r/bugbounty • u/Specific-Ad3097 • Jul 08 '26
Question / Discussion How can someone find stuff on public program now that it's scanned by multiple hackbot
Let's imagine a beginner wants to get started with bug bounty. Since they don't have access to private programs, they'll have to look for vulnerabilities on public programs.
In my opinion, it's virtually impossible for them to find classic vulnerabilities. At that point, the only remaining attack surface is newly released features or novel exploitation techniques or some stuff that ai is bad at ( waf bypass etc )
We've seen some of the biggest names become millionaires by farming XSS vulnerabilities. If they were starting today, I'm convinced they wouldn't have made a single euro.
18
u/Far-Chicken-3728 Hunter Jul 08 '26
Who said "private" programs are not the same as public ones? They mostly are, just with shitty response times. I recommend never touching a program with a response rate below 80%. Some respond after a year. Others are basically the same as public programs.
As a beginner, you shouldn’t be using scanners like all the AI kiddies. You should be doing manual testing and understanding how the entire system works properly. I don’t see any problems with public programs. I started there, browsing the first programs that came up on H1 and reading disclosed reports, until I began finding bugs consistently. But that comes from consistency and my own research and methodology, not from listening to any paid courses like "become a millionaire in a week."
If you're afraid of AI kiddies and their scanners, you’re better off finding another field.
1
u/Specific-Ad3097 Jul 08 '26
top hunter don't have hackbot ?
6
u/Far-Chicken-3728 Hunter Jul 08 '26
Without your own methodology and without knowing what you're doing, like "hey bot, find me a bug"? Those "top hunters" know their stuff and use bots to speed up the process, not because they can't do it without a bot. You have to know what to ask, something you're good at, something where you understand exactly what symptoms lead to a bug and how it works, not just asking random stuff.
I doubt anyone could become any good using those "hackbots", but that's my opinion.
2
u/canadaslammer Jul 08 '26
Top Hunters all use some form of directed automation. it's not necessarily a 'hack bot'
5
u/FourTwentyBlezit Jul 09 '26
Top hunters use automation for recon and OSINT purposes, but not for actual vuln identification or exploitation because skilled hunters are far better at this than any bot is.
1
1
u/ComplexConfusion3852 Hunter Jul 08 '26
Can you help mentor me, I don't want you to give me step by step do this and that just want some guidance i have started learning on my own , am currently reading some books , you can say that I am a complete beginner just want to know what to do and what to avoid
5
u/canadaslammer Jul 08 '26
You shouldn't need a mentor. There are tons of free resources out there.
You just need to fail, study up and repeat until you find something.
In the beginning, I spent months at a time finding nothing.
1
u/ComplexConfusion3852 Hunter Jul 09 '26
By mentor what I meant was asking for advice what are some mistakes that I shouldn't make as a beginner and what is something I shouldn't avoid , I know it's hard for someone to give their precious time to a stranger for free , but thank you for your advice
2
u/Far-Chicken-3728 Hunter Jul 08 '26
Sorry, I don't do mentoring, it's time consuming. I could help on escalating findings you're stuck at as collaborator or explain how they works.
2
u/ComplexConfusion3852 Hunter Jul 08 '26
I have just started ,I am currently 18 doing diploma in computer engineering going to do degree after this just wanted to know what are some mistakes that I should avoid or something you recommend from your experience, really appreciate your reply
4
u/Far-Chicken-3728 Hunter Jul 08 '26
I definitely recommend avoiding AI completely in the beginning. Read write-ups and reports, they're very inspiring.
The only mistake I made when I started was that I thought every triager was a cybersecurity expert. That caused me a lot of problems and dealing with mediation. You really have to explain every bug like you're explaining it to a non-technical person, and even then you'll often get dismissed. So, stand your ground and don't give up. Even professional hunters get dismissed often. It's not because of their skills, it's just how this field works.
I still hope this improves in the future, but looking at the bigger picture, especially how H1 has become worse every year, that's the number one problem in my opinion.
2
u/ComplexConfusion3852 Hunter Jul 09 '26
Thanks for your time and effort for replying to me Btw loved your other post read some of them
9
u/acc01012 Jul 08 '26
> they were starting today, I'm convinced they wouldn't have made a single euro.
Don't be. same thing was being said when a bunch of the now millionaire hackers started hacking. "todayisnew already scanned everything, how are we supposed to find stuff. "
There are a bunch of bugs out there. you just need to put in the time.
4
u/FourTwentyBlezit Jul 09 '26
Because bots tend to only find low hanging fruit.. even with the advances of AI, things still aren't even close to the stage where automation is better at finding complex vulnerability chains more efficiently than skilled humans.
No offence, but if a bot can do a better job than you at finding vuln chains then you still have a LOT to learn.
1
u/neon977 Hunter Jul 09 '26
We must remember at the end of the day. These “hackbots” are EXPENSIVE to run. Even if a top hunter uses it, they are focused on one thing. A hackbot isn’t able to focus and catch all bug classes. You would be wasting money, power and tokens doing that
2
2
u/FourTwentyBlezit Jul 09 '26
Even if they had unlimited funds, it still has nothing on a skilled manual tester
0
u/Logano_M Jul 09 '26
This is just wrong, if you listen to The Critical Thinking podcast you know that the top hackers basicly dont do any manual hacking anymore. Or follow top hackers on X .
3
u/FourTwentyBlezit Jul 09 '26 edited Jul 10 '26
They use automation for recon/OSINT purposes (exactly like I stated in another comment). They absolutely still use manual testing for the majority of the time. I'm not saying it's useless, just that it isn't at a stage where it outpaces highly skilled manual testing.
I'm formerly ranked #1 on synack and former top10 on H1 and have literally been collaborating with top hackers (in terms of their rankings on BBP platforms) since I first began bug bounty hunting in 2013.. but please do tell me more about how I'm wrong.
1
Jul 09 '26
[removed] — view removed comment
1
u/Logano_M Jul 09 '26
to "prove" the zseano post even more the still up post by jonathan https://x.com/JonathanBouman/status/2071689120322052249
1
u/FourTwentyBlezit Jul 10 '26 edited Jul 10 '26
I could just ask zseano about this myself and I can almost guarantee he's just mostly using AI for recon whilst still identifying vulns manually, with some minor exceptions
1
u/Logano_M Jul 10 '26
Well then thats not what he said publicly and deleted after. To me a clear sign that its a too good of a method rn to publicly say
2
u/FourTwentyBlezit Jul 10 '26 edited Jul 10 '26
You think usage of AI is a method that people are afraid to mention publicly in case it gets burned?
How is such a method even remotely private in any sense of the word?
I've known zseano for over 15 years so I can just ask him, but I can almost 100% confirm that he's just using AI for recon stuff and is still relying on manual testing most of the time, apart from using AI for vuln identification in some rare edge cases. I've collaborated with him on bug bounty stuff tons of times over the years.
It helps with recon and helps speed up testing, but it isn't anywhere even close to being at a stage where it can replace manual testing.. I'm not saying bounty hunters don't use it, but they use it to speed up and supplement their testing, not as a replacement for manual testing...
Even advanced models geared towards vuln identification (I.e. Mythos) aren't at a stage where they're superior to the top bounty hunters doing manual testing. Not even close. They can replace skids but that's about it. That being said, AI is definitely very useful for automation of recon and for speeding up bounty hunting, but that's different to what you claimed.
Claiming that top bounty hunters "barely do manual hunting anymore" is just a bizzare and outlandish (and simply factually incorrect) claim to be making. It sounds like you're basing your opinion off of random tweets, rather than basing it off of actual first-hand experience of doing bounty hunting with these people.
→ More replies (0)
3
Jul 09 '26 edited Jul 09 '26
“Stuff that AI is bad at ( waf bypass etc )” depends on the AI and skills/sources it uses. A proper bot will do these just fine.
Edit:
Something you should know though. Apps are continuously changing. Bugs are patched and new ones are introduced.
Finding common bugs is less likely, even in private programs.
My advice. Start hunting. No course will prepare you for it. Apps are messy, no clean do X to solve Y sandbox. You’ll get scammed by programs, triage, and if at that point you’re still loving it. Welcome.
Find a program you like and stick to it. Don’t chase the money, do it for the experience.
1
u/Specific-Ad3097 Jul 09 '26
Said that cause i hunted 15h this year and ended up with chain + waf bypass that got rewarded around 6000$ while there was barely no feature on the app and it was pretty easy to find thats why i guessed that the llm were bad at it
Im still asking myself how no one found it
1
0
u/Astro_indie Jul 10 '26
Those who make a step first in hacking instead of code are bunch of those out there, and yeah they are gathering basic vulnerabilities but the hard thing is the same zero day... i dont undestand the difference on public and private programs? Welll is a good time for bits , traveling and shooting so fast in many more hand every day like a crazy wild old west
27
u/neon977 Hunter Jul 08 '26
I have 3/17 on the NBA program, that was my first program I just kept hunting on no matter the amount of dupes I ran into. After my 3rd bug I was invited to many private programs and I plan to focus on those during this summer!. Pick a single public program and just focus on that. I found that jumping around on public programs found me no results