it considered a bug if an AI exposes someone's full name or reveals the activities of a private LinkedIn account?

arctic acorn
#

I would say so

#

Unless you're very sure that the said name isn't available publicly and that the LinkedIn truly is private

#

Otherwise it could easily pull that from search mode.

ancient wing
#

is it okey to send screenshots here?

arctic acorn
#

redact sensitive info

#

(all of it)

formal sonnet
#

I know python, C, C++, and FrontEnd along with MySQL

#

also, basics of Linux and Networking, what else do I need to become a Bug Hunter?

#

could someone help me through?

arctic acorn
#

but you should learn more about tools like burp suite

formal sonnet
#

yeah, how

arctic acorn
hybrid orchid
long dagger
#

i remember that trend, chatgpt leaked a bunch of microsoft codes for activation which you could have got for just simply asking the ai

#

Crazy!

analog glen
#

For it to do that, someone would have had to include samples of activation codes in the training data. It would be interesting to know how many of those "activation" codes were valid vs hallucinations

analog glen
#

It shouldn't. It's pretty dumb a lot of the time.

long dagger
#

they needed to write a scenario

#

so they can lie to the ai

#

like making a story or smth

gilded meteor
#

A quick question, people who have a full time job and keep learning new things(I mean you need to stay updated with the technology as its advancing everyday), how do you manage bug hunting along the way?

lilac spindle
lapis junco
sterile nebula
#

explain this anyone?

#

Your test account must include the phrase “sectest” in the username.

hybrid orchid
molten surge
#

This crouse in tryhackme

sterile nebula
#

nvm I am quite new

#

which course

zenith wren
#

can sm1 help me w bug bounty

#

am new

#

dm me if u can help me

gentle meteor
#

with what do u need help

winged basalt
#

EVERYTHING

zenith wren
sterile nebula
#

i would appreciate some help too :)

gilded meteor
#

Hey hunters, quick question... Should I focus on one bug at a time? For instance if I'm testing a site, should I look for one specific bug such as xss, ssrf or it should be like let's see what I can find...

obtuse fern
zenith wren
#

what tools do i need

#

for doing succesful bug bountys.

obtuse fern
zenith wren
#

@obsidian prism

#

How u b ypass waf

fallen palm
#

What a useful server!

#

No one can help this dude with his waf bypass

#

Come on @obtuse fern

obtuse fern
obtuse fern
# zenith wren kgb

Why do you need it ? There's no universal answer to that question , it depends on the context of the app and network configuration of the target

zenith wren
#

To run sql on the site

#

to check if the site is vulnerable and exploitable

obtuse fern
zenith wren
obtuse fern
arctic acorn
#

And without knowing the scope, no one is going to help someone bypass something

thick laurel
#

Hey guys I’m having an issue with Burp Intruder
When I run SQLi payloads, everything works fine until a payload containing the word "password" hits
Then I get an 84MB response Burp says it's too large to display, and it freezes

Happens every time unfortunately,,,, Any idea how to fix this?

gentle meteor
#

anyone interested to find some bug bounties tonight

robust lava
#

I'm seeking someone for an active bug bounty collaboration or apprenticeship. If you're interested, feel free to reach out!

unborn ice
#

@ember herald Please don't advertise here.

sullen nova
#

So I just want to ask, for the web professional testers among us, part of internal pentesting is vhosts and part of external pentesting is subdomains, right?

hybrid orchid
#

Subdomains are a DNS concept. DNS works both internally and externally.

#

VHosts are a web server concept. Web servers can be deployed both internally and externally.

uneven galeBOT
#

Gave +1 Rep to @hybrid orchid (current: #10 - 873)

royal cloud
#

guys can anyone tell me if i have no knowledge about bug bounty or hacking which books should i read first i only want to learn how to do bug bounty, how to find web vulnerability

unborn ice
royal cloud
unborn ice
royal cloud
uneven galeBOT
#

Gave +1 Rep to @unborn ice (current: #2 - 3702)

royal cloud
fringe lynx
#

Guys, how do I start on bug bounty as a beginner? I know how to scan ports using Nmap. I saw vids on youtube that said that Hackerone and other popular sites usually gets the easier bugs swooped out by big boi experts before us beginners can say "I found it"

#

-# also what is clickjacking..

final crown
#

learn the basics first

#

after a year or two of consistent learning only then you can start to think about doing those

#

its still a very competitive field since everyone and their fathers are doing it 🤣
so just learn the owasp top 10 by heart, refine your own methodology for them and you will maybe have a chance to find a small bug

bold compass
final crown
#

learn the basics like i said

#

tryhackme has a great free path for that

bold compass
#

got it, time to meditate in tryhackme this whole summer 🔥

arctic acorn
# fringe lynx -# also what is clickjacking..

since you asked, it involves overlaying UI elements through something like stored/reflected XSS or CSRF to trick a user into clicking a malicious link or button hidden behind opaque style sheets or layering

#

and yeah, nmap scanning an IP really doesn't mean anything, especially if you're hunting on websites. Even if you were, you wouldn't have authorization to touch the other ports

#

so... only 80/443 is open to you either way

median sigil
#

While testing a program, I found an icon_url parameter where I inserted my Burp Collaborator URL and received both DNS and HTTP interactions.

Does this confirm SSRF? What additional tests should I run to validate the severity (e.g., internal access or metadata exposure)?

Appreciate any tips on escalating or reporting this properly.???

long oyster
#

Hello! I’m trying to get fast like 100-200$ from bug bounty. I finished the Web fundamentals on tryhackme. What do I need to learn and do to make that money in like 2-3 weeks?

final crown
worn dome
#

Is there any channel for ctfs? 🥲

obtuse fern
obtuse fern
woven hawk
#

Hey
I am learning web app pentesting. For that, I am solving PortSwigger labs, doing Hacker1 labs.
I am looking for tips on how I can make my workflow smoother.
I am also having problems with the recon steps since there are so many tools. I am getting confused between tools. Moreover, as a beginner, do I need to learn scripting first-hand, or should I take some time with Kali tools?
I am aiming to get a job within a month. I have my basics clear, and I have little experience handling IBM QRadar, Defender.
I am open to any suggestions.

mellow fossil
#

Hey,
I would like to crack 1 or 2 bug bounties and only know some basics. Which is the best platform for beginners to crack bug bounty and tell me how can I crack it to earn some

obtuse fern
mellow fossil
obtuse fern
graceful kiln
mellow fossil
graceful kiln
# mellow fossil Ok! Have you guys done one this industry based bbg and if so then tell me some k...

the knowledge/advice i have to offer is learn first before attempting any public program as you're unlikely to find anything if you don't have a basic understanding of the fundamentals at the very least.
a good exercise perhaps would be to go to a public program, read the scope and guidelines and see if you understand the types of vulnerabilities they're looking for. if you can't explain what those vulns are, you may not be ready to hunt for them.
wish you the best in your bb journey 🙂

proven cobalt
#

Folks, please don't get into the habit of generating bug reports using AI. It's creating undue burdens for bounty programs to filter through all the utter rubbish being produced. See below.

https://www.youtube.com/watch?v=xy-u1evNmVo
https://www.theregister.com/2025/05/07/curl_ai_bug_reports/

AI generated bug reports are becoming a serious problem? Is this incompetence? Or malicious?

https://hackerone.com/reports/3125832
https://www.linkedin.com/feed/update/urn:li:activity:7324820893862363136/

🏫 MY COURSES
Learn the fundamentals of programming: https://lowlevel.academy

🧙‍♂️ HACK YOUR CAREER
Wanna learn to hack? Join my...

▶ Play video

: Lead dev likens flood to 'effectively being DDoSed'

final crown
proven cobalt
# final crown the consequences of artificial intelligence..

Unfortunately, yes. It's opening the floodgates for people to come into the industry without the appropriate skills and knowledge, looking for a quick buck. But, when they say AI would generate more work/jobs, they weren't suggesting it would generate work cleaning up the increasing volumes of dysfunctional drivel spewed by the machines

grim widget
molten patio
#

Especially since you classify it as the "vulnerability with highest global impact by far that you've ever found"

#

I know you've found some pretty crazy vulnerabilities before, so can only imagine what this is then

grim widget
molten patio
#

Oh, ok. Yeah, that makes sense, and is somewhat of a relief as well 😅

spark lodge
#

what are some good webapps like juice shop to practice testing? Hoping to add some to my home lab

gaunt olive
#

Dvwa

#

You can also look at webgoat too

spark lodge
uneven galeBOT
#

Gave +1 Rep to @gaunt olive (current: #1880 - 2)

gaunt olive
#

Oops, thats webgoat

spark lodge
#

Saved, Thanks

gaunt olive
#

Btw, owasp will release TOP 10 2025

bitter crown
#

W

cedar mulch
#

#bug-bounty I want to be a good hacker someone help me please

cedar mulch
finite halo
gaunt olive
#

Anyoen tried using rengine? Whats your opinion on it?

indigo herald
#

Hey everyone, I need some direction.

So far, I’ve learned JS deobfuscation, basic SQLi, IDOR, Burp Suite (intruder & repeater), curl usage, base64 decoding, source file inspection, and some web challenges (like template injection). I'm familiar with basic recon (Nmap, checking JS files), and exploring tools, but I’m still piecing it all together.

Lately, I feel a bit confused — like I know fragments but can’t see the full picture. What should I focus on next to get better at bug hunting?

Any advice would help.

lilac spindle
# indigo herald Hey everyone, I need some direction. So far, I’ve learned JS deobfuscation, bas...

You know techniques and have done bite sized challenges. If you haven’t finished the Web Application Pentesting path, I recommend you do. You can further challenge yourself by doing a black box approach on certain vulnerable web applications (e.g. OWASP Juice Shop, OWASP crAPI). This allows you to look at web applications as itself without anyone telling you the vulnerabilities that lie inside.

indigo herald
uneven galeBOT
#

Gave +1 Rep to @lilac spindle (current: #22 - 453)

high tinsel
#

Hey guys, I’d really like to hear from someone with more experience. I’ve been studying for about 45 days now and focusing a lot on web stuff because I want to get into bug bounty. Is there anyone here who already has some experience that I could talk to, just to see if I’m on the right track? hahaha

I’ve been putting a lot of effort into the TryHackMe paths (even paying for premium because I’ve really been enjoying the content), and I’m also taking other hacking and networking courses on the side to keep everything balanced, you know?

I just want a bit of insight from someone who’s ahead in the game to understand if I’m moving in the right direction.
Because honestly, this is something I’m really enjoying learning and I want to make it part of my life for real.

arctic acorn
#

Check out PortSwigger Academy as well

high tinsel
uneven galeBOT
#

Gave +1 Rep to @arctic acorn (current: #153 - 57)

high tinsel
#

Also, curious — did you get into bug bounty through platforms like HackerOne or did you follow a different path?

arctic acorn
arctic acorn
#

also worth noting that HTB is also very good, they even have a certification exam called CBBH (Certified Bug Bounty Hunter)

high tinsel
#

And I know I probably sound like I’m interviewing you or something but I’m just genuinely curious, was there a moment where things started to really click for you? Like, how long did it take before you felt like you weren’t just fumbling around?

arctic acorn
upper blaze
#

is caido better than burpsuite?

obtuse fern
upper blaze
uneven galeBOT
#

Gave +1 Rep to @obtuse fern (current: #1 - 5033)

fluid condor
coral roost
#

can anybody tell me from where I can learn bug bounty for free

obtuse fern
verbal dagger
#

Guys I'm a beginner, just trying to figure out how XSS are really triggered, I've already secured some bounties in BAC type of bugs, but I never ever found an XSS, can anyone recommend any article or tutorial or any tool to automate the process of finding XSS, or methods of manual testing? I tried few but they didn't work for me!!

#

I even tried creating my own custom tool using ParamSpider, httpx, and Dalfox with the help of ChatGPT, but it wasn’t very effective or maybe I didn’t know how to use it properly.

obtuse fern
#

Also Burp's Web Security Academy has a whole xss module 🙂

verbal dagger
#

Okay, Thanks man!

slow vault
#

I’m just getting started with bug bounty hunting and CTFs, and I recently signed up for HackerOne. Right now, I’m still pretty new to it and don’t have a ton of experience, but I’m eager to learn and improve. can someone recommend THM lessons, tutorials or anything that is self-explanatory on that stuff

obtuse fern
slow vault
#

thx

#

do you have experience on Hacker One?

obtuse fern
proven cobalt
vague turret
# slow vault do you have experience on Hacker One?

hackerone is pretty useful for "hacking away" legally. putting your knowledge to the test in a controlled way. it's pretty neat, even if you don't find anything, it's fun to smash your head against a corporate wall.

