Bug bounties pay for the same work attackers do — find the flaw before anyone else, prove it cleanly, collect. No jail risk, published scope, real money. This roadmap takes a beginner from zero to a first payout in 90 days: skills, targets, the bugs that actually pay, and the report format that gets triaged instead of trashed. Straight path, no motivational garbage.
TL;DR — Learn web fundamentals → recon at scale → chase IDOR/XSS/auth bugs → report like a professional. 90-day plan with daily structure below. The money lives in boring bugs nobody bothered to look for twice.
1. THE GAME (KID VERSION)
Kids' version: the school promises ten candy bars to anyone who finds a broken lock in the building. Front door locked. Fire door sticks. Window in the back gym doesn't latch. You walk the building, try every handle, write down which ones fail, hand the list to the principal, get candy.
That is a bug bounty. Company publishes a scope (which properties), rules (what you may touch), and rewards (what flaws pay). You hunt inside those lines, submit proof, get paid. HackerOne and Bugcrowd are the boards; hundreds of companies run private programs through them too. VDP-only programs pay nothing but build your reputation — skip them once you need money, use them for practice.
Important framing: bounty work is not criminal hacking with a permission slip. Scope is contractual. Touch something outside it and the permission evaporates instantly — the same action that earns a bounty inside scope earns a cease-and-desist outside it. Read the scope like a contract because it is one.
2. THE 90-DAY PLAN
Days 1–20 — foundation. HTTP without docs: methods, status codes, headers, cookies, how sessions ride requests. HTML/JS enough to read what the browser does. Burp Suite community edition installed and proxied from day one — every request visible, every response logged. Practice labs: PortSwigger Web Security Academy (free, ~80 labs — do the XSS, IDOR, access-control, and auth sections completely), then hackthebox web challenges.
Days 21–50 — recon machine. Pick 3 programs with wide scope and decent response times. Build the daily routine: subdomain enumeration (subfinder, amass), live-host probing (httpx), directory busting (ffuf with a quality wordlist), parameter discovery. Everything logged. The goal is a personal target database — every endpoint, every parameter, every forgotten staging box. Recon is 70% of bounty work and the part most people are too lazy to do thoroughly.
Days 51–90 — exploitation sprints. Morning: test yesterday's recon finds for the big four — IDOR, broken access control, XSS, auth flaws. Afternoon: write reports for anything confirmed. Evening: one PortSwigger lab on the topic you're weakest at. Submit at least one report per week even if small — reports build your signal score on the platform, and programs prioritize hunters with history.
3. BUGS THAT ACTUALLY PAY
The secret: IDOR and access-control bugs pay consistently because they are BORING. Everyone chases RCE glamour, nobody enumerates 4,000 endpoints checking whether ID=1043 becomes ID=1044. Change a number, get someone else's invoice, screenshot it, collect. Low skill floor, high persistence requirement.
4. RECON THAT FINDS REAL THINGS
Look specifically where bugs hide: staging/dev subdomains (weaker auth, test accounts), forgotten API versions (v1 never got patched), file upload endpoints (the classic), password-reset flows (token reuse, no expiry), and every endpoint taking an ID parameter (IDOR candidates — replace, increment, decode if base64).
5. THE REPORT THAT GETS PAID
Triagers handle dozens a day. Your report competes for their attention:
Duplicate handling: first valid report wins, everyone else gets "informative". Speed matters — but sloppy reports on new bugs beat perfect reports on old ones. Keep a personal tracker of every submission and triage response; your rejection reasons are a syllabus of what to learn next.
6. RULES OF THE ROAD
7. FIELD CHEAT SHEET
— RELATED GUIDES —
Scope read, labs cleared, recon pipeline running — 90 days from zero to first payout is a scheduling problem, not a talent problem. Daily enumeration, IDOR checks on every ID parameter, weekly submissions, reports written for triagers not for ego. Open the board, pick the target, start the clock.
TL;DR — Learn web fundamentals → recon at scale → chase IDOR/XSS/auth bugs → report like a professional. 90-day plan with daily structure below. The money lives in boring bugs nobody bothered to look for twice.
1. THE GAME (KID VERSION)
Kids' version: the school promises ten candy bars to anyone who finds a broken lock in the building. Front door locked. Fire door sticks. Window in the back gym doesn't latch. You walk the building, try every handle, write down which ones fail, hand the list to the principal, get candy.
That is a bug bounty. Company publishes a scope (which properties), rules (what you may touch), and rewards (what flaws pay). You hunt inside those lines, submit proof, get paid. HackerOne and Bugcrowd are the boards; hundreds of companies run private programs through them too. VDP-only programs pay nothing but build your reputation — skip them once you need money, use them for practice.
Important framing: bounty work is not criminal hacking with a permission slip. Scope is contractual. Touch something outside it and the permission evaporates instantly — the same action that earns a bounty inside scope earns a cease-and-desist outside it. Read the scope like a contract because it is one.
2. THE 90-DAY PLAN
Days 1–20 — foundation. HTTP without docs: methods, status codes, headers, cookies, how sessions ride requests. HTML/JS enough to read what the browser does. Burp Suite community edition installed and proxied from day one — every request visible, every response logged. Practice labs: PortSwigger Web Security Academy (free, ~80 labs — do the XSS, IDOR, access-control, and auth sections completely), then hackthebox web challenges.
