Can't find any bugs in bug bounty programs

0_p4th

Newbie
Joined
May 13, 2023
Messages
3
Reaction score
0
So it's been some couple months learning pentesting, bug bounty related attacks and CTFs. But the moment i switched to real bug bounty it felt like switching to GOD difficulty.
Even when trying a recent company on hackerone/bugcrowd i can't find even the simplest bug and i feel stuck and frustrated after wasting a day trying to find low level bugs.
I would appreciate any advice/video/course...etc that would help in reconn and scanning.
 
most tools are going to be used by most bounty hunters already. to find high paid/frequency bugs you need to join private programs. You join private programs by invite. you get an invite for submitting bugs (sometimes even if they are duplicates or non-paid). the private programs will have a select amount of hunters for a certain amount of time. this will be your best chance for the big payouts.

pick a niche. authentication vulnerabilities, access control, mobile applications etc. knowing what you're looking for and when to look for it matters.

do all of portswigger academy labs
 
Do not give up. You need to focus on one program at a time. Give it a few days, one day is not enough. Try Google related but bounty programs.
 
A couple months isn't enough, pal. You are competing with people with years of experience. Of course the most obvious vulnerabilities have been spotted.
 
Back
Top