chivato Profile picture
Mar 29, 2022 15 tweets 3 min read Read on X
I've been at HackerOne for about 5 months now. It's been eye-opening seeing how all of these hackers work from the other side of the screen. Here is a list of some of the tips I've gathered 🧵🧵🧵 #BugBounty #BugBountyTips
Most of the prolific hunters will focus on one target for large amounts of time, learning the ins and outs of the application.
If you are going to go for low hanging fruit, focus on building outstanding automation and recon lists.
Data analytics to identify what works and what doesn't is extremely underrated in the bug bounty field, and can be set up to passively analyze what is generated from automation.
Use nuclei templates only as inspiration for your own custom templates. By relying on the public nuclei templates you are setting yourself up for dupes and disappointment.
It's worth picking a technology, finding ways to fingerprint said tech from a blackbox perspective. Then get extremely good at exploiting said service and formulate a list of targets which use the tech (this could be used to easily identify misconfigurations for example).
Good recon is just as important (if not more important) than exploitation. Even the worst hacker could find an XSS if it's on a half-arsed asset the development team forgot about years ago.
Just because a report get's triaged and resolved, don't forget about it! Set up passive automation to check if the bug ever regresses into a vulnerable state.
Keep track of all submitted bugs - even ones closed off as informative or N/A. Future changes in application or in program policy may make them valid.
Collaborate! Some of the biggest payouts are seen from hackers collaborating, and it's definitely more fun.
Familiarise yourself with technologies like docker and kubernetes for both automation and a quick way to spin up specific tech.
Be patient and respectful with triagers. We look at hundreds of reports per week and sometimes we make mistakes. A gentle nudge instead of a passive-aggressive message goes a long way :)
If you see a subdomain with a single numerical value (i.e. testserver1.example.com), check for other subdomains by iterating over the integer (you may find another vulnerable host).
Read the program policy carefully and make a small summary of things that may be relevant to you, such as rules that apply to a common bug type. This will help avoid disappointment and N/A later on.
I'll keep this updated as my time at HackerOne goes on. I hope this is helpful :)

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with chivato

chivato Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @SecGus

Jul 6, 2022
I'm seeing loads of people receiving their FlipperZero(s) (@flipper_zero), so I thought I'd compile a list of the best resources to play with and other useful info I've found/seen recently.
FlipperZero Forum (feature requests and questions): forum.flipperzero.one
Official Discord: discord.gg/eMfkYaPFsm
Unofficial Discord (they post loads of great dumps and captures to emulate): discord.gg/HDNn5tDYAN
Official FlipperZero Firmware repo: github.com/flipperdevices…
Awesome FlipperZero (compilation of databases, dumps, apps, plugins and more): github.com/djsime1/awesom…
Writing your first FlipperZero plugin: flipper.atmanos.com/docs/category/…
Locked out or damaged F0: docs.flipperzero.one/basics/firmwar…
Read 7 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(