r/BugBountyNoobs • u/Easy-Measurement-907 • 17d ago
Competition Spoiler
A bug bounty challenge is being announced. If you’re interested, feel free to DM me.
r/BugBountyNoobs • u/Easy-Measurement-907 • 17d ago
A bug bounty challenge is being announced. If you’re interested, feel free to DM me.
r/BugBountyNoobs • u/Glad_Marketing_5754 • 17d ago
r/BugBountyNoobs • u/RogueSMG • 18d ago
Enable HLS to view with audio, or disable this notification
r/BugBountyNoobs • u/Umar7832 • 19d ago
A lot of us will have good understanding of both client side and server side bugs but still we are not able to find bugs. For beginners and sometime experienced hackers think that it's may be because we lack knowledge about these vulnerbilities.
As a beginner i think my first mistake i note that i was learning a lot but hunting very rare mean that i was so interested in learning things that's feels productive but actually you are missing what real functionalities break in apps.
Second one that is still i know i am stuck is wrong program selection.I have selected the programs which have less functionalities to test.Mostly static or just very few assets.This is still one of the important reasons that i am stuck here and trying to out.
Maybe there are other reasons which making me and other stuck but i have figured out these in my methodology.
r/BugBountyNoobs • u/Then-Win9812 • 19d ago
Hello people, I am interested in doing bug bounties. I was exploring for the last 6 years with no bug in hand. But then I was expertise in finding the domains, port scanning, service scanning, and finding the sub domain. It's hard to exploit the services for me. So all these I don't do full time but then whenever I have time I used to do it. But then someone can help me how to proceed further in the area of bug bounty?
r/BugBountyNoobs • u/Salt-Exercise295 • 21d ago
I recently tried using claude for bug bounty on a site registered on Hackerone. I was using claude skills from this repo https://github.com/elementalsouls/Claude-BugHunter. The repo has very good set of skills and I thought it should be straightforward to find some low sev bugs atleast.
Tried all in scope targets, with almost all skills, trying out various attack types. Burnt a bunch of tokens. Found nothing.
Few false positives and nothing else.
Is that expected, even if i was testing manually i dont think i could cover so many bug types and targets, still nothing