@MalikDisha8108 It was Bulk PII Disclosure of many users via GET API query, only difficult part was that it was accepting UUID as parameter value which I got many from waybackurls
@yussuff111 On medium you can read some good reports about each vulnerability types like IDOR, SQLi, SSRF and when you are hunting on a program you will remember these reports tricks and it will help you to get some cool findings
@yussuff111 I am using medium articles for learnings new attack methods, Portswigger web security academy labs for getting hands on experience about vulnerability
@Shravan73962 If you are having experience in web development then you can start with hackthebox or portswigger Web security academy and read hackerone disclosed reports and medium. Com infosec write-up
Challenge to earn 5000 USD Bounties from Bug-bounty Day-7:-
Study: 1 hour
Hunt: 3 Hour
Bugs submit today: 1 Also have some bug which i will be submitting
Bugs submitted total: 12
Duplicates Bugs: 3
Triaged: 1
Bounty Earned: 1000 USD
@whats_next9 Bro, choose the target based on your favourite bug type, like say you like Auth bypass kind of vulnerability then you should choose a target which has many roles like Admin, Owner, Viewer, Guest etc