This is a resource factory for anyone looking forward to starting bug hunting and would require guidance as a beginner.
Please don't hesitate to contribute to this repo!
Hi! I'm Ansh Bhawnani. I am currently working as a Security Engineer and also a part time content creator. I am creating this repository for everyone to contribute as to guide the young and enthusiastic minds for starting their career in bug bounties. More content will be added regularly. Keep following. So let's get started!
NOTE: The bug bounty landscape has changed since the last few years. The issues we used to find easily an year ago would not be easy now. Automation is being used rigorously and most of the "low hanging fruits" are being duplicated if you are out of luck. If you want to start doing bug bounty, you will have to be determined to be consistent and focused, as the competition is very high.
World class security researchers and bug bounty hunters are on Twitter. Where are you? Join Twitter now and get daily updates on new issues, vulnerabilities, zero days, exploits, and join people sharing their methodologies, resources, notes and experiences in the cyber security world!
CTF
Online Labs
Offline Labs
Servers
Shodan - Search Engine for the Internet of Everything
Censys Search - Search Engine for every server on the Internet to reduce exposure and improve security
Onyphe.io - Cyber Defense Search Engine for open-source and cyber threat intelligence data
ZoomEye - Global cyberspace mapping
GreyNoise - The source for understanding internet noise
Natlas - Scaling Network Scanning
Netlas.io - Discover, Research and Monitor any Assets Available Online
FOFA - Cyberspace mapping
Quake - Cyberspace surveying and mapping system
Hunter - Internet Search Engines For Security Researchers
Crowdsourcing
Individual Programs
Title
Description
Steps to Reproduce
Proof of Concept
Impact
Sample Report
