Skip to main content

Command Palette

Search for a command to run...

BUG - BOUNTY

Updated
2 min readView as Markdown
P
CTF player and Web Pentester

Platforms

hackerone

Bugcroud

Integrity

YesWehack

Synack


WorkFlow

RECON

Have to gather All information of target

1) Finding Domains & Subdomains

Tools

1) Subfinder

2) Amass

2) Identifying Technologies

Identify what technolofy is running on target serer

Tools

1) wappalyzer

2) whatweb

SURFACE MAPING

Now i have list of target, Now in need to understand how they work

Crawling & Direct Busting

Browse all tools of website and discover its all web pages

Tools

1) ffuf

2) Gobuster

Understanding Functionality

manually exploe the application, How do API request look like when we add sometthing in cart

Tools

1) Burpsuite

Vulnerability Testing

Look for specific weakness

1) can i broke the login logic? (Authentication Flows)

2) can i view or edit another user's data? (Access Control issues)

3) can i inject malicious code (injection flows , like XSS or SQLi)

Exploitation

FInding a Potential Bug

Reporting

i found the bug successfully exploited it , now ii need to generate the reports on community findings


Skills Required For BUG BOUNTY

  1. Web application Security (most imp)

understanding if OWASP TOP 10

  1. Networking Fundamentals

understanding of HTTP/HTPS protocol, how request and response work , DNS , IP addresses, and common Ports

  1. Scripting - bash or python

don't need of software, but basic scripting skills are incredibly helpful

  1. Reconnaissance Techniques

Knowing ow to find hidden information about your target is hald battle, this involves using search engine( Google Dorking), Github, Certificate Logs, Various OSINT

  1. Vulnerability Analysis

i need to be able to analyze the result, understanding why a vulnerabilty exists


Commom Tools Used By BUG HINTERS

1) Burpsuite

2) OWASP ZAP

3) Nmap

4) Subfinder

5) Amass

6) ffuf


CONCLUSION

Start with fundamentals, practise responsibly, Focus on quality not just quantity, be patiemt and persistent

3 views

Bug-Bounty

Part 1 of 1

All Thing related To Bug-Bounty