[Journey] Zero to $1,000/mo+ from Bug Bounty

Bamspeedy

Registered Member
Joined
Feb 19, 2022
Messages
57
Reaction score
41
I am starting a journey to turn Bug Bounty into a consistent income stream. I began with zero knowledge just a couple months ago. Since then, I've put a significant amount of time into learning how to find impactful bugs on web applications. I completed the entire CBBH course on HackTheBox, although I believe it was largely not a good use of my time considering what I know now in regards to actually finding bugs. My preferred methodology is manual hunting, specifically looking for Business Logic vulnerabilities.

I've recently transitioned from the learning phase to bug hunting primarily. Now I want to see where consistency can get me. So far I've found 3 bugs on public programs, one of which was a High severity bug that would have been worth $1,000 on its own, but it was marked as a duplicate, unfortunately.

I will continue investing 5-6 hours per day of bug hunting as I believe that consistent focus will develop into a minimum of $1,000/mo in bounties.

I'll update the thread as I log more hours and findings. Open to answering questions for those who are interested!
 
nice journey, thanks for sharing

i’d be curious to hear more about how you translated what you learned on htb (especially cbbh) into actual practical bug hunting.
what did you change in your approach once you started working on real programs?
 
Had a good week bug hunting. The consistency is already starting to pay off. I put over 40 solid hours of hunting since the last post. That means actively searching, analyzing HTTP logs, reading documentation, finding potential vulnerabilities, and learning of a specific web application.
I’m currently 'camping' on one specific program. My goal is to eventually understand the application’s functionality as well as the developers do. It’s a massive upfront time investment, but it’s the only way to find the high-impact bugs that automated tools miss. Even with my current limited knowledge of this scope, I’ve already submitted 2 High severity bugs since last week.

The Current Scoreboard:

  • Total submitted: 5
  • Pending Triage: 2 (Both High)
  • Duplicates: 1
  • Informational: 2
Depending on the triage outcome, those two pending bugs alone should put me well on my way toward my monthly goal. But the best advice I’ve picked up recently is to 'submit and forget.' Once the report is in, the payout is out of my hands. The goal is to just keep grinding and let the results take care of themselves.

nice journey, thanks for sharing

i’d be curious to hear more about how you translated what you learned on htb (especially cbbh) into actual practical bug hunting.
what did you change in your approach once you started working on real programs?
Thanks for the reply. To be honest, the biggest shift for me was realizing that the CBBH path is very 'pentest' heavy. HTB recently changed the name of the certification to Certified Web Exploitation Specialist (CWES), which is much more accurate. I wish they’d been more transparent about that early on; it would have saved me some time! The course is more about how to exploit very specific technical bugs than how to find bugs. To be fair, the latter is much more difficult to teach. Because you can't really teach someone how to think a certain way. There really is no substitute for hands on learning on real bug bounty programs. That’s why 80-90% of my focus now is just on hunting. I’m learning what I need as I go. I’ve found that I much prefer manual hunting for Business Logic bugs. It doesn't require as much deep technical exploitation knowledge, just a good understanding of how HTTP works and knowing how to navigate Burp Suite. The rest is just curiosity and persistence.
 
I am starting a journey to turn Bug Bounty into a consistent income stream. I began with zero knowledge just a couple months ago. Since then, I've put a significant amount of time into learning how to find impactful bugs on web applications. I completed the entire CBBH course on HackTheBox, although I believe it was largely not a good use of my time considering what I know now in regards to actually finding bugs. My preferred methodology is manual hunting, specifically looking for Business Logic vulnerabilities.

I've recently transitioned from the learning phase to bug hunting primarily. Now I want to see where consistency can get me. So far I've found 3 bugs on public programs, one of which was a High severity bug that would have been worth $1,000 on its own, but it was marked as a duplicate, unfortunately.

I will continue investing 5-6 hours per day of bug hunting as I believe that consistent focus will develop into a minimum of $1,000/mo in bounties.

I'll update the thread as I log more hours and findings. Open to answering questions for those who are interested!
you don't use any AI for help? you just spend a lot of time to find bugs manually, respect for that, good luck in your journey
 
Do you have any relevant foundation before completing the CBBH course on HackTheBox
 
Following this. The camping approach makes a lot of sense - deep knowledge of one app beats surface-level scanning across dozens.

