How to start Bug Hunting?
1. First of all, you need to understand what is Bug Bounty and why it is done?
A bug bounty program is a deal offered by many websites and software developers by which individuals can receive recognition and compensation for reporting bugs, especially those about exploits and vulnerabilities.
2.Some Books online books for Bug Bounty!!!
There are some books for Web application penetration testing methodology and hunting the web. Through this, you learn the basics and essentials of penetration testing and bug hunting.
- The Web Application Hacker’s Handbook
- OWASP Testing Guide
- Highly suggested by Bugcrowd’s Jason Haddix
- Penetration Testing
- The Hacker Playbook 2: Practical Guide to Penetration Testing
- The Tangled Web: A Guide to Securing Web Applications
- Jhaddix Bug Hunting Methodology
- The Hacker Playbook-3
- Ethical Hacking and Penetration Guide
- Web Penetration Testing with Kali Linux
Here are some mobile application for Bug Hunting
- The Mobile Application Hacker’s Handbook
- iOS Application Security
- Owasp Mobile AppSec
While you’re learning it’s important to make sure that you’re also understanding and retaining what you learn. Practicing on vulnerable applications and systems is a great way to test your skills in simulated environments.
Some website provides you real websites to practice your skills!!
- BWAPP
- Webgoat
- Rootme
- OWASP Juicy Shop
- Hacker101
- Hacksplaining
- Penetration Testing Practice Labs
- Damn Vulnerable iOS App (DVIA)
- Mutillidae
- Trytohack
- HackTheBox
- SQL Injection Practice
4. Read tech Vulnerabilities POCs (Proof of Concepts) and write-ups from other hackers
- Bug Bounty write-ups and POC
- Awesome Bug Bounty
- SecurityBreached-BugBounty POC
- Facebook Hunting POC
- Bug Hunting Tutorials
- PentesterLand Bug Bounty Writeups
- Hackerone POC Reports
- Bug Bounty POC
- Netsec on Reddit
- Bug Bounty World
5. Some youtube channels for making concepts clear for you!!
- JackkTutorials on YouTube
- DEFCON Conference videos on YouTube
- Hak5 on YouTube
- How To Shot Web — Jason Haddix, 2015
- Bug Bounty Hunting Methodology v2 — Jason Haddix, 2017
- Hunting for Top Bounties — Nicolas Grégoire, 2014
- The Secret Life of a Bug Bounty Hunter — Frans Rosén, 2016
- Finding Bugs with Burp Plugins & Bug Bounty 101 — Bugcrowd, 2014
- How to hack all the bug bounty things automagically reap the rewards profit — Mike Baker, 2016
- SecurityIdiots
- BlackHat
- Injector PCA
- DevilKiller
- SulemanMalik
- Penetration Testing in Linux
6. Web Vulnerability Scanners Tools for Bug Bounty!!
- Netsparker Application Security Scanner — Application security scanner to automatically find security flaws.
- Nikto — Noisy but fast black box web server and web application vulnerability scanner.
- Arachni — Scriptable framework for evaluating the security of web applications.
- w3af — Web application attack and audit framework.
- Wapiti — Black box web application vulnerability scanner with built-in fuzzer.
- SecApps — In-browser web application security testing suite.
- WebReaver — Commercial, graphical web application vulnerability scanner designed for macOS.
- WPScan — Black box WordPress vulnerability scanner.
- Zoom — Powerful WordPress username enumerator with infinite scanning.
- cms-explorer — Reveal the specific modules, plugins, components, and themes that various websites powered by content management systems are running.
- joomscan — Joomla vulnerability scanner.
- ACSTIS — Automated client-side template injection (sandbox escape/bypass) detection for AngularJS.
- SQLmate — A friend of sqlmap that identifies sqli vulnerabilities based on a given dork and website (optional).
Comments
Post a Comment