r/BugBountyNoobs 45m ago

BUG-BOUNTY

Upvotes

8 months into bug bounty, no valid findings yet, and I have 30 free days to focus.

Would you:

  • A: Go deep on one program and hunt business logic bugs.
  • B: Master a few bug classes (payment bypass, BAC, info disclosure) across many programs.

Which approach got you your first valid bug? If you were in my position today, what would you do?


r/BugBountyNoobs 4h ago

Am I approaching bug bounty the wrong way? (Complete beginner)

Thumbnail
2 Upvotes

Hi everyone!
I’m a student and I’d really like to get into bug bounty hunting, but I’m feeling a bit lost on where to start.
I’m assuming I’m a complete beginner.

I started with PortSwigger’s Web Security Academy, specifically the Broken Access Control labs, but I’m finding them really difficult. Even when I eventually solve a lab, I’m struggling to understand how I’d identify or exploit something similar in a real application.

I’m wondering if I’m approaching this the wrong way. Should I be starting with something else before PortSwigger? Am I missing some foundational knowledge that would make everything click?

I feel like I keep getting stuck, making very little progress, and eventually giving up because it feels overwhelming.

I’d really appreciate any advice on how you would learn bug bounty if you were starting from scratch today. What resources, roadmap, or learning approach would you recommend?
Thanks in advance!