What would be your approach in bug hunting programs


Could you all share your experience and approach, how would you start hunting for a bug when you’re into bounty programs?

How hard is it for a novice to start hunting for bugs at hackerone or bugcrowd? Would you recommend any?

Sites which pays for your research or zero day vulnerabilities

I have never really made it as a successful bug bounty hunter, so I’m not sure if my advice carries much weight, but here goes.

First thing, if you take a look at the bounties available a vast majority of them are web related. I would get really experienced in web development in the core languages such as PHP, RoR, and Javascript first of all. I think this will be a must.

Next, I wouldn’t expect anything to start happening overnight. Don’t get yourself worked up thinking you are going to be making a ton of money. This is one of those fields that you are passionate about first and then the money comes next.

Get yourself a couple of books on what you are interested in. Again, my focus would be web application hacking, but there are plenty of resources out there.

Getting involved with the community is probably a good idea, or maybe working with a couple of friends and splitting any reward might be helpful, but not sure.

Overall I think that the important part is that you are just passionate about it. If that’s the case you will do well.


Is it possible to share all the platforms like zerodium which pays me well? I think it would be great to maintain that list

@hackractual could you please create a topic?


That’s the only one I know, and I learned about it at the same time you did.


That is to say, you guys don’t know about the big names in bug hunting like HackerOne and BugCrowd or just not ones that pay well?

Microsoft just upped the ante with their bug bounty program recently. So did PayPal. (site down for update.)

I think even Steve Gibson had something to say about recent bug bounty programs on one of the more recent episodes of Security Now!


Yeah, I knew about those but the example the other guy made was paying upwards of $1M for specific vulnerabilities, granted they are incredibly difficult vulnerabilities.


Oh! Okay. I didn’t pick up on the theme.




