700th Post Special- Make money online finding bugs on websites

awesomewebsites

Elite Member
Jr. Executive VIP
Jr. VIP
Joined
Nov 16, 2011
Messages
19,802
Reaction score
11,280
This is my 700th post on this website and thus I would like to share one of the methods I had used to make money online.

First of all here is the earning proof for some motivation:

xs5zCuL

Uploaded as a file

Yes you read it right, I was paid $3000 for finding a bug on Facebook.

How to start finding bugs on websites:

1) I will suggest you start reading about the bugs reported by other researchers in the past. You can read the reports on hackerone.com . There are hundreds of reports explained on websites like Twitter, Uber.

2) For Facebook bugs, this link has all the bugs reported category wise:

https://www.facebook.com/notes/phwd...fref=gs&dti=349225725474262&hc_location=group

3) Now some of you might be thinking that I do not have technical knowledge to find the bugs. In reality, you can also find logical bugs which require no coding language. Try to copy steps mentioned for a past report on new websites.

Where to Submit Bugs

Facebook : https://www.facebook.com/whitehat/report/

Other Platforms: Hackerone.com and Bugcrowd

How much can I make with this ?

There is no limit to this. If you are good learner and lean the basics of bug hunting, you can earn decent money online. Top earners on Hackerone easily make $10000 - $20000 per month. To reach that level, you need to learn fast. All the best.

If you have any questions, post here and I will answer.

xs5zCuL


Adding the image of bug bounty I got from Facebook here as I am not able to edit my post now.
 

Attachments

  • FB bug payment.png
    FB bug payment.png
    32.5 KB · Views: 254
Last edited by a moderator:
Sounds technical haha. So how do they award simple logical bugs?
There was nothing technical involved, only thing required was observation. Simple logical bugs are paid based on severity. For instance, a guy found that clicking on an birthday event ( Born on) revealed the parents. He was paid $7500 for that. What technical knowledge is required for this ?
 
There was nothing technical involved, only thing required was observation. Simple logical bugs are paid based on severity. For instance, a guy found that clicking on an birthday event ( Born on) revealed the parents. He was paid $7500 for that. What technical knowledge is required for this ?
None. I just assumed your finding would be technical since it paid out 3k and you didn't elaborate. Congratulations on your find!
 
Thought it is the right time to update this. Facebok yesterday released the year summary regarding bug reports submitted in the year 2017.
$880,000 Paid to Researchers in total

Stats
  • This year we received more than 12,000 submissions, with over 400 valid reports.
  • The average reward per submission increased to almost $1,900, up from $1,675 last year.
  • We also saw an increase in new researchers participating - 32% of researchers with a reward in 2017 submitted for the first time this year.
  • India came out on top with the number of valid submissions in 2017, with the United States and Trinidad & Tobago in second and third place, respectively
You can read the full report here :
https://www.facebook.com/notes/face...-880000-paid-to-researchers/1918340204846863/

Next time you find a loophole on Facebook, do not exploit it. Be a good boy and report it to Facebook.
 
This is actually very interesting. Gonna have to look at other sites to see if they offer similar rewards. Thanks for the share.
 
Privacy issues exist on all sites. I have one fof Twitter, instagram and facebook. Just no reason to sell it because I'll make more long term abusing it
 
This is actually very interesting. Gonna have to look at other sites to see if they offer similar rewards. Thanks for the share.
You can find hundreds of them on Hackerone.
Privacy issues exist on all sites. I have one fof Twitter, instagram and facebook. Just no reason to sell it because I'll make more long term abusing it
You are able to abuse till a researcher or Facebook notices it. How long have you been abusing it ?
Wow this is awesome i had 2 3 in my mind !! Will send them

Thank you so much...
2-3, that can give $$$$-$$$$$. Do not forget my share. All the best.
 
Last edited:
You can find hundreds of them on Hackerone.

You are able to abuse till a researcher or Facebook notices it. How long have you been abusing it ?

2-3, that can give $$$-$$$$$. Do not forget my share. All the best.
Over a year. At this point a lot of people call it common knowledge and it's useful fof doxing. I don't dox but i know a lot of people who do and they already know this exploit
 
what if the bug is something like a simple action I do on fb and it doesn't happen. And I have to do it twice. Will something like this be called a bug ? what shall be the proof of this? a screen recording of it not working ?
 
what if the bug is something like a simple action I do on fb and it doesn't happen. And I have to do it twice. Will something like this be called a bug ? what shall be the proof of this? a screen recording of it not working ?
That is not considered a bug.
 
If I can get an access to some of my friends Facebook account with a simple trick, can I get paid if I report it?
 
If I can get an access to some of my friends Facebook account with a simple trick, can I get paid if I report it?
Does that trick works on all Facebook accounts ? If you have found a trick to access Facebook account of other users, you can expect $10000-$15000 for that bug. One such bug was reported in past and was paid $15000.
 
Does that trick works on all Facebook accounts ? If you have found a trick to access any Facebook account, you can expect $10000-$15000 for that bug.
Not on all Facebook accounts, but I think every person can do it for at least one of their friends.
 
I know one bug with password! I cannot enter to any account, but on each account i can enter with 2 password if I know one. Should i report that?
 
Not on all Facebook accounts, but I think every person can do it for at least one of their friends.
That should get paid but not much. There is no harm in reporting it, go for it. It is free and will hardly take few minutes.

I know one bug with password! I cannot enter to any account, but on each account i can enter with 2 password if I know one. Should i report that?
I need to understand this before making a reply here. Can you explain more clearly ?

I need to understand this before making a reply here. Can you explain more clearly ?

If i know your password for your account. I cant enter with similar, not yours. But it's different...

Or, you can enter on your account with 2 passwords. Not 1.

Or, you can enter on your account with 2 passwords. Not 1.
Still not able to understand. You can try submitting it to the Facebook team but explain everything clearly and add a video POC.

Ok I will.
 
Last edited by a moderator:
That should get paid but not much. There is no harm in reporting it, go for it. It is free and will hardly take few minutes.
Alright, I am going to report now.
How much do you think I can get paid for it?
 
Back
Top