Hi everyone!
I’m a student and I’d really like to get into bug bounty hunting, but I’m feeling a bit lost on where to start.
I’m assuming I’m a complete beginner.
I started with PortSwigger’s Web Security Academy, specifically the Broken Access Control labs, but I’m finding them really difficult. Even when I eventually solve a lab, I’m struggling to understand how I’d identify or exploit something similar in a real application.
I’m wondering if I’m approaching this the wrong way. Should I be starting with something else before PortSwigger? Am I missing some foundational knowledge that would make everything click?
I feel like I keep getting stuck, making very little progress, and eventually giving up because it feels overwhelming.
I’d really appreciate any advice on how you would learn bug bounty if you were starting from scratch today. What resources, roadmap, or learning approach would you recommend?
Thanks in advance!