I've been in the bug bounty scene for over a decade now. $2M in bounties later, I figured it was time to sit down and talk about everything I've learned! 👉🏼 https://t.co/08n3TETXvc
Bug bounty question:
If you submit a bug, and it gets marked as an internal dupe because "the team already knew about it", is it fair to ask for proof?
@SupportWakefit Pathetic experience! Ordered 2 wardrobes on Sept 21, delivery due Oct 25 — still “in process.” Now told to wait till Nov 18! More 1 month of delay = loss for me. If not delivered by Nov 1, I’ll escalate this legally. Need accountability from upper management!
@WakefitCo Pathetic experience! Ordered 2 wardrobes on Sept 21, delivery due Oct 25 — still “in process.” Now told to wait till Nov 18! More 1 month of delay = loss for me. If not delivered by Nov 1, I’ll escalate this legally. Need accountability from upper management!
If you can't hack yourway into learning hacking from available resources, you don't have what it takes to be a hacker or you'll never become a great one. In other words, this is something you achieve the hard way and not something you can buy.
#bugbountytips#bugbounty
If you are hunting on finely established companies, try out some tutorials or guiding videos of them, you will find some features which you never used in other ways and the secret is, no one else did also.
#bugbountytip [2]
Never let your pending/open report number bar less than 1.
That will become your motivation to pay more time in finding more creative critical issues, because you know even if you fail, you have some reports pending which will pay you at the end.
#bugbountytips [6]
To know internal technologies study career/job openings of your target, your can see the required skills in specific technology in JD. Now you can modify your recon based on that.
Here's a snippet from @TomNomNom's recent appearance on @TheASWPodcast. Watch the entire interview w/ @Codexatron here: https://t.co/3O6BAbwwwh #security#API
#!/bin/bash
for i in {1..100};
do
sleep 1d
if [welcomeTweet == true] && [$user == 'Scalar360'];
then
echo "Thanks @detectify"
else
echo "Tweet not found, day $i "
fi
done
Result:
Tweet not found, day 43
Tweet not found, day 44
Tweet not found, day 45
A lot of people who want to do bug bounties for a living, but should you? Let's discuss!
📽️Video: https://t.co/Bhj8CEcH6D
✍️Written (most detailed): https://t.co/4enPQsvYTP