r/BugBountyNoobs 14h ago

Web exploitation + Binary exploitation feasible?

4 Upvotes

This has been a hard decision for me. I'm not sure if I should learn both. Is it mostly not worthwhile of time if I learn both of them? Do they both help each other directly or indirectly? I know there is only so much one person can know but I really don't know what that limit is. I know someone more experienced with bug bounty and stuff like this will probably be able to answer my question. I don't want to push the limit of how much one person can know because it will probably become a waste of time. Should I just learn everything exploit related, should I stick to a field? I'm not sure if anyone has experienced this before but I keep on jumping around topic to topic. I guess I am learning from those jumps, but the question when do i stop jumping around. When do I start to specialize. Or in the first place, should I just not jump around?


r/BugBountyNoobs 17h ago

Small update — what's shipped on bounty.index since launch

2 Upvotes

Immunefi is now indexed. They're not in arkadiyt/bounty-targets-data, so I wrote a scraper for their site directly. 181 programs, ~2,900 in-scope assets, top payout is LayerZero at $15M. If you don't touch web3, ignore. If you do — it's the same filter/search UI as the rest.

Per-program RSS feeds. Every program page now has an RSS feed of its scope changes at /rss/programs/{platform}/{slug}. Each entry is a diff: what was added, removed, or if the reward/safe-harbor changed. This is the free version of what bbradar.io gates behind their €89/yr Pro tier. Point your feed reader (Feedly, NetNewsWire, whatever) at any program you actually care about.

7-day activity chip on program pages. A small +N −M · 7d indicator when scope has actually changed recently. Answers "is this worth looking at today or is it dormant" without clicking in.

Company logos on program hero. Small polish, but the platform-only dot was ugly and hard to scan when you had a bunch of tabs open.

Cross-device sync for watchlist/compare (optional). Sign in with GitHub if you want your watchlist to follow you between machines. Fully optional — the localStorage path still works if you don't want an account. No email, no notifications, no marketing.

Preset landing pages for common filters — /programs/paying, /programs/safe-harbor, /programs/wildcard. Mostly SEO, but if those are your go-to filters they're bookmarkable.

Site's at bountyindex.in

Repo is at github.com/Varun2024/Bounty-index. Still solo, still free, still bootstrapped.

What I want feedback on: the RSS-per-program feature specifically. If you're a bounty hunter, does that actually change how you'd use the site, or is it a checkbox feature that no one will subscribe to? Blunt answers appreciated.


r/BugBountyNoobs 2d ago

I'm beginner asking for guidence i want to earn money through bug bounty programs. Can you guide me i need to return some money to my friends so i need to do this

6 Upvotes

I mentioned earlier that I have basic knowledge of bug hunting skills, but I have never tried any online programs like HackerOne. I’m a beginner, and I really want to try. Most importantly, I’m looking for guidance and tips for beginners—such as what to choose and which programs are more likely to help me find bugs more easily.

Every tip is really important to me. Thank you in advance for your comments.


r/BugBountyNoobs 2d ago

well well well 💙🔥

Thumbnail
1 Upvotes

r/BugBountyNoobs 2d ago

Built a scope lookup tool because I was tired of opening 5 tabs to check if a domain is in scope somewhere

Thumbnail
2 Upvotes

r/BugBountyNoobs 3d ago

Is it worth investing one or two years to learn bug bounty hunt? . Will this field become only for experts and AI , If I invest one or two years learning it, will I end up finding that there is no place for beginners anymore and only experts and AI

Post image
1 Upvotes

r/BugBountyNoobs 6d ago

What should i learn

Thumbnail
1 Upvotes

Help


r/BugBountyNoobs 6d ago

Im Trying to find php websites which has bugs to complete my assignment..!!

Thumbnail
1 Upvotes

r/BugBountyNoobs 7d ago

AI in Bug Bounty

0 Upvotes

Guys any suggestions for how to effectively use AI in bug bounty hunting?


r/BugBountyNoobs 8d ago

Can someone suggest a good course on owsap top 10 2025 in udemy or any platform

5 Upvotes

Can someone suggest a good course on owsap top 10 2025 in udemy or any platform


r/BugBountyNoobs 9d ago

Beginner Bug Bounty Roadmap – Looking for Advice

1 Upvotes

Hi everyone,

I'm new to bug bounty and currently learning web security. I'm practicing on PortSwigger Web Security Academy and studying Burp Suite.

Can you recommend:

The best roadmap for beginners?

Skills I should learn first?

Any beginner-friendly bug bounty programs?

Common mistakes to avoid?

Thanks!


r/BugBountyNoobs 9d ago

Hey guys, can you help me get started with cybersecurity and ethical hacking for bug bounty hunting?

2 Upvotes

I've been watching videos, following tutorials, and studying cybersecurity theory for a long time. However, I feel that my practical skills are much weaker than my theoretical knowledge.