Days 21–50 — recon machine. Pick 3 programs with wide scope and decent response times. Build the daily routine: subdomain enumeration (subfinder, amass), live-host probing (httpx), directory busting (ffuf with a quality wordlist), parameter discovery. Everything logged. The goal is a personal target database — every endpoint, every parameter, every forgotten staging box. Recon is 70% of bounty work and the part most people are too lazy to do thoroughly.
Days 51–90 — exploitation sprints. Morning: test yesterday's recon finds for the big four — IDOR, broken access control, XSS, auth flaws. Afternoon: write reports for anything confirmed. Evening: one PortSwigger lab on the topic you're weakest at. Submit at least one report per week even if small — reports build your signal score on the platform, and programs prioritize hunters with history.
3. BUGS THAT ACTUALLY PAY
| Bug class | Difficulty | Typical payout | Why it pays |
| IDOR (data access) | Easy | $100–$1,000 | Direct impact — other users' data on screen |
| Broken access control | Easy–Med | $200–$2,000 | Admin actions reachable by normal users |
| Stored XSS | Medium | $500–$5,000 | Session theft chains — triage loves impact |
| Auth bypass / reset flaws | Medium | $1,000–$5,000 | Account takeover = every account |
| SSRF (cloud pivot) | Hard | $1,000–$10,000+ | Cloud metadata access escalates everything |
| RCE on production | Hard | $5,000–$25,000+ | Full compromise — top of every table |
The secret: IDOR and access-control bugs pay consistently because they are BORING. Everyone chases RCE glamour, nobody enumerates 4,000 endpoints checking whether ID=1043 becomes ID=1044. Change a number, get someone else's invoice, screenshot it, collect. Low skill floor, high persistence requirement.
4. RECON THAT FINDS REAL THINGS
Bash:
# Subdomains → live hosts → content discovery
subfinder -d target.com -o subs.txt
httpx -l subs.txt -o live.txt
ffuf -u https://target.com/FUZZ -w raft-medium-directories.txt -o fuzz.json
# Parameter hunt on every live endpoint
paramspider -d target.com
# Old/dead subdomains (takeover candidates)
amass enum -passive -d target.com
# then check CNAMEs pointing at unclaimed cloud resources
Look specifically where bugs hide: staging/dev subdomains (weaker auth, test accounts), forgotten API versions (v1 never got patched), file upload endpoints (the classic), password-reset flows (token reuse, no expiry), and every endpoint taking an ID parameter (IDOR candidates — replace, increment, decode if base64).
5. THE REPORT THAT GETS PAID
Triagers handle dozens a day. Your report competes for their attention:
- Title — impact-first: "IDOR in /api/v2/invoices exposes any user's billing data by changing invoice_id". Never "XSS found".
- Summary — two sentences: what, whose data, confirmed how.
- Steps — numbered reproduction starting from a clean session. Account A does X, capture request, change ID to B's value, replay. Every click, every request.
- Evidence — full request/response pairs (Burp copy), screenshots with the payload visible, impact proof showing ANOTHER account's data — never your own.
- Impact — concrete: "any authenticated user can read any other user's invoices; scale = entire user base". No speculation chains about what an attacker MIGHT do — show what YOU did.
- Fix note — one line: "server-side ownership check on invoice_id". Signals you understand the bug, not just the tool output.
Duplicate handling: first valid report wins, everyone else gets "informative". Speed matters — but sloppy reports on new bugs beat perfect reports on old ones. Keep a personal tracker of every submission and triage response; your rejection reasons are a syllabus of what to learn next.
6. RULES OF THE ROAD
- Scope check before every test session — subdomains drift in and out of scope monthly.
- No social engineering, no physical testing, no DoS/traffic flooding — instant ban from most programs.
- Data access: take the minimum proof (one screenshot, one record), never bulk-download — that crosses from research into offense fast.
- Public disclosure waits for the program's timeline. Posting a zero-day on Twitter before the fix ships ends bounty careers.
- VPN/home IP consistency helps — sudden Tor exits during testing get accounts flagged for review.
7. FIELD CHEAT SHEET
| Stage | Tool / move |
| Foundation | PortSwigger labs — XSS, IDOR, auth sections |
| Recon | subfinder + httpx + ffuf, daily pipeline |
| Hunt focus | IDOR → access control → XSS → auth |
| Request replay | Burp repeater, change IDs, compare responses |
| Report | impact title + numbered repro + request evidence |
| Signal | submit weekly, track triage feedback, iterate |
— RELATED GUIDES —
- XSS Explained: The Bug That Owns Browsers
- Subdomain Takeover 2026: The DNS Gap Nobody Scans
- Google Dorks List: 40 Ready-to-Run Dorks for 2026
- OSINT: How to Find Almost Anyone Online
- Kali Linux: The Complete Beginner Field Manual
- How Platforms Detect Cashout: Fraud Signals 101
- Cashout OpSec: Discipline After the Exit
Scope read, labs cleared, recon pipeline running — 90 days from zero to first payout is a scheduling problem, not a talent problem. Daily enumeration, IDOR checks on every ID parameter, weekly submissions, reports written for triagers not for ego. Open the board, pick the target, start the clock.
Last edited: