Identifying Our Target from Bugcrowd

8 hours ago 9
BOOK THIS SPACE FOR AD
ARTICLE AD

Tasneem Sahat

In this tutorial, we will discuss how to identify our target for bug hunting. First, we need to choose a platform where we can find targets. Many platforms offer bug bounty programs where companies invite hackers to pentest their sites and report vulnerabilities in exchange for rewards.

The most popular platforms for this are Bugcrowd and HackerOne, where many hackers participate in bug bounty programs and earn money by finding security flaws.

Today, we will focus on Bugcrowd.

Go to bugcrowd.com and navigate to the Programs section.Here, you’ll find a list of companies running bug bounty programs, each offering rewards based on the severity of vulnerabilities.Choose a program and read the details carefully. The rules will clearly state that after finding a bug, you need to submit a valid Proof of Concept (PoC). (We’ll discuss how to create a PoC later.)In-scope Targets: The list of assets where you are allowed to perform pentesting.Out-of-scope Targets: These are restricted, meaning you cannot test them.Bounties: Each vulnerability has a different reward based on its impact.

Once we’ve selected our target, we can start hunting for bugs!

Contact Me: mdsahat6397@gmail.com.

Read Entire Article