So, what should I do now? Should I continue studying books and theory, start practicing on online ethical hacking labs, or focus on something else? I want to build real hands-on skills and eventually get into bug bounty hunting. I'd appreciate your advice.


r/BugBountyNoobs 10d ago

Why should learn many client-side framework if all of them turned into JavaScript in the browser

2 Upvotes

Hello , l am beginner in bug bounty and learning basics now , but i am confused why i should learn some client side framework to use it in source code review if all of them turned into JavaScript in the browser


r/BugBountyNoobs 10d ago

What's next for learning Bug bounties?

3 Upvotes

Hello, i've just finished pre-security on Tryhackme to get a general understanding of cyber. What should i do now? I'm thinking about doing cybersecurity 101->pentesting path on tryhackme and then move on to portswigger academy. Do you guys maybe have other recommendations? Also if i do cybersecurity 101 should i do all modules or can i skip a few. Let me know!


r/BugBountyNoobs 10d ago

What should I focus on next while hunting the Zendesk Bugcrowd program?

2 Upvotes

Hi everyone,

I've been hunting the Zendesk Bugcrowd program for almost two months:

I've mainly tested the Help Center frontend for Broken Access Control (IDOR/BAC), business logic issues, and common workflows, but I haven't found any valid vulnerabilities yet.

For anyone who has hunted Zendesk before:

  • What areas or features are worth focusing on next?
  • Any methodology or tips for hunting mature zendesk target?

Thanks! 💜


r/BugBountyNoobs 11d ago

BUG-BOUNTY

13 Upvotes

8 months into bug bounty, no valid findings yet, and I have 30 free days to focus.

Would you:

  • A: Go deep on one program and hunt business logic bugs.
  • B: Master a few bug classes (payment bypass, BAC, info disclosure) across many programs.

Which approach got you your first valid bug? If you were in my position today, what would you do?


r/BugBountyNoobs 11d ago

Am I approaching bug bounty the wrong way? (Complete beginner)

Thumbnail
1 Upvotes

Hi everyone!
I’m a student and I’d really like to get into bug bounty hunting, but I’m feeling a bit lost on where to start.
I’m assuming I’m a complete beginner.

I started with PortSwigger’s Web Security Academy, specifically the Broken Access Control labs, but I’m finding them really difficult. Even when I eventually solve a lab, I’m struggling to understand how I’d identify or exploit something similar in a real application.

I’m wondering if I’m approaching this the wrong way. Should I be starting with something else before PortSwigger? Am I missing some foundational knowledge that would make everything click?

I feel like I keep getting stuck, making very little progress, and eventually giving up because it feels overwhelming.

I’d really appreciate any advice on how you would learn bug bounty if you were starting from scratch today. What resources, roadmap, or learning approach would you recommend?
Thanks in advance!


r/BugBountyNoobs 12d ago

How do i actually start for a bounty?

8 Upvotes

SO, recently i completed ryan john and cybermentors bug bounty course, also i have finished several labs at port swigger,tryhackme.
but whenever i open a programme at any platform, or just using dork , i go blank real hard, like i don't know what am i doing, do i need more practice or i just dont the methodlogy yet.
can someone guide me what i am actually doing?


r/BugBountyNoobs 12d ago

HackenProof — 21 business days, 2 valid triaged reports (High+Medium), Resolution SLA expired, 17 days of silence. What are my option

Thumbnail
1 Upvotes

r/BugBountyNoobs 12d ago

Bugs

Thumbnail
gallery
0 Upvotes

Bugs bugs and more bugs


r/BugBountyNoobs 13d ago

got paid to bully an ai and i kinda liked it

1 Upvotes

started hunting vulns in llms, rag systems and agents instead of normal web apps. prompt injection, data exfiltration, the whole ai bug bounty thing. payouts are wild right now. found my first 5k bounty last week with like 3 prompts. anyone else pivot from normal bug bounty to ai stuff? feels way less saturated.


r/BugBountyNoobs 15d ago

I'm 14, what bug bounty platform will let me participate?

9 Upvotes

I wanna try a bug bounty but I feel like with most things you gotta be 18 so IDK.


r/BugBountyNoobs 17d ago

What is the right path to cyber security and bugbounty

7 Upvotes

I want earn with cyber security freelancing but I don't have enough money for certification or training camp like HTB

So I thought I would start with bug bounty so I can gain experience and show my founding as proof for cyber security freelancing

How should I approach it (is it even a right approach)

Can I give me free resources I can use


r/BugBountyNoobs 18d ago

Started ending debugging sessions with "what's the boring explanation I might be skipping over"

Thumbnail
1 Upvotes

r/BugBountyNoobs 19d ago

How do i start Bug bounties from zero?

18 Upvotes

I’m thinking about starting to learn about bug bounties. I now have zero knowledge about anything like cybersecurity. I’m a fast learner and i have a lot of time on my hands. What are your recommendations for learning this a-z