Bug Bounty Career: Web Hacking

Shakhawat Hossain - 0xShakhawat
4 min readMay 9, 2022
web hacking 0xShakhawat

Details

  • The objective is to help Information Security professionals,
    enthusiasts and even the youngest, to enter the Bug Bounty area;
  • Knowing the skills necessary to work in the area of ​Bug Bounty;
  • Of course, this is not a guide that will make you a professional, but I
    hope it helps;

Bug Bounty Platforms

  1. HackerOne
  2. Bugcrowd
  3. Intigriti
  4. Bug Hunt
  5. Hackaflag
  6. Yogosha
  7. Zeroday initiative
  8. Open Bug Bounty
  9. YesWeHack
  10. Cobalt.io
  11. Synack Red Team

Skills Bug Bounty Hunter

  • Knowledge in Programming Logic;
  • Knowledge in Web Attack Vectors;
  • Knowledge in Reverse Engineering;
  • Skills in Web Development;
  • Programming Logic exercised;
  • Computational basis;
  • CTF Player;
  • Knowledge in Network Computer;
  • Knowledge in System Administrator (Linux and Windows);
  • Knowledge in Cloud Computer (AWS, GOOGLE and AZURE);
  • Skills in Infrastructure Exploitation;

Web Vulnerabilities — TOP 17

  1. Open Redirect;
  2. HTTP Parameter Pollution;
  3. Cross-Site Request Forgery;
  4. HTML Injection and Content Spoofing;
  5. Carriage Return Line Feed Injection;
  6. Cross Site Scripting;
  7. Template Injection;
  8. SQL Injection;
  9. Server Side Request Forgery;
  10. XML External Entity;
  11. Remote Code Execution;
  12. Memory Vulnerabilities;
  13. Subdomain Takeover;
  14. Race Conditions;
  15. Insecure Direct Object References;
  16. Oauth Vulnerabilities;
  17. Application Logic and Configuration Vulnerabilities;

More Web Vulnerabilities: https://owasp.org/www-
community/vulnerabilities/

Vulnerabilities — HackerOne Rank

Resources Study

  1. https://chawdamrunal.medium.com/pro-tips-for-bug-bounty-
    f9982a5fc5e9
  2. https://medium.com/bugbountywriteup/bug-bounty-hunting-
    methodology-toolkit-tips-tricks-blogs-ef6542301c65
  3. https://www.bugcrowd.com/resources/webinars/5-tips-and-tricks-to-run-
    successful-bug-bounty-programs/
  4. https://www.youtube.com/watch?v=CU9Iafc-Igs&ab_channel=ST%C3%96K
  5. https://github.com/EdOverflow/bugbounty-cheatsheet
  6. https://chawdamrunal.medium.com/pro-tips-for-bug-bounty-
    f9982a5fc5e9
  7. https://medium.com/bugbountywriteup/bug-bounty-hunting-
    methodology-toolkit-tips-tricks-blogs-ef6542301c65
  8. https://www.bugcrowd.com/resources/webinars/5-tips-and-tricks-to-run-
    successful-bug-bounty-programs/
  9. https://www.youtube.com/watch?v=CU9Iafc-
    Igs&ab_channel=ST%C3%96K
  10. https://github.com/EdOverflow/bugbounty-cheatsheet
  11. https://github.com/djadmin/awesome-bug-bounty
  12. https://github.com/devanshbatham/Awesome-Bugbounty-Writeups
  13. https://github.com/Muhammd/awesome-bug-bounty
  14. https://github.com/ajdumanhug/awesome-bug-bounty-tips
  15. https://medium.com/bugbountyhunting/bug-bounty-toolkit-aa36f4365f3f
  16. https://github.com/nahamsec/Resources-for-Beginner-Bug-Bounty-
    Hunters
  17. https://github.com/bobby-lin/bug-bounty-guide

Writeups Bug Bounty

https://pentester.land/list-of-bug-bounty-writeups.html
https://medium.com/bugbountywriteup
https://github.com/yaworsk/bugbounty/blob/master/writeups.md
https://www.youtube.com/channel/UCNRM4GH-SD85WCSqeSb4xUA
https://paper.seebug.org/802/

Skills Development — YouTube Channels

STÖK (Fredrik Alexandersson)

Red Team Village DC Red Team Village

InsiderPhD Katie Paxton-Fear

Nahamsec Ben Sadeghipour

HackerOne

BugCrowd

The Cyber Mentor Heath Adams

John Hammond John H.

Codingo Michael S.

HackerSploitHackerSploit

https://youtube.com/c/HackerSploit

LiveOverflow

https://youtube.com/c/LiveOverflow

IPPSec

S4vitar Marcelo Vázquez(Spanish Content)

Zigoo Ebrahim Hegazy (Arabic )

ACADI-TI

Wraiith

Bsides

Vinicius Vieira

Kindred

Bug Bounty Public Disclosure

RoadSec

https://youtube.com/c/Roadsec

Mindthesec

Hackaflag

Blackhat

**more skill development youtube channel will be added.

Tools — Bug Bounty

Follow Me: Shakhawat Hossain @0xShakhawat

--

--