ALERT!
Click here to register with a few steps and explore all our cool stuff we have to offer!

Jump to content



Photo

+1200GBP made this from Bug Bounty hunting


  • Please log in to reply
+1200GBP made this from Bug Bounty hunting

#1

DavidLaid
DavidLaid
    Offline
    19
    Rep
    29
    Likes

    Crack'd up on DMAA & Ephedrine

  • PipPipPipPipPip
Posts: 205
Threads: 37
Joined: May 01, 2018
Credits: 0

Five years registered
#1

Hello,

I want to share my earnings from Bug Bounty hunting, i have been learning a lot in the past 6 weeks.

I have been trying to search bugs on one company even when i have ran out of ideas,

i sticked to the same company and weeks later i have found several high security bugs.

I sent it to them and today i logged in PayPal and recieved +1100 GBP + 100GBP they sent me few weeks ago.

My tip would be stick to same company, learn about them, learn about their platform, start testing things and eventually you will find something.

 

Bounty(1100GBP and 100GBP):

 

98mVtIK.png

 

GHVBIy6.png

 

This is just start...

I hope that I have motivated at least 1 person to start learning about bug hunting.


  • 5

#2

Poosy
Poosy
    Offline
    73
    Rep
    176
    Likes

    ヾ(≧▽≦*)o

Posts: 911
Threads: 47
Joined: Jun 16, 2015
Credits: 0

Eight years registered
#2
Wow, how do you make sure they pay you?

Negotiate a bug bounty program with them?

  • 0

#3

DavidLaid
DavidLaid
    Offline
    19
    Rep
    29
    Likes

    Crack'd up on DMAA & Ephedrine

  • PipPipPipPipPip
Posts: 205
Threads: 37
Joined: May 01, 2018
Credits: 0

Five years registered
#3

Wow, how do you make sure they pay you?

Negotiate a bug bounty program with them?

 

You need to find company which have Bug Bounty program, if they dont i think its illegal to search for bugs on their websites.

For example: hackeroneDOTcom or bugcrowdDOTcom have many programs which pay you for bugs.


  • 1

#4

Poosy
Poosy
    Offline
    73
    Rep
    176
    Likes

    ヾ(≧▽≦*)o

Posts: 911
Threads: 47
Joined: Jun 16, 2015
Credits: 0

Eight years registered
#4

You need to find company which have Bug Bounty program, if they dont i think its illegal to search for bugs on their websites.
For example: hackeroneDOTcom or bugcrowdDOTcom have many programs which pay you for bugs.


Nice. How did you build experience in this expertise?

  • 0

#5

R3venantR
R3venantR
    Offline
    0
    Rep
    2
    Likes

    New Member

Posts: 24
Threads: 2
Joined: Nov 15, 2017
Credits: 0
Six years registered
#5

Nice! What sort of evidence do you have to show the company or the bug bounty program? Do you need to detail exactly what you did, or just point them in the direction? And do those bug bounties, like hackerone set the reward amount, or is that down to the company you target to offer an amount based on what you find? I mean 1200 is no laughing matter, well done.


  • 0

#6

worlockt
worlockt
    Offline
    912
    Rep
    408
    Likes

    Currency Exchanger

Posts: 428
Threads: 40
Joined: May 18, 2018
Credits: 307

Five years registered
#6

This is a good start.

6 weeks time and you earn good figure.

Keep improving.


  • 1

I am here for currency exchange service.
PM me
Telegram: t.me/worlockt
( Click above link. )

 

Confirm me via PM before deal off-site.


#7

DavidLaid
DavidLaid
    Offline
    19
    Rep
    29
    Likes

    Crack'd up on DMAA & Ephedrine

  • PipPipPipPipPip
Posts: 205
Threads: 37
Joined: May 01, 2018
Credits: 0

Five years registered
#7

Nice! What sort of evidence do you have to show the company or the bug bounty program? Do you need to detail exactly what you did, or just point them in the direction? And do those bug bounties, like hackerone set the reward amount, or is that down to the company you target to offer an amount based on what you find? I mean 1200 is no laughing matter, well done.

 

To prove you found valid bug you need to send them valid Proof Of Concept (PoC) which explains how the bug could impact their customers or them.

hackerone is just platform in the middle, the amount of reward you will recieve depends how big the impact is, but XSS is usually 500-5000$(reward also depends how big the company is because of their budget)

Then you can withdraw via hackerone to btc/paypal/bank...


  • 0

#8

Hynk7
Hynk7
    Offline
    30
    Rep
    46
    Likes

    Junkie

Posts: 329
Threads: 21
Joined: Jun 17, 2018
Credits: 0

Five years registered
#8

Holy fucking shit, that's a lot of money.. 

 

Congrats dude and thanks for sharing this with us. I might try it myself. :D 


  • 1

:ohgod:

Discord - Hynk#2190


#9

R3venantR
R3venantR
    Offline
    0
    Rep
    2
    Likes

    New Member

Posts: 24
Threads: 2
Joined: Nov 15, 2017
Credits: 0
Six years registered
#9

To prove you found valid bug you need to send them valid Proof Of Concept (PoC) which explains how the bug could impact their customers or them.

hackerone is just platform in the middle, the amount of reward you will recieve depends how big the impact is, but XSS is usually 500-5000$(reward also depends how big the company is because of their budget)

Then you can withdraw via hackerone to btc/paypal/bank...

 

Nice, thanks for the info. Good luck with your future bounties. Definitely something to think about.


  • 1

#10

vfgerhgg
vfgerhgg
    Offline
    0
    Rep
    1
    Likes

    Advanced Member

  • PipPipPipPip
Posts: 113
Threads: 1
Joined: Jun 28, 2018
Credits: 0
Five years registered
#10

That;s sick bro


  • 1


 Users browsing this thread: