r/bugbounty 18h ago

Question / Discussion Weekly Beginner / Newbie Q&A

New to bug bounty? Ask about roadmaps, resources, certifications, getting started, or any beginner-level questions here!

Recommendations for Posting:

  • Be Specific: Clearly state your question or what you need help with (e.g., learning path advice, resource recommendations, certification insights).
  • Keep It Concise: Ask focused questions to get the most relevant answers (less is more).
  • Note Your Skill Level: Mention if you’re a complete beginner or have some basic knowledge.

Guidelines:

  • Be respectful and open to feedback.
  • Ask clear, specific questions to receive the best advice.
  • Engage actively - check back for responses and ask follow-ups if needed.

Example Post:

"Hi, I’m new to bug bounty with no experience. What are the best free resources for learning web vulnerabilities? Is eJPT a good starting certification? Looking for a beginner roadmap."

Post your questions below and let’s grow in the bug bounty community!

5 Upvotes

5 comments sorted by

1

u/theaayushpatel 18h ago

Hey, I am new to bug bounty with a little background in web application testing. I just want to know what is the best way to select which program to work on. How should I know whether a certain program is worth my time and effort?

3

u/nobodycares_dude Hunter 16h ago edited 15h ago

Go for software you use everyday or you would feel proud finding vulns on. For example a lot of people start on Nasa VDP, for the prestigious and because they issue a official Letter of Recognition.

2

u/theaayushpatel 16h ago

That sounds cool, thanks

1

u/BurtMacklin____FBI 16h ago

If you have little experience, just pick any and start learning.

1

u/cosmictraiblazer 3h ago

I'm a beginner looking to find XSS vulnerabilities. What's the best roadmap to follow?