Posts: 51
Threads: 5
Joined: Aug 2023
08-09-2023, 03:48 AM
(This post was last modified: 08-09-2023, 03:49 AM by btl3r.)
I am very interested to start my journey as a bug bounty hunter. But there are a lot of competition and i just cant keep up with experienced hunter.
Learnt about bug bounty from platform like tryhackme, hackthebox and 1 purchased one course from udemy, https://www.udemy.com/course/complete-et...ug-bounty/
by Ryan John Phd.
Having this in mind its very demotivating. I am a very beginner and still learning. Can you guys who is experience in this give some tips or share some stories about your 1st triaged bounty, doesnt matter the amount you are paid.
Last question, is it worth to venture down the rabbit hole in bug bounty? considering the huge competitors.
Posts: 49
Threads: 9
Joined: Aug 2023
(08-09-2023, 03:48 AM)btl3r Wrote: I am very interested to start my journey as a bug bounty hunter. But there are a lot of competitive and i just cant keep up with experienced hunter.
Learnt about bug bounty from platform like tryhackme, hackthebox and 1 purchased one course from udemy, https://www.udemy.com/course/complete-et...ug-bounty/
by Ryan John Phd.
Having this in mind its very demotivating. I am a very beginner and still learning. Can you guys who is experience in this give some tips or share some stories about your 1st triaged bounty, doesnt matter the amount you are paid.
Last question, is it worth to venture down the rabbit hole in bug bounty? considering the huge competitors.
Bug bounty can be worth it but it can also be a pain in the ass. If you really wanna go for it, try all the boxes in thm and htb without tutorials. Go on youtube and search for people teaching bug bounty related things like John Hammond and liveoverflow. It can also be worth it to find a partner to help you with bounties with.
Posts: 51
Threads: 5
Joined: Aug 2023
(08-09-2023, 03:51 AM)Lotus Wrote: (08-09-2023, 03:48 AM)btl3r Wrote: I am very interested to start my journey as a bug bounty hunter. But there are a lot of competitive and i just cant keep up with experienced hunter.
Learnt about bug bounty from platform like tryhackme, hackthebox and 1 purchased one course from udemy, https://www.udemy.com/course/complete-et...ug-bounty/
by Ryan John Phd.
Having this in mind its very demotivating. I am a very beginner and still learning. Can you guys who is experience in this give some tips or share some stories about your 1st triaged bounty, doesnt matter the amount you are paid.
Last question, is it worth to venture down the rabbit hole in bug bounty? considering the huge competitors.
Bug bounty can be worth it but it can also be a pain in the ass. If you really wanna go for it, try all the boxes in thm and htb without tutorials. Go on youtube and search for people teaching bug bounty related things like John Hammond and liveoverflow. It can also be worth it to find a partner to help you with bounties with.
Yup im on the right path its just that i found it to be very very basic. For example when they teach about IDOR, its very unlikely that you will get those in the real scene.
By the way are you a hunter yourself? If you are mind sharing a little bit about your 1st bounty?
Posts: 49
Threads: 9
Joined: Aug 2023
(08-09-2023, 04:12 AM)btl3r Wrote: (08-09-2023, 03:51 AM)Lotus Wrote: (08-09-2023, 03:48 AM)btl3r Wrote: I am very interested to start my journey as a bug bounty hunter. But there are a lot of competitive and i just cant keep up with experienced hunter.
Learnt about bug bounty from platform like tryhackme, hackthebox and 1 purchased one course from udemy, https://www.udemy.com/course/complete-et...ug-bounty/
by Ryan John Phd.
Having this in mind its very demotivating. I am a very beginner and still learning. Can you guys who is experience in this give some tips or share some stories about your 1st triaged bounty, doesnt matter the amount you are paid.
Last question, is it worth to venture down the rabbit hole in bug bounty? considering the huge competitors.
Bug bounty can be worth it but it can also be a pain in the ass. If you really wanna go for it, try all the boxes in thm and htb without tutorials. Go on youtube and search for people teaching bug bounty related things like John Hammond and liveoverflow. It can also be worth it to find a partner to help you with bounties with.
Yup im on the right path its just that i found it to be very very basic. For example when they teach about IDOR, its very unlikely that you will get those in the real scene.
By the way are you a hunter yourself? If you are mind sharing a little bit about your 1st bounty?
Years ago I wanted to be one, but found that it wasn't for me. Finding active bugs in sites that offer a bug bounty program takes a lot of time and effort, especially with how competitive the scene is. I have found bugs/exploits in sites before, but they weren't ones that had bug bounty programs.
Posts: 877
Threads: 2
Joined: Jun 2023
I would say like only 1% of bug hunters are making big money. I wouldn't waste my time. it's a good way to start a "career" that's all. if you're motivated by money don't do bug bounty.
Posts: 172
Threads: 22
Joined: Sep 2024
i recommend to start with programs that not offer money , you can get reputations that will help you to get invited to private programs that may not be challenging as public programs
Posts: 33
Threads: 2
Joined: Oct 2024
10-08-2024, 09:11 AM
(This post was last modified: 10-08-2024, 09:12 AM by hationes4553.
Edit Reason: Missed the quote
)
Quote: i recommend to start with programs that not offer money , you can get reputations that will help you to get invited to private programs that may not be challenging as public programs
Best advice so far. You can expect less competition from programs with no paid rewards.
But let's be honest, if you have little to no experience in finding and exploiting real vulnerabilities (AKA not lame things on 1980's like websites) you are going to have a hard time finding anything. You won't learn with bug bounty as a beginner, just suffer and drop out of motivation. Bug bounty scopes are usually covered by some professionals before going public.
Posts: 20
Threads: 0
Joined: Sep 2024
(08-09-2023, 04:16 AM)Lotus Wrote: (08-09-2023, 04:12 AM)btl3r Wrote: (08-09-2023, 03:51 AM)Lotus Wrote: (08-09-2023, 03:48 AM)btl3r Wrote: I am very interested to start my journey as a bug bounty hunter. But there are a lot of competitive and i just cant keep up with experienced hunter.
Learnt about bug bounty from platform like tryhackme, hackthebox and 1 purchased one course from udemy, https://www.udemy.com/course/complete-et...ug-bounty/
by Ryan John Phd.
Having this in mind its very demotivating. I am a very beginner and still learning. Can you guys who is experience in this give some tips or share some stories about your 1st triaged bounty, doesnt matter the amount you are paid.
Last question, is it worth to venture down the rabbit hole in bug bounty? considering the huge competitors.
Bug bounty can be worth it but it can also be a pain in the ass. If you really wanna go for it, try all the boxes in thm and htb without tutorials. Go on youtube and search for people teaching bug bounty related things like John Hammond and liveoverflow. It can also be worth it to find a partner to help you with bounties with.
Yup im on the right path its just that i found it to be very very basic. For example when they teach about IDOR, its very unlikely that you will get those in the real scene.
By the way are you a hunter yourself? If you are mind sharing a little bit about your 1st bounty?
Years ago I wanted to be one, but found that it wasn't for me. Finding active bugs in sites that offer a bug bounty program takes a lot of time and effort, especially with how competitive the scene is. I have found bugs/exploits in sites before, but they weren't ones that had bug bounty programs.
What did you switch to?
|