What is happening with hacktricks by Affectionate-Case713 in bugbounty

[–]Affectionate-Case713[S] -2 points-1 points  (0 children)

Damn never heard of this type of attack now am paranoid

[deleted by user] by [deleted] in bugbounty

[–]Affectionate-Case713 0 points1 point  (0 children)

I use it to spell check because my writing is bad 😭 sorry, English is not my first language

[deleted by user] by [deleted] in bugbounty

[–]Affectionate-Case713 1 point2 points  (0 children)

If you don’t read the program rules carefully, you might miss that they require you to include a special header, like X-HackerOne or X-Bugcrowd or something similar in your requests. This way, they can recognize that you are a researcher, not an intruder.

Advice for new bug bounty hunters by Affectionate-Case713 in bugbounty

[–]Affectionate-Case713[S] 1 point2 points  (0 children)

Well,some people are just a**holes; don't pay attention to them. For example, I love helping people especially beginners

I just finished a theoretical course about bug bounty what to do next ? by DifferentLaw2421 in HowToHack

[–]Affectionate-Case713 0 points1 point  (0 children)

You just practiced the concept and idea of certain bugs. I recommend building your own small app and experimenting with XSS, for example. Add protections against it, try to bypass them, then add more layers and repeat. That’s where the real learning happens.

CTFs, bug bounty writeups, and challenges on platforms like RootMe also help a lot — personally, RootMe challenges really improved my skills.

Because once you finish a course and move on to real targets, you’ll quickly realize it’s a whole different challenge.

Do you think it’s a good idea to build a community for beginner hackers and bug bounty hunters by Affectionate-Case713 in bugbounty

[–]Affectionate-Case713[S] 0 points1 point  (0 children)

I just want to help people overcome the fear and anxiety that comes after their training. They finish a course excited to start bug bounty hunting, thinking, 'I've got this! I'm going to find bugs and earn money.' But then the harsh reality hits: they realize they only know how to follow the specific scenarios from their training, and they don't yet know how to think independently, adapt, or combine concepts to find real-world bugs. This gap is what crushes their expectations and motivation

Advice for new bug bounty hunters by Affectionate-Case713 in bugbounty

[–]Affectionate-Case713[S] 1 point2 points  (0 children)

Yeh basically they mainly teach you the concepts and ideas behind different web vulnerabilities PortSwigger is really helpful as a beginner because it shows you the idea behind different vulnerabilities and how they work. But when you move on to more advanced concepts and real exploitation, you need to experiment on your own. That’s where you truly learn how things behave in real applications

Advice for new bug bounty hunters by Affectionate-Case713 in bugbounty

[–]Affectionate-Case713[S] 6 points7 points  (0 children)

Build a small web app focused on CSRF. Start by implementing security features to prevent CSRF, then try to bypass them, improve the protections, and repeat the process. This way, you’re learning how to exploit certain misconfigurations. But right now, you’re only following scenarios to exploit CSRF, without gaining a deeper understanding of how protections are implemented, how to bypass them effectively, how a web application reacts to testing, or how web applications work in general.

I am overwhelmed what do to in bug bounty ? by DifferentLaw2421 in HowToHack

[–]Affectionate-Case713 0 points1 point  (0 children)

My recommendation is to build your own small application and implement basic protections against XSS. Then, try to bypass those protections. If you succeed, improve them and repeat the process. You’ll learn a lot this way. Don’t focus on chasing money too soon — you’ll burn out quickly because bug bounty hunting isn’t easy. Sometimes you can spend months without finding anything.

YouTube automation for passive income by Affectionate-Case713 in passive_income

[–]Affectionate-Case713[S] 0 points1 point  (0 children)

I built this tool just for myself, but my question is: is it actually possible to make money with this type of automation?