Curious about a few things:
- How do you decide which program to camp on? Looking at payout history, scope size, or something else?
- What's your duplicate rate been like so far? That's what kills a lot of hunters I've talked to
- Are you sticking to one platform (HackerOne, Bugcrowd) or spreading across multiple?

40 hours of focused hunting per week is solid commitment. The business logic angle is smart too - those bugs tend to pay better than the low-hanging XSS stuff everyone else reports.
 
I am starting a journey to turn Bug Bounty into a consistent income stream. I began with zero knowledge just a couple months ago. Since then, I've put a significant amount of time into learning how to find impactful bugs on web applications. I completed the entire CBBH course on HackTheBox, although I believe it was largely not a good use of my time considering what I know now in regards to actually finding bugs. My preferred methodology is manual hunting, specifically looking for Business Logic vulnerabilities.

I've recently transitioned from the learning phase to bug hunting primarily. Now I want to see where consistency can get me. So far I've found 3 bugs on public programs, one of which was a High severity bug that would have been worth $1,000 on its own, but it was marked as a duplicate, unfortunately.

I will continue investing 5-6 hours per day of bug hunting as I believe that consistent focus will develop into a minimum of $1,000/mo in bounties.

I'll update the thread as I log more hours and findings. Open to answering questions for those who are interested!
Any news?
 
Any news?
UPDATE:
Apologies for the radio silence, I sorta forgot about this thread. But I've been hunting, still putting in a minimum of 3 hours a day, every day. Found lots of new bugs since my last post. Public programs have been an absolute meat grinder. The amount of triage BS I've been through in the past couple months would probably cause a lot of people to quit (I nearly did, multiple times). But I just keep pushing regardless.

Honestly, finding a new bug and submitting it is pretty thrilling. There's really nothing like knowing you outsmarted a security team with a million dollar budget. But more than that, there is a lot of satisfaction in it. Hunting forces me to think critically for very long periods, which can be exhausting. But the payoff is extremely rewarding even when I don't get paid.

The Current Scoreboard:

Total Bugs Submitted: 12
Accepted: 1
Under Review: 2
Duplicates: 4
Informative: 4
Out of Scope: 1
Potential Bounties: (Under Review): $1,000+
Total Bounty Awarded: $600

The 4 duplicates were an absolute gut punch. All of those submission were either High or Critical, meaning huge payouts worth thousands. The fact that they are duplicates means the program acknowledges that they are bugs, but I was just too slow. At least I got some reputation as a consolation prize.

3 of the bugs marked 'Informative' were acknowledged by triagers to be actual bugs, but considered an accepted risk.
I think only the first bug I ever submitted was truly 'Informative'. Looking back, I would never submit that report now.
Knowing what actually constitutes a legitimate finding, what programs will accept, and how to best argue impact is a skill in itself.

I'm quite happy to finally be getting invites to private programs. All of the successful hunters I see pretty much hunt on private only. I suppose cutting your teeth on public programs and getting hit with soul crushing duplicates is a rite of passage.

Following this. The camping approach makes a lot of sense - deep knowledge of one app beats surface-level scanning across dozens.

Curious about a few things:
- How do you decide which program to camp on? Looking at payout history, scope size, or something else?
- What's your duplicate rate been like so far? That's what kills a lot of hunters I've talked to
- Are you sticking to one platform (HackerOne, Bugcrowd) or spreading across multiple?

40 hours of focused hunting per week is solid commitment. The business logic angle is smart too - those bugs tend to pay better than the low-hanging XSS stuff everyone else reports.
Program selection is probably the single most important thing, honestly. I really took my time to look at all the programs on all of the major platforms (HackerOne, BugCrowed, Intigriti, etc). I have submissions on all of them. But I do intend to focus on one primarily to build up solid reputation. A lot of people recommend huge wildcard scope for beginners, but I think that's bad advice. If you want to hunt manually you actually want small scope, since you are looking at the logic of applications and not just running scans for low hanging fruit like subdomain takeovers.

