Bug Bounty PlatformsBugcrowd- https://www.bugcrowd.com/
Hackerone - https://www.hackerone.com/
Synack- https://www.synack.com/
Japan Bug bounty Program- https://bugbounty.jp/
Cobalt- https://cobalt.io/
Zerocopter- https://zerocopter.com/
Hackenproof- https://hackenproof.com/
BountyFactory- https://bountyfactory.io
Bug Bounty Programs List- https://www.bugcrowd.com/bug-bounty-list/
AntiHack- https://www.antihack.me/
Some Books for reading about Bug Hunting
There are some books for Web application penetration testing methodology and hunting the web. Through this you learn the basics and essentials of penetration testing and bug hunting. Since bug bounties often include website targets, we’ll focus on getting you started with Web Hacking and later we’ll branch out.
- The Web Application Hacker’s Handbook
- OWASP Testing Guide
- Penetration Testing
- The Hacker Playbook 2: Practical Guide to Penetration Testing
- The Tangled Web: A Guide to Securing Web Applications
- Jhaddix Bug Hunting Methodology
- The Hacker Playbook-3
- Ethical Hacking and Penetration Guide
- Web Penetration Testing with Kali Linux
Practice makes Perfect!
While you’re learning it’s important to make sure that you’re also understanding and retaining what you learn. Practicing on vulnerable applications and systems is a great way to test your skills in simulated environments. These will give you an idea of what you’ll run up against in the real world.
- BWAPP
- Webgoat
- Rootme
- OWASP Juicy Shop
- Hacker101
- Hacksplaining
- Penetration Testing Practice Labs
- Damn Vulnerable iOS App (DVIA)
- Mutillidae
- Trytohack
- HackTheBox
- SQL Injection Practice
- Try Hack Me
Read tech Vulnerabilities POCs (Proof of Concepts) and write-ups from other hackers
Now that you’ve got a baseline understanding of how to find and exploit security vulnerabilities, it’s time to start checking out what other hackers are finding in the wild. Luckily the security community is quite generous with sharing knowledge and we’ve collected a list of write-ups & tutorials:
- Bug Bounty write-ups and POC
- Awesome Bug Bounty
- SecurityBreached-BugBounty POC
- Facebook Hunting POC
- Bug Hunting Tutorials
- PentesterLand Bug Bounty Writeups
- Hackerone POC Reports
- Bug Bounty POC
- Netsec on Reddit
- Bug Bounty World
Video Tutorial
- Rjitech
- JackkTutorials on YouTube
- DEFCON Conference videos on YouTube
- Hak5 on YouTube
- How To Shot Web — Jason Haddix, 2015
- Bug Bounty Hunting Methodology v2 — Jason Haddix, 2017
- Hunting for Top Bounties — Nicolas Grégoire, 2014
- The Secret life of a Bug Bounty Hunter — Frans Rosén, 2016
- SecurityIdiots
- BlackHat
- Injector PCA
- DevilKiller
- SulemanMalik
- Penetration Testing in linux
Usefull tips
ReplyDeleteThanks 👍👍👍 very helpful for us
ReplyDeleteWao here I got everything on a one page Thanks 👍👍👍
ReplyDelete