undone tiger
fading sky
unkempt halo
fading sky
unkempt halo
obtuse fern
pearl stump
#

Hey everyone, I'm new here, it would be nice to make each other friends and climb together, I'm a beginner learner, I'm currently in THM pre security, mind anyone to be more friend with me so that we can discuss everything in dm together?

woeful crystal
#

Hi I am IFP CyberFardin I am new here I am 16 years old and I want to learn cyber security .How can I learn . I know about networking . Some Linux commands . And more but I struck at what should I do now 😭😩

fallen palm
#

Hey! I’ve been learning the basics of ethical hacking and I really want to get better. Can you suggest how I should continue learning or what resources you’d recommend?

obtuse fern
fallen palm
#

I know the basics now and I’m really interested in the offensive side—like pentesting and ethical hacking. How should I start learning properly?

obtuse fern
fallen palm
#

Yeah appreciate that

#

🙂

split axle
#

Hi all,
I'm planning to study bug bounty starting with IDOR and SSRF, I wouldn't mind people joining with me 🙂

sharp sparrow
honest scarab
#

bug bounties sound fun

earnest loom
#

Will anyone be so kind to suggest me the best platform for learning bug bounty from basics to advanced. I am currently a BSCS student and just completed 4th semesters. I'm eager to dive into this field.

#

Also if anyone is already doing bug bounty and needs a good hardworking partner, I can surely be of help and we can learn together. Thanks

obtuse fern
earnest loom
uneven galeBOT
#

Gave +1 Rep to @obtuse fern (current: #1 - 5182)

obtuse fern
obtuse fern
uneven galeBOT
#

Gave +1 Rep to @earnest loom (current: #2926 - 1)

unborn ice
pearl stump
#

Hey @earnest loom
If you're a beginner and looking for a beginner partner to learn together with, I'll be glad to team up with you, what do you say? Maybe we should talk about our goal and other stuff and try to learn together?!😉

pearl stump
#

Nice, let's talk on insta or WhatsApp first? Let's know each other's motive better first. @pastel relic

noble sleet
#

Hi everyone, . I'm new to cybersecurity and trying to improve my English too. I'm learning Python and ethical hacking. I want to make friends and learn together. Anyone here wants to talk or help?

fading gulch
noble sleet
arctic acorn
noble sleet
arctic acorn
noble sleet
arctic acorn
#

Uh yes

#

If it makes it any easier, you can use Google Translate to talk lol

unreal beacon
faint depot
#

PentesterLab is another awesome platform

wind bay
#

Yo I need a little help, Ive finished both the PEH and BugBounty Course of TCM and I wanna get into Bugbounty. But kinda struggling still with the starting, So need few tips

obtuse fern
wind bay
#

That too ive finished, Just need a guide on How do i pick my first target on hackerone or bugcrowd and also stuck and confused with the recon part

warped rapids
#

Can anyone help me with medium reward from Bykea?

unborn ice
unborn ice
uneven galeBOT
#

Gave +1 Rep to @warped rapids (current: #2939 - 1)

split axle
wind bay
#

cool

faint depot
#

Why is this in the bug bounty channel?

earnest grotto
#

where can i do this?

half hare
#

Hello, welcome to the server! 🙂
Please interact a bit more before promoting your project.
As for when it comes to anything related to coding, we have a dedicated channel for that: #programming.
However, keep in mind that we can't help when it comes to school, college or professional work.

earnest loom
#

Hey, I hope you are all doing well. I am using free version of tryhackme. I have connected with the tryhackme server through openvpn and also 10.10.10.10 is accessible and the ip is assigned. If you go to this link https://tryhackme.com/room/owasptop102021 and look at the task 4, how am i supposed to access the given link cause it always says "This site can't be reached", Can someone guide me through this issue, pls?

earnest loom
long oyster
#

I just finished the full Burp Suite module on THM and really enjoyed it. I'm planning to get into bug bounties, but I’m wondering — what should I focus on next?