For my specific strategy I look for SaaS applications with complex privilege structures. Or programs where the "treasure" is extremely obvious. For instance, if you have an application that promises secure messaging across users and you find ANY way to read a message when you aren't supposed to, that's a critical finding worth thousands. So it reduces the noise and you know exactly what you are looking for. That has been a successful approach for me, but probably why I've also had so many duplicates. This is why getting private invites is so crucial. But first you need to prove you can hack.
wish you good luck thank you for sharing
Thank you! Much appreciated.
that's cool but I'm pretty sure it's really exhausting for eyes
I'm lucky in that I've never seemed to have a problem with focusing on a screen for many hours.
Do you have any relevant foundation before completing the CBBH course on HackTheBox
I studied Computer Science in college, but that's about it. I took a completely different career path after that. I know multiple successful BB hunters that came into it with basically no prior knowledge. So don't let that stop you!
 
UPDATE:
Apologies for the radio silence, I sorta forgot about this thread. But I've been hunting, still putting in a minimum of 3 hours a day, every day. Found lots of new bugs since my last post. Public programs have been an absolute meat grinder. The amount of triage BS I've been through in the past couple months would probably cause a lot of people to quit (I nearly did, multiple times). But I just keep pushing regardless.

Honestly, finding a new bug and submitting it is pretty thrilling. There's really nothing like knowing you outsmarted a security team with a million dollar budget. But more than that, there is a lot of satisfaction in it. Hunting forces me to think critically for very long periods, which can be exhausting. But the payoff is extremely rewarding even when I don't get paid.

The Current Scoreboard:

Total Bugs Submitted: 12
Accepted: 1
Under Review: 2
Duplicates: 4
Informative: 4
Out of Scope: 1
Potential Bounties: (Under Review): $1,000+
Total Bounty Awarded: $600

The 4 duplicates were an absolute gut punch. All of those submission were either High or Critical, meaning huge payouts worth thousands. The fact that they are duplicates means the program acknowledges that they are bugs, but I was just too slow. At least I got some reputation as a consolation prize.

3 of the bugs marked 'Informative' were acknowledged by triagers to be actual bugs, but considered an accepted risk.
I think only the first bug I ever submitted was truly 'Informative'. Looking back, I would never submit that report now.
Knowing what actually constitutes a legitimate finding, what programs will accept, and how to best argue impact is a skill in itself.

I'm quite happy to finally be getting invites to private programs. All of the successful hunters I see pretty much hunt on private only. I suppose cutting your teeth on public programs and getting hit with soul crushing duplicates is a rite of passage.


Program selection is probably the single most important thing, honestly. I really took my time to look at all the programs on all of the major platforms (HackerOne, BugCrowed, Intigriti, etc). I have submissions on all of them. But I do intend to focus on one primarily to build up solid reputation. A lot of people recommend huge wildcard scope for beginners, but I think that's bad advice. If you want to hunt manually you actually want small scope, since you are looking at the logic of applications and not just running scans for low hanging fruit like subdomain takeovers.

For my specific strategy I look for SaaS applications with complex privilege structures. Or programs where the "treasure" is extremely obvious. For instance, if you have an application that promises secure messaging across users and you find ANY way to read a message when you aren't supposed to, that's a critical finding worth thousands. So it reduces the noise and you know exactly what you are looking for. That has been a successful approach for me, but probably why I've also had so many duplicates. This is why getting private invites is so crucial. But first you need to prove you can hack.

Thank you! Much appreciated.

I'm lucky in that I've never seemed to have a problem with focusing on a screen for many hours.

I studied Computer Science in college, but that's about it. I took a completely different career path after that. I know multiple successful BB hunters that came into it with basically no prior knowledge. So don't let that stop you!
Thanks for your update man.

This is the first time I'm seeing someone doing a bug bounty journey, so it got my interest.

I'm going the same route as you; I don't have a technical background, so I mostly focus on logic, BAC, and information disclosure bugs. I don't hunt every day like you, but I do get some bounty, and it's really nice. I'm thinking of going full-time hunting this year.

Have you tried e-commerce programs? They have a ton of logic bugs, especially if they have a mobile app. Their web app "might" be secure, but the mobile app isn't. You could test your skill there if you want, or go to a social media program like Fetlife (public program) on HackerOne, not a bad choice but their bounty is kinda low.

Good luck hunting and keep us updated.
 
Interesting journey!

From what you learned so far, what path would you recommend to someone that's interested in diving into hunting, starting from scratch?
What learning resources and topics would you recommend to start with and to focus on at the beginning?

Thanks in advance!
 
This is why getting private invites is so crucial. But first you need to prove you can hack.

I think private programs are not crucial for success. I have 150+ private programs, but I have succeeded mostly in public. Yeah, public programs are crowded, but in private programs, you compete against someone more experienced who was invited earlier than you.

Besides, most of the private programs bounty range is low (50-100$ for a low, 3000$ for a crit). So I think you pick a program you find fun and comfortable to hunt. If you hate that program, then hunting on it feels like hell, and you will burn out really quickly.
 
I really enjoyed reading what you posted. Do you have any technical knowledge?
You can take all the actions you do manually and turn them into a kind of Skill in Claude Code. That way you can let llm do all the repetitive / methodological / systematic work and you can focus on what requires a human perspective.
 
No update? I think OP gave up, sadly.
Haven't given up!
Still hunting pretty much every day. Though admittedly I've been struggling with motivation due to a few things regarding the current landscape of bug bounty. Such as:

Prominence of AI sucking a lot of joy that I initially got out of hunting and finding bugs. Before agents, I would use AI mostly as a tool to query things I didn't fully understand, or get payloads to test myself, or ask for direction on where to look next. That made it really useful without doing all the work for me. Now, it's really hard not to just point an agent at a target and just let it do its thing, with little involvement from me. I've found bugs this way, but it's extremely unsatisfying. I'm trying to work manual hunting back in, which helps avoid duplicates and brings some of the enjoyment back.

Duplicates as a result of everyone using the same AI agents. I haven't been hit quite as hard on dupes as some people I know, and I think that's mainly from picking my targets for the least amount of competition. I also try to dig deeper and push impact as much as possible. But it's still a major problem. It's hard to get excited about a finding when you know the chance of it being marked duplicate is high.

Slow triage time. I have a handful of reports now stuck in triage for 3+ months. And mind you, these are all High and Critical reports which triage has assessed as bugs, not duplicates, but haven't accepted or paid out. I'll gently ask for an update and just get completely ghosted. Extremely de-motivating, for sure.

Getting marked RTFS on legitimate bugs for no reason, then ghosted on appeal. The reality of bug bounty is a lot of thankless and unpaid work.

That said, I have been getting bugs accepted and paid. However I was hoping for much better results by this time, considering the amount of work I've put in.
I started bug bounty 1 year ago. I have logged over 1,000 hours of bug hunting and 200 or so hours of CTF and labs.

First year results:
Bugs submitted: 26
Total Accepted/Paid: 8
Total Bounty Awarded: $2,800
Pending Rewards based on Severity: $5,000 - $8,000

Even if I get paid the upper band of what's currently pending, it still falls short of my $1,000/mo goal, which I didn't think was too ambitious to begin with.

I'm going the same route as you; I don't have a technical background, so I mostly focus on logic, BAC, and information disclosure bugs.
Would love to hear how your experience has been. Are you still finding bugs? Are you getting paid?

From what you learned so far, what path would you recommend to someone that's interested in diving into hunting, starting from scratch?
Sorry for the late reply. If you're still looking, I would highly recommend starting with the Portswigger CTF labs. They are the easiest to get into and a great way to learn early on. AI is also extremely useful for learning. You can ask it to clarify things when you don't understand, and then have it test you.

I really enjoyed reading what you posted. Do you have any technical knowledge?
You can take all the actions you do manually and turn them into a kind of Skill in Claude Code. That way you can let llm do all the repetitive / methodological / systematic work and you can focus on what requires a human perspective.
Yeah, I think skills are the way to get the most out of agents. I've only dabbled with adding custom skills, so it's definitely something I need to start doing.
 
Back
Top