# Getting Started With Bug Bounty!

![image](https://cdn.hashnode.com/res/hashnode/image/upload/v1658057370613/vD3GcFEiA.jpeg)

How to get started in Bug bounty is a common question nowadays. If you think you will become successful overnight or over the week or a month, this is not a field you should join. Doing bug bounties are very competitive, it might take a year at least to do good in bug bounty.

> “Do not expect someone will spoon feed you everything”.

Well i'm not an experienced hunter, i'm also a beginner in this field. My main motive of this blog is to share my learning paths.

You should have a basic understanding of how things work on the internet, and still there are many more things to learn. I'm listing few important topics below :

*   HTTP -- TCP/IP Model
*   Linux -- CLI
*   Web Application Technologies
*   Networking Basics
*   Learning Basics of HTML, PHP, JavaScript, SQL.

The list never ends it all depends upon your interest.

Choosing a path in bug bounty field is very important, it totally depends upon the person's interest but i prefer web application security testing because according to me it is the easiest one.

1\. Web Application Security Testing

2\. Mobile Application Security Testing (Android/IOS)

But not limited to these two it totally depends upon your interest.

### Bug Bounty Platforms:

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1658057372189/D_ztqN0hB.jpeg)

1.  Bugcrowd ([https://bugcrowd.com](https://bugcrowd.com))
2.  Hackerone ([https://hackerone.com/](https://hackerone.com/))
3.  Intigriti (https://www.intigriti.com/)
4.  Synack (https://synack.com/)
5.  Safehats (https://safehats.com/)

### Resources :

Books :

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1658057373660/lrUIaGF8T.jpeg)

-[Web Application Hacker’s Handbook](https://all-med.net/pdf/the-web-application-hacker-s-handbook/)

- [Web Hacking 101]%[Link](https://www.academia.edu/39753383/Web_Hacking_101_How_to_Make_Money_Hacking_Ethically)

- **The Hacker Playbook** [1](https://rumahhijabaqila.com/pdf-download/33887-the-hacker-playbook-1-pdf-download-959-235.php), [2](https://all-med.net/pdf/the-hacker-playbook-2/), and [3](https://all-med.net/pdf/the-hacker-playbook-3/)

- [The Mobile Application Hacker's Handbook](https://all-med.net/pdf/the-mobile-application-hacker-s-handbook/)

- [Mastering Modern Web Penetration Testing](https://www.amazon.com/Mastering-Modern-Web-Penetration-Testing/dp/1785284584)

In addition to these books, i’ll suggest you to read and understand OWASP Testing Guide & OWASP Top 10 Vulnerabilities. [https://owasp.org](http://https:owasp.org)

### Youtube Channels:

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1658057375330/GgEwPOS4x.jpeg)
- [Live Over Flow](https://www.youtube.com/results?search_query=live+overflow) ([https://www.youtube.com/c/LiveOverflowCTF](https://www.youtube.com/c/LiveOverflowCTF))

- [Nahamsec](https://www.youtube.com/channel/UCCZDt7MuC3Hzs6IH4xODLBw) ([https://www.youtube.com/c/Nahamsec](https://www.youtube.com/c/Nahamsec))

- [Farah Hawa](https://www.youtube.com/channel/UCq9IyPMXiwD8yBFHkxmN8zg) ([https://www.youtube.com/c/FarahHawa](https://www.youtube.com/c/FarahHawa))

- [PortSwigger](https://www.youtube.com/channel/UCkytgKNbJ0L1UuN1K27GAKA) ([https://www.youtube.com/c/PortSwiggerTV](https://www.youtube.com/c/PortSwiggerTV))
- [Bug Bounty Public Disclosure](https://www.youtube.com/channel/UCNRM4GH-SD85WCSqeSb4xUA) ([https://www.youtube.com/channel/UCNRM4GH-SD85WCSqeSb4xUA](https://www.youtube.com/channel/UCNRM4GH-SD85WCSqeSb4xUA))

- The Cyber Mentor (https://www.youtube.com/c/TheCyberMentor)

- Stök Fredrik ([https://www.youtube.com/c/STOKfredrik](https://www.youtube.com/c/STOKfredrik))

### Blogs/Write-ups You Should Follow:

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1658057376725/NKj94O3Z5.jpeg)

- [Bug Crowd Blog](https://www.bugcrowd.com/blog/) (https://www.bugcrowd.com/blog/)

- [Bug Hunting Medium](https://medium.com/bugbountywriteup/bug-bounty-hunting-methodology-toolkit-tips-tricks-blogs-ef6542301c65) (https://medium.com/bugbountywriteup/bug-bounty-hunting-methodology-toolkit-tips-tricks-blogs-ef6542301c65)

- [Pentester Land](https://pentester.land/list-of-bug-bounty-writeups.html) ([https://pentester.land/list-of-bug-bounty-writeups.html](https://pentester.land/list-of-bug-bounty-writeups.html))

- [Hackerone Blog](https://hackerone.com/blog) ([https://hackerone.com/blog](https://hackerone.com/blog))

Twitter # tags you should follow:

#bugbounty

#bugbountytips

#infosec

#togetherwehitharder

#cybersecurity

### Bug Bounty Tools you should Master:

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1658057378321/hliK3vpig.jpeg)

Burp Suite

Open Vas

Metasploit

Nmap

Scrappy

John The Ripper

Wfuzz

Zaproxy

Still there are many tools but these are the mainly used tools.

### Labs To Practice Legally:

- [Port Swigger Labs](https://portswigger.net/web-security) (https://portswigger.net/web-security)

- [Damn Vulnerable Web Application](http://www.dvwa.co.uk/) (http://www.dvwa.co.uk/)

- [Web Goat](https://owasp.org/www-project-webgoat/) ([https://owasp.org/www-project-webgoat/](https://owasp.org/www-project-webgoat/)

- [bWAPP](http://itsecgames.com/) ([http://itsecgames.com/](http://itsecgames.com/))


>“Start learning and keep Hunting!”




