Got paid for reporting another security bug today

awesome work bud! quick question how many hours does it take you to find these? this is not my forte but it seems like a lot of work, mind you that is a sweet payment!
 
awesome work bud! quick question how many hours does it take you to find these? this is not my forte but it seems like a lot of work, mind you that is a sweet payment!
This particular bug took less than an hour. I first found this bug on another site. And then started checking other sites one by one for the same bug.
 
People on I2P and freenet pay for bugs as well,,, still better off marketing, under the wire. Congrats OP on your bounty.
 
@OP any forum that talk about hacking and exploit?
I would like to join such forum to learn and gain some grounds in this niche.
 
How long did it actually take you to find the bug?
An hour.
@OP any forum that talk about hacking and exploit?
I would like to join such forum to learn and gain some grounds in this niche.
The are Facebook groups and blogs. Best is to read already disclosed reports on sites like Hackerone.
 
People who find bugs are very talented and have a very inquisitive mind.

To do this sort of job you need a good understanding of the language you're hunting in, and be able to spot syntax errors, memory overruns etc.

I have been a developer since the days of hex, assembly language and machine code.
You need to enjoy doing this sort of thing, otherwise it becomes a chore.

For me, the better ROI on my time is writing software and selling, I can earn better money this way.

I think that the bug bounties payed by some companies are on the small side, especially when it comes to google.

Good luck OP.
Any suggestion of a place to sell scripts/code or just enroll in a job
 
oh thats 750.00 USD, though thats 75000 USD. LMAO


anyway nice op
 
I don't have any knowledge with this,
and saw another thread confirming this method and from there
i found a program called Zap Proxy,
and tested some websites in bug crowd,
then i found a SQL injection ( the severity is P1)
but i have no idea what to do next ? (I think i will miss up 1000$)
 
I don't have any knowledge with this,
and saw another thread confirming this method and from there
i found a program called Zap Proxy,
and tested some websites in bug crowd,
then i found a SQL injection ( the severity is P1)
but i have no idea what to do next ? (I think i will miss up 1000$)
Good luck with this finding. Hope you find more.
 
Back
Top