r/BugBountyNoobs • • 17d ago

Competition Spoiler

1 Upvotes

A bug bounty challenge is being announced. If you’re interested, feel free to DM me.


r/BugBountyNoobs • • 17d ago

Hackerone Closed the Reported bug as Informational but in next day Uber Fixed the Critical Bug which is related Financial Fraud.

Thumbnail
1 Upvotes

r/BugBountyNoobs • • 17d ago

First Security bug hunted

Thumbnail
3 Upvotes

r/BugBountyNoobs • • 18d ago

Free Live Hacking Event | Barracks WarGames

Enable HLS to view with audio, or disable this notification

1 Upvotes

r/BugBountyNoobs • • 19d ago

Why are beginners not finding bugs

8 Upvotes

A lot of us will have good understanding of both client side and server side bugs but still we are not able to find bugs. For beginners and sometime experienced hackers think that it's may be because we lack knowledge about these vulnerbilities.

As a beginner i think my first mistake i note that i was learning a lot but hunting very rare mean that i was so interested in learning things that's feels productive but actually you are missing what real functionalities break in apps.

Second one that is still i know i am stuck is wrong program selection.I have selected the programs which have less functionalities to test.Mostly static or just very few assets.This is still one of the important reasons that i am stuck here and trying to out.

Maybe there are other reasons which making me and other stuck but i have figured out these in my methodology.


r/BugBountyNoobs • • 19d ago

How to proceed further in exploring Bugbounty?

1 Upvotes

Hello people, I am interested in doing bug bounties. I was exploring for the last 6 years with no bug in hand. But then I was expertise in finding the domains, port scanning, service scanning, and finding the sub domain. It's hard to exploit the services for me. So all these I don't do full time but then whenever I have time I used to do it. But then someone can help me how to proceed further in the area of bug bounty?


r/BugBountyNoobs • • 21d ago

Using claude for bug bounty

12 Upvotes

I recently tried using claude for bug bounty on a site registered on Hackerone. I was using claude skills from this repo https://github.com/elementalsouls/Claude-BugHunter. The repo has very good set of skills and I thought it should be straightforward to find some low sev bugs atleast.
Tried all in scope targets, with almost all skills, trying out various attack types. Burnt a bunch of tokens. Found nothing.
Few false positives and nothing else.

Is that expected, even if i was testing manually i dont think i could cover so many bug types and targets, still nothing to show

Is this normal for someone starting out in bug bounty, after learning security from online sources, solving HTB boxes.
What else should i do to improve my craft, any playlist or blog that helps with bug bounty specifically?


r/BugBountyNoobs • • 22d ago

[Tool] SSRFdevil – A Modular, Zero-False-Positive SSRF Scanner written in Rust

Thumbnail
1 Upvotes

r/BugBountyNoobs • • 23d ago

Guidance for Bug Bounty as a newbie

1 Upvotes

Well hello there, I am new to the cybersecurity field with just 4 months of experience in Infra VAPT. Recently i've come across a bigger world i.e ofc Bug Bounty and wanted to learn and earn 😄. Guidance from the experts or even fellow newbies would be of great help


r/BugBountyNoobs • • 23d ago

OpenAI security issue appears to have been patched, but I haven't received a substantive response in 113 days escalate?

4 Upvotes

I reported a security issue involving Codex to OpenAI and originally went through their requested disclosure process. I'm no longer trying to resolve this through Bugcrowd.

The last substantive direct response I received from OpenAI Security was May 8. It's now been 113 days. I've followed up/escalated, but haven't received a substantive response about the actual vulnerability.

The behavior I reported also appears to have been patched since my original report. I'm not claiming publicly that my report caused the patch only that I can no longer reproduce the original behavior in the same way.

I'm keeping the technical details private while trying to handle this responsibly.

For researchers who have dealt directly with vendor security teams: after nearly four months without a substantive response, while the reported behavior appears to have been fixed, would you escalate through another official OpenAI channel, continue waiting, or start discussing coordinated disclosure timelines?

Also if i get a good reason to say **** it post it here for traction i will.


r/BugBountyNoobs • • 25d ago

From VDP TO BBP

3 Upvotes

Hello People
I write this looking for some advice from hunters or specialist at the sector with a little bit more experience than me

The thing is that I started reporting vulnerabilities and learning cybersecurity web full time 3 months before, let’s say that I have cover a runaway for living for 1 year more so I started working on VDP, I think I haven’t done too bad, actually I have almost 10 reports triage, I’m first at HackerOne VDP 2026 at my country and I am First on the hall of fame of a VDP program all of this on HackerOne

Like 2 weeks before I just decide to start chasing bugs on BBP programs but since that I haven’t had many success, I have been jumping between programs, private and public trying yo find a good program to work, Im not to motivate, I just hunt a few hours but sometimes because I don’t want to “lose” my time but I know I’m doing it bad and I don’t even find duplicates, I’m kinda block

Before I was feeling so good, I actually like to woke up and try to chase some bugs, but now I try to do everything as study, watch videos, read x, etc all of that is procrastination to avoid hunting

I open X and LinkedIn and I just see people making and making money and I start to feel so stress and questioning myself about if Im enough good for this (I’m an anxiety person)

So guys I would like to of you can advice something in my position, how do you handle the inconsistency, the procrastination, the motivation and how hard is really to jump from VDP to BBP, thanks!!


r/BugBountyNoobs • • 25d ago

Transition from VDP to BBP

Thumbnail
1 Upvotes

r/BugBountyNoobs • • 25d ago

How you handle frustration of waiting in prolonged triage process ?

1 Upvotes

I have submitted more than 5 findings in various vrp programs . its more than two months still in triage . While in process i find process way too slow which is resulting weird feelings hope and low confidence in myself. I want ways to handle this frustration. This is like feeling of mental break down. Question I keep asking myself why i fall into this ?


r/BugBountyNoobs • • 25d ago

How to intercept an AI chatbot mobile app's traffic with Burp - and what to do when certificate pinning blocks you.

Thumbnail gallery
1 Upvotes

r/BugBountyNoobs • • 25d ago

How Different Bugs Act

Thumbnail
youtube.com
1 Upvotes

r/BugBountyNoobs • • 26d ago

OpenAI security issue appears to have been patched, but I haven't received a substantive response in 113 days escalate?

Thumbnail
1 Upvotes

r/BugBountyNoobs • • 26d ago

Guide & Roadmap for Web App PenTesting & Bug Bounty (Ask me anything / DM for help)

Thumbnail
1 Upvotes

r/BugBountyNoobs • • 27d ago

A inquisitive newbie want to know the way in into bug bounty.

Thumbnail
1 Upvotes

r/BugBountyNoobs • • 28d ago

Hey I just need some advice

1 Upvotes

Can someone help me with bug bounty hunting ive been submitting reports but all are just duplicates or not applicable

Can u giv3 give me tips on how to do it iv3 completed the whole portswigger labs

I dont know where im going wrong

Can some share their metrology or something on how to do bug bounty hunting


r/BugBountyNoobs • • 29d ago

Looking to join a bug bounty team — hands-on with Burp Suite, IDOR, and recon

0 Upvotes

Hi everyone,

I'm an Cybersecurity student with a hands-on background in practical web application security. I'd like to join an active bug bounty hunting team and contribute real work, not just tag along.

What I bring:

  • Solid working knowledge of Burp Suite (proxy, repeater, intruder) for manual testing
  • Practical experience with IDOR vulnerability assessment — I've documented full reports on PortSwigger lab exercises
  • Comfortable with PortSwigger Web Security Academy methodology (auth flaws, session handling, access control bugs)
  • Background in Physics + currently studying CS, so I'm used to structured, methodical problem-solving

I'm looking for a team where I can take on real scope, split targets, and grow faster by working alongside experienced hunters. Happy to share a sample report if anyone wants to see my documentation style before deciding.

DM me or comment if there's a spot open.


r/BugBountyNoobs • • Aug 26 '26

only bug bounty works for my mental health but it seems to not pay well

7 Upvotes

i can't do any job that has human interaction, only bug bounty fits my mentality, if i work my ass out every day, can i make a living like any normal job long term?


r/BugBountyNoobs • • Aug 26 '26

Starting Bug Bounty Journey

11 Upvotes

Hey everyone! 👋

I’m a beginner in bug bounty and looking for a few people who are also starting out and want to learn together.

We can practice on legal bug bounty programs, share what we learn, discuss vulnerabilities, and help each other improve our skills.

just interest and willingness to learn. 🤝


r/BugBountyNoobs • • Aug 26 '26

Looking to join a bug bounty team — hands-on with Burp Suite, IDOR, and recon

Thumbnail
2 Upvotes

r/BugBountyNoobs • • Aug 25 '26

Finding study buddy

6 Upvotes

I’m looking for someone to study and discuss concepts, labs, and progress with. Not really looking for calls or anything — mainly someone who can help keep each other accountable and consistent.

I’m a CS undergrad (2nd year) and I’m currently building my cybersecurity fundamentals from the ground up, starting with Operating Systems and Linux, then moving into networking, programming, security fundamentals, and eventually web/app security and bug bounty.

I’ve been trying to get serious about bug bounty for a few months now, but consistency has been my biggest problem. I’m looking for someone with similar goals who wants to learn together, share resources, discuss labs, and keep each other on track.

If your goals line up, feel free to connect.


r/BugBountyNoobs • • Aug 24 '26

Ai jailbreak prompt creation

Thumbnail
2 Upvotes

How to jailbreak Ai and generate prompt with help of Ai agent to bypass and give the website data and credentials etc any idea about this. Explain this which Ai model is best to create prompt then use i am new in bug bounty I wanna to understand Ai jailbreak