Should I dive into the OWASP Top 10, Bug Bounty Toolkit, Recon, or something else before I start hunting on real platforms?

golden wolf
#

got any clues on task 9,10,11

vestal crane
#

wrong channel bud

#

but you wont get clues

unborn ore
#

@obtuse fern Kindly reply to my message as soon as possible, as this is a high critical security vulnerability.

obtuse fern
tame sirenBOT
#
TryHackMe's Email

TryHackMe's support email address.

unborn ore
#

I reported but not responding

obtuse fern
unborn ore
#

Yeah

#

Even I also report another bug last week but not reply

#

@obtuse fern thanks 😊 for replying

uneven galeBOT
#

Gave +1 Rep to @obtuse fern (current: #1 - 5377)

obtuse fern
unborn ore
#

Yeah

fallen palm
#

how do i learn bug bounty?

silk axle
#

is there any bug bounty hunter?

acoustic bane
#

What kind of experience level are self employed bug bounty hunters?

unborn ice
acoustic bane
unborn ice
#

BB is not a viable income.

#

All the streamers also get money coming from sponsors from their videos etc.

fallen palm
#

But is it worth our time?

obtuse fern
#

5-10k monthly or yearly 🙂 ?

fallen palm
#

Thanks for the insight, I'll try learning about bug bounty, after all something is better than nothing 🥲🥲🥲

uneven galeBOT
#

Gave +1 Rep to @void furnace (current: #2972 - 1)

obtuse fern
#

Thanks for sharing the experience 🙂 👍

uneven galeBOT
#

Gave +1 Rep to @void furnace (current: #1942 - 2)

hallow venture
#

what do you make on average for each bounty im not sure what a good price is.

hallow venture
#

what would you consider average

vestal crane
#

anywhere from a pat on the back to $1000000

#

bug bounty is not a sustainable way to live

hallow venture
#

i know that im just interetsed in the concept and i didnt know how muh some people make off of it.

vestal crane
#

it really depends, some people make a lot, some make little to none, most do it for the fun of it

hallow venture
#

so it's just a way to make a little money on the side and not like a way to make a good yearly income.

fast fable
#

correct

modest herald
#

in real engagments what are the rules for automated scanning like dirbuster and fuzzing

obtuse fern
lilac spindle
#

For bug bounties, this is usually in the scope like 1 req/second

daring inlet
#

monad

daring inlet
#

fr

lapis tiger
#

Hello brothers,

I’m still new to Bug Bounty.
I registered on a website and went to my profile page where I tried to change my address (city, postal code...).
I intercepted the request using Burp Suite, and I found that the request contains a CSRF token.

I tried to remove the token or replace it with a random value, but the request failed.
However, when I keep the original token and just add a single character to it, the request still returns 200 OK.

The issue is that I must keep the original token and just append one character — then it works.

Has anyone encountered something similar?
I’d really appreciate it if someone could guide me on how to progress with this kind of vulnerability.

Thank you so much, may God bless you and your parents.

fast fable
lapis tiger
woven ibex
#

Hello there

daring inlet
#

coool

lilac spindle
lapis tiger
lilac spindle
daring inlet
#

fr

acoustic owl
#

where can i learn bug bounty

half hare
clever oracle
#

I have some experience with web application penetration testing. Currently, I’m working on a project where I need to perform penetration testing on an Android application. Can anyone suggest tools or provide guidance to help me get started?

clever oracle
uneven galeBOT
#

Gave +1 Rep to @obtuse fern (current: #1 - 5516)

lapis tiger
#

Hello everyone, I have a question.

While testing the CSRF protection mechanism on a website, I noticed that I could modify the CSRF token by appending a special character like =, ;, :, or + at the end of the token, and then add any arbitrary text or numbers after it — and the server still accepts the request as if the token is 100% valid.

👉 Has anyone encountered this kind of CSRF token bypass before?
🤔 Is this considered a valid CSRF vulnerability worth reporting in bug bounty?

fast fable
#

Before you consider any vulnerability for a bounty, you need to figure out what the impact is. Do you still need the entirety of the token to make the request? What does the request do? How could an attacker abuse it?

fast violet
fast fable
#

literally how

fast violet
#

ok was dumb idea if you an concat somethin to a string you just could put it in the string in the first place

#

oO

#

sry

fast fable
#

it just wouldn't be used in a SQL db, or shouldn't at least

fast violet
#

yeah maybe in 1998 but not now, also im really new to this stuff, im a seasoned IT guy interested in vulnerabilities ,but well, was a dumb idea to post in the bug-bounty challenge channel at my topic level.