There are lots of guides on how to start into bug bounty hunting, but I will share my personal experience of getting into bug bounty hunting without previous knowledge of coding or web development, and will also share some useful resources as well as answering some common questions.
How I started?
I started hunting for bugs without knowing any web development. I joined H1 without knowing what XSS was. It took me a little more than a year to be where I am — constant learning and studying. This is a competitive field; you can earn money but it won't be easy, you need to earn it.
I had no idea how a lot of things worked but eventually I learned about them. Now I can proudly say I found all Top 10 OWASP vulnerabilities like SQLi, RCE, XXE, apart from many more, but it took a lot of hard work — it didn't happen from one day to another.
Right now this is my full-time job.
Where to start?
When starting you may get overwhelmed with all the information there is out there, and that's fine, but I recommend learning one thing at a time; once you are done with that you move up to another thing/topic. For example, pick a vulnerability type and learn in depth about it, then move to another, etc.
What vulnerabilities does every bug bounty hunter know? There are too many and some are fairly new like HTTP smuggling, so I will just mention some of the ones I think you should start with. You will learn others along your journey. They are not in order, so you can pick any of them to start:
- XSS
- CSRF
- IDOR
- Open Redirect
- SSRF
- SQL injection (the basics, since it can be hard when starting)
These are common web vulnerabilities but there are many more. So when starting from zero I would pick one of the above and try to learn about it. Then repeat. If you already know all of them, then search for others.
Where can I learn about them?
There are a lot of resources to learn every vulnerability type — everything is out there. I will just mention some useful websites that you can start learning from now, completely free.
PortSwigger's labs
portswigger.net/web-security — They explain almost all vulnerability types that exist. They give a really good summary on what the vulnerability is, and also have a lab that is a controlled environment where you can hack it, exploiting that vulnerability type.
HackerOne's Hacktivity
hackerone.com/hacktivity — The search function inside HackerOne sucks, so you can use Google to search for this: "Hackerone XSS" in Google will give you results of other hackers' findings on real websites about XSS. Personally, I used this a lot when starting, and still look at it almost every day, so you can get a real vision of how the vulnerability looks on a real website and how hackers find and report them.
CTFs (Capture The Flag)
CTF is where you hack into a controlled environment to find a "flag" that will prove you completed it. I honestly don't like CTFs and never really got into it, but some people do and learn a lot from it. It can be useful to improve your skills and some people just enjoy doing them.
HackerOne Discord
discord.com/invite/32ZNZVN — I just can't think of what would be of me if I had never found this Discord server. I joined there without knowing what XSS was. I didn't know any web vulnerability. It took a lot of work and a lot of desire to learn to get where I am, and eventually paid off. There are a lot of people there that will point you in the right direction, feel free to ask questions there.
Do I need to use any special tool?
When you start, all you need is the free version of Burp Suite to intercept and log traffic, and a browser. Eventually you will start using other tools or developing your own and that's normal, but you don't need to learn 20 tools to start hunting for bugs… just a browser and Burp Suite.
Do I need to know how to code?
Well, you don't need to, but it definitely helps. I knew a bit of Python when I started in the bug bounty world and it helped me automate some basic tasks, and recently I used it a lot for "complex" PoCs of my last reports.
I would recommend learning a bit of bash scripting and Python so if you want to automate a task you can do it. It is also important to know the basics of JavaScript and HTML to actually know how to get an XSS — you should definitely learn a bit about them too.
How to write a report?
You need to be clear about what the bug and the impact are. There are awesome reports on HackerOne that you can take as a guide. Also check HackerOne's quality-reports guide.
When should I start looking for vulnerabilities in real websites?
Well, this is a hard question. Everyone makes their own journey. Some prefer to do CTFs, some like to do a lot of labs, some like to read some books like "The Web Application Hacker's Handbook" and just then jump into a program, and that's totally fine.
Personally I don't like CTFs. I didn't do any labs apart from 2 or 3 from PortSwigger on HTTP smuggling. I did read a hacking-related book and understood nothing about it. What I did was jump directly to old bug bounty programs and start searching for the vulnerabilities I learned about, and that's it. Pretty simple, right?
Being a bug bounty hunter or security analyst means you will always be learning new things — new vulnerabilities, new techniques, etc. There isn't any hacker that can say "I know it all" and just stop learning. So start looking for vulnerabilities whenever you feel like doing it. There isn't a "right" moment. I would recommend that you learn a few web vulnerabilities before trying to hunt for bugs, but you are always free to do whatever you want — remember, every journey is different.
Do I need to get a certification like CEH?
Definitely not. You can get it if you want to work for a company but it won't give you any special advantage in the bug bounty world when finding and reporting vulnerabilities. A lot of hackers are self-taught like me. You can learn everything without spending a single dollar on any cert or any website that claims you can become a hacker in 2 weeks by buying their $500 course. Don't trust them.
Automation
Automation can be anything from automating simple tasks such as a big command you do every day, to a large script to do multiple things. This isn't a "must", but it will definitely save you time and maybe you get more bugs.
General rule every hacker (or just Linux user) knows: if you write the same command (that is relatively long) 2 or more times a day, then make a function in
.bashrcor make a script and move it to/usr/local/binto call it from everywhere. This will save you time.
I recommend watching Nahamsec's YouTube videos where he does recon and shows some cool techniques and how you can automate your workflow. What I recommend:
- Automate subdomain enumeration and discovery.
- Automate brute-forcing directories.
- Automate visualization of live subdomains.
- Automate everything that takes a "long" time to do manually so you can focus on something else while it is running.
Conclusion + Tips
- The bug bounty field is competitive.
- Everything is on the internet, just ask Mr. Google.
- This is not for everyone.
- Try to avoid being overwhelmed with information. Take breaks.
- Send this to the people that ask you "Can you teach me how to hack?"
- Work hard and you will eventually get it.
- Some people on Twitter share useful resources, tips, etc. — follow them!
- Good luck.
Hope this is useful for some people,
zonduu.