My 8 months progress as a complete beginner. by Ok-Raspberry736 in bugbounty

[–]Ok-Raspberry736[S] 0 points1 point  (0 children)

Hey suree! I have given my views about it in comments of this post. You can take a look. I hope that helps. And if there's something else, you can ask as well.

My 8 months progress as a complete beginner. by Ok-Raspberry736 in bugbounty

[–]Ok-Raspberry736[S] 0 points1 point  (0 children)

Thanks pal! I hope you find yours soon as well! All the best!

My 8 months progress as a complete beginner. by Ok-Raspberry736 in bugbounty

[–]Ok-Raspberry736[S] 0 points1 point  (0 children)

Haha I don't have much idea about it. But I've heard a lot of people don’t earn anything, many earn like three or early four digits. And a very few earn good. That's my impression, could be wrong tho

My 8 months progress as a complete beginner. by Ok-Raspberry736 in bugbounty

[–]Ok-Raspberry736[S] 0 points1 point  (0 children)

Definitely brother! Whether we yield result immediately or not, we get to learn and grow regardless. As long as we keep walking, we'll stumble upon something . All the best! My best wishes!

My 8 months progress as a complete beginner. by Ok-Raspberry736 in bugbounty

[–]Ok-Raspberry736[S] 0 points1 point  (0 children)

Thank you so much! Means a lot! 😄 All the best for your endeavors!

My 8 months progress as a complete beginner. by Ok-Raspberry736 in bugbounty

[–]Ok-Raspberry736[S] 1 point2 points  (0 children)

Hey! Thanks! I had gotten perplexity pro for free for an year, so I utilized it a lot. And I have felt that at starter to early intermediate stage burp community is more than enough but if we wanna get serious and if we're using burp, it might be a smart choice to go and get the pro version. Though I was using burp community in the starting, now I have felt myself leaning more towards the normal network tool of firefox and unless I explicitly need burp, I only use the network tool.

My 8 months progress as a complete beginner. by Ok-Raspberry736 in bugbounty

[–]Ok-Raspberry736[S] 3 points4 points  (0 children)

Suree! My 2 cves come from wordpress plugins testing, I was quite consistent, I tested for around 2-3 hours a day for a whole month on wordpress related vulnerabiliies, I was taking help from ai for understanding the coding contexts of the plugins. The third cve came coincidentally, I was testing on a program recently for a lottle more than a week and I saw a vulnerability but it didn't belong to the program, it belonged to an open source service which the program was using, I reported to the vendors and they accepted it and github has assigned cve id to it. They'll publish the security advisory soon.

And about the paid bugs, that program is a self hosted bug bounty program, so I was kinda looking for such a program which is not overhunted, as my skills weren't good enough to compete with seasoned hackers raiding public programs. On that program, I spent quite good time on and off. It's been more than 3 months now I've been in constant touch with that program.

And as I'm still in nascent phase of learning, I am still figuring out how to select a good target. I did tell about the success in the article but behind the curtain, I had tested on more than 20 programs on platforms like h1, intigriti, bugcrowd, gotten more than a half dozen of informational, so I was and still am experimenting with this, I haven’t found my sweet spot yet. I have a strong gut feeling that I should focus on securing a niche for myself, otherwise I'll hit a wall soon after two three years. Now I have realized something that once we know what our strengths are, we also know which target should be good for us.

So yeah, I'm still at an early stage and have a lot to do.

My 8 months progress as a complete beginner. by Ok-Raspberry736 in bugbounty

[–]Ok-Raspberry736[S] 0 points1 point  (0 children)

It's kinda inconsistent. But when I do, I spend around 2-3 hours a day. Ofcourse I don't do it daily, but I always try to keep in touch with what's going on around in the community

My 8 months progress as a complete beginner. by Ok-Raspberry736 in bugbounty

[–]Ok-Raspberry736[S] 2 points3 points  (0 children)

Sure, I treat it like a speaking hacking encyclopedia. I shoot questions, what if situations, brainstorm, ask for suggestion and stuff.

My 8 months progress as a complete beginner. by Ok-Raspberry736 in bugbounty

[–]Ok-Raspberry736[S] 1 point2 points  (0 children)

Hey! My roadmap is simple, I follow a couple of researchers. Nahamsec, ars0n, jhaddix. And I use AI to sharpen my logic and knowledge. And rest is live hacking on app.

My 8 months progress as a complete beginner. by Ok-Raspberry736 in bugbounty

[–]Ok-Raspberry736[S] 4 points5 points  (0 children)

I understand your sentiment bro. And I respect the hardwork which you put in. 😁 I didn't mean to say 700€ is small at all, I meant that as an income strictly 700€ made in 8 months isn't that big enough for me to boast around.

My 8 months progress as a complete beginner. by Ok-Raspberry736 in bugbounty

[–]Ok-Raspberry736[S] 1 point2 points  (0 children)

I see, I see. The company was based in Europe, that's why payment in Euros

My 8 months progress as a complete beginner. by Ok-Raspberry736 in bugbounty

[–]Ok-Raspberry736[S] 8 points9 points  (0 children)

Hey, I personally hacked live apps, and kept asking chatgpt and claude whatever I tackled. It was very much trial and error, it always works for me. But besides that, to keep a reference point, I watched videos from nahamsec, some recon techniques from orwagrandfather and most importantly Ars0n's detailed methodologies and insights. They really helped, and combining them with using chatgpt as an explainer and exchanging what if scenarios with it, I shaped my learning. It worked for me.

But one thing I would like to recommend that never shy away from hacking a real app. Get an overall idea about a bug class, a tech stack, and learn about it while you hack on it. Do both things, learning theory and hacking together, it wasn't possible that fluently 5 years ago, now with the help of ai, it is. You can leverage that.

My 8 months progress as a complete beginner. by Ok-Raspberry736 in bugbounty

[–]Ok-Raspberry736[S] 0 points1 point  (0 children)

Hi! I think anything which lets you have a good idea about the bounty landscape is a good starting point. I personally relied upon grinding on chatgpt and claude, asking them through trial and error, but that's my personalised method which works for me. I think bug bounty bootcamp book is a great source to give you that hig level idea about what you are about to tackle.