Conference notes: How to Differentiate Yourself as a Bug Bounty Hunter (OWASP Stockholm)
Posted in Conference notes on November 7, 2018
Posted in Conference notes on July 1, 2018
Hi, these are the notes I took while watching the “Bug Bounty 101 - How To Become A Bug Hunter” talk given by Pranav Hivarekar for Bug Bounty Talks.
A bug bounty program is a deal offered by many websites and software developers by which individuals can receive recognition and compensation for reporting bugs, especially those pertaining to exploits and vulnerabilities. These programs allow the developers to discover and resolve bugs before the general public is aware of them, preventing incidents of widespread abuse. Source
Hacker Report 2018 by HackerOne (page 10 - Bug bounties vs. salary)
State of Bug Bounty Report 2017 by Bugcrowd (page 8 - Adoption by industry)
Pranav had 50+ invalid bugs until he started focusing on 2 things:
The man who thinks he can and the man who thinks he can’t are both right - Confucius
Which one are you?
If you’re starting, focus only on Web and mobile, and build from there (new areas like IoT, etc).
If you mix with people who are at a higher level of success than you, then they will pull you up to their level - Steven Aitchison
One best book is equal to hundred good friens but one good friend is equal to a library - Abdul Kalam
Only test sites who run bug bounty programs (unless you want to go to jail!) like: Facebook, Google, Bugcrowd, HackerOne, Synack…
See you next time!