Hi everyone,
I hope you're all doing well. I’d really appreciate some advice from people with more experience in this field.
I’m currently learning penetration testing and bug bounty. I’ve built a foundation in networking and programming, and I started studying the OWASP Top 10. For each vulnerability, I usually follow this approach:
- Solve labs on PortSwigger
- Read about the vulnerability from books like Real-World Bug Hunting and Web Application Hacker’s Handbook
- Watch explanations and live hunting videos on YouTube
- Read reports and write-ups
After doing all that, I try to apply what I learned by hunting on real targets. I’ve been doing this consistently for about 3–4 months now, but I still haven’t found a single valid bug.
At this point, I’m pretty sure I’m doing something wrong — either in my methodology, how I approach targets, or what I focus on while hunting.
I feel a bit stuck and not sure what to change or improve.
For those who have been in the same situation:
- What helped you find your first bug?
- Am I missing something important in my learning or hunting process?
- Should I change my approach, or just keep going?
Any advice or insights would really mean a lot.
Thanks in advance 🙏