Blacksec

Administrator
Staff member
ROOT
VIP
Bug bounties pay for the same work attackers do — find the flaw before anyone else, prove it cleanly, collect. No jail risk, published scope, real money. This roadmap takes a beginner from zero to a first payout in 90 days: skills, targets, the bugs that actually pay, and the report format that gets triaged instead of trashed. Straight path, no motivational garbage.

TL;DR — Learn web fundamentals → recon at scale → chase IDOR/XSS/auth bugs → report like a professional. 90-day plan with daily structure below. The money lives in boring bugs nobody bothered to look for twice.

1. THE GAME (KID VERSION)

Kids' version: the school promises ten candy bars to anyone who finds a broken lock in the building. Front door locked. Fire door sticks. Window in the back gym doesn't latch. You walk the building, try every handle, write down which ones fail, hand the list to the principal, get candy.

That is a bug bounty. Company publishes a scope (which properties), rules (what you may touch), and rewards (what flaws pay). You hunt inside those lines, submit proof, get paid. HackerOne and Bugcrowd are the boards; hundreds of companies run private programs through them too. VDP-only programs pay nothing but build your reputation — skip them once you need money, use them for practice.

Important framing: bounty work is not criminal hacking with a permission slip. Scope is contractual. Touch something outside it and the permission evaporates instantly — the same action that earns a bounty inside scope earns a cease-and-desist outside it. Read the scope like a contract because it is one.

2. THE 90-DAY PLAN

Days 1–20 — foundation. HTTP without docs: methods, status codes, headers, cookies, how sessions ride requests. HTML/JS enough to read what the browser does. Burp Suite community edition installed and proxied from day one — every request visible, every response logged. Practice labs: PortSwigger Web Security Academy (free, ~80 labs — do the XSS, IDOR, access-control, and auth sections completely), then hackthebox web challenges.

Days 21–50 — recon machine. Pick 3 programs with wide scope and decent response times. Build the daily routine: subdomain enumeration (subfinder, amass), live-host probing (httpx), directory busting (ffuf with a quality wordlist), parameter discovery. Everything logged. The goal is a personal target database — every endpoint, every parameter, every forgotten staging box. Recon is 70% of bounty work and the part most people are too lazy to do thoroughly.

Days 51–90 — exploitation sprints. Morning: test yesterday's recon finds for the big four — IDOR, broken access control, XSS, auth flaws. Afternoon: write reports for anything confirmed. Evening: one PortSwigger lab on the topic you're weakest at. Submit at least one report per week even if small — reports build your signal score on the platform, and programs prioritize hunters with history.

3. BUGS THAT ACTUALLY PAY

Bug classDifficultyTypical payoutWhy it pays
IDOR (data access)Easy$100–$1,000Direct impact — other users' data on screen
Broken access controlEasy–Med$200–$2,000Admin actions reachable by normal users
Stored XSSMedium$500–$5,000Session theft chains — triage loves impact
Auth bypass / reset flawsMedium$1,000–$5,000Account takeover = every account
SSRF (cloud pivot)Hard$1,000–$10,000+Cloud metadata access escalates everything
RCE on productionHard$5,000–$25,000+Full compromise — top of every table

The secret: IDOR and access-control bugs pay consistently because they are BORING. Everyone chases RCE glamour, nobody enumerates 4,000 endpoints checking whether ID=1043 becomes ID=1044. Change a number, get someone else's invoice, screenshot it, collect. Low skill floor, high persistence requirement.

4. RECON THAT FINDS REAL THINGS

Bash:
# Subdomains → live hosts → content discovery
subfinder -d target.com -o subs.txt
httpx -l subs.txt -o live.txt
ffuf -u https://target.com/FUZZ -w raft-medium-directories.txt -o fuzz.json

# Parameter hunt on every live endpoint
paramspider -d target.com

# Old/dead subdomains (takeover candidates)
amass enum -passive -d target.com
# then check CNAMEs pointing at unclaimed cloud resources

Look specifically where bugs hide: staging/dev subdomains (weaker auth, test accounts), forgotten API versions (v1 never got patched), file upload endpoints (the classic), password-reset flows (token reuse, no expiry), and every endpoint taking an ID parameter (IDOR candidates — replace, increment, decode if base64).

5. THE REPORT THAT GETS PAID

Triagers handle dozens a day. Your report competes for their attention:

  • Title — impact-first: "IDOR in /api/v2/invoices exposes any user's billing data by changing invoice_id". Never "XSS found".
  • Summary — two sentences: what, whose data, confirmed how.
  • Steps — numbered reproduction starting from a clean session. Account A does X, capture request, change ID to B's value, replay. Every click, every request.
  • Evidence — full request/response pairs (Burp copy), screenshots with the payload visible, impact proof showing ANOTHER account's data — never your own.
  • Impact — concrete: "any authenticated user can read any other user's invoices; scale = entire user base". No speculation chains about what an attacker MIGHT do — show what YOU did.
  • Fix note — one line: "server-side ownership check on invoice_id". Signals you understand the bug, not just the tool output.

Duplicate handling: first valid report wins, everyone else gets "informative". Speed matters — but sloppy reports on new bugs beat perfect reports on old ones. Keep a personal tracker of every submission and triage response; your rejection reasons are a syllabus of what to learn next.

6. RULES OF THE ROAD

  • Scope check before every test session — subdomains drift in and out of scope monthly.
  • No social engineering, no physical testing, no DoS/traffic flooding — instant ban from most programs.
  • Data access: take the minimum proof (one screenshot, one record), never bulk-download — that crosses from research into offense fast.
  • Public disclosure waits for the program's timeline. Posting a zero-day on Twitter before the fix ships ends bounty careers.
  • VPN/home IP consistency helps — sudden Tor exits during testing get accounts flagged for review.

7. FIELD CHEAT SHEET

StageTool / move
FoundationPortSwigger labs — XSS, IDOR, auth sections
Reconsubfinder + httpx + ffuf, daily pipeline
Hunt focusIDOR → access control → XSS → auth
Request replayBurp repeater, change IDs, compare responses
Reportimpact title + numbered repro + request evidence
Signalsubmit weekly, track triage feedback, iterate

— RELATED GUIDES —

Scope read, labs cleared, recon pipeline running — 90 days from zero to first payout is a scheduling problem, not a talent problem. Daily enumeration, IDOR checks on every ID parameter, weekly submissions, reports written for triagers not for ego. Open the board, pick the target, start the clock.
 
Last edited: