Introduction To Bug Bounty For Noobs

DarkLotus
InfoSec Write-ups
Published in
3 min readApr 12, 2020

--

Welcome to the world of bug bounty

1)If you have no idea what bug hunting is then do watch Mr. Robot at least one season.
I’m sure that now you have a clear mindset of becoming a hacker. Let’s master the skills!

2)Now its time for shell/linux, it is the basics which supports hacking,it is one of the most important things in our journey to bug bounties:

Hindi : Linux commands : Clear your Linux Basics in 25 min for beginners
English : Introduction to Linux and Basic Linux Commands for Beginners

3)Now, I suggest you do this course,which helped me getting started:

V1: Bug Bounty Hunting — Offensive Approach To Hunt Bugs

V1 costs around Rs.360 (Approx. $5),there are two versions. The V2 is the latest one but a little xpensive.

V2: OFFENSIVE BUG BOUNTY — HUNTER 2.0

4)Now go and hunt for bugs, but if you want to learn more then books are your best friends, after one month of hunting start off to read these books:

Book №1 — Mastering Modern Web Penetration Testing
Book №2 — The Hacker Playbook Part 1

6) Now take a break and off you go for those bugs!

7) After one month, you’re back again to read…..

Book №3 — The Web Application Hacker’s Handbook Edition 2
Book №4 — Web Hacking 101

8) Now you are all set for bug hunting, but i will suggest you to read a few more books.

Book №5 — The Hacker Playbook Part 2
Book №6 — The Hacker Playbook Part 3
Book №7 — Hands-On Bug Hunting for Penetration Testers

NOTE: In The Hacker Playbook Part 1, 2 and 3, you’re supposed to read them from the beginning to “The Throw — Web Application Exploitation” , you can skip the chapters after as they are mostly non-signfigant in bug bounties because they focus on post exploitation.

9) These books are the Seven Wonders of Bug Hunting, and now you are 60% ready for bug hunting and for the remaining 40% you will have to read and go through blogs, write ups,etc.

Bounties will be the reward for your hardwork

10) It is now time to make your network strong, install apps like twitter,linkdin,discord, meetup, etc.

Follow these guys on Twitter:
TomNomNom
s0md3v
ADITYASHENDE17
stokfredrik
NahamSec
Harsh Bothra
A hacker’s life

They tweet a lot of tips and tricks which will help you. Be sure to follow and go through each of their accounts.

Subscribe to these Youtube channels:
STÖK
Bitten Tech (HINDI)
HackerSploit
PwnFunction
PraTech Tutorials (HINDI)
Nahamsec
The Cyber Mentor

11) Try to attend these esteemed security conferences NULLCON, Bsides, h1 events and many others.

I suggest you to first hunt on points/swag based programs.Thank You so much for reading! Support me if you like my work! Buy me a coffee and Follow me on twitter.

Buy me a coffee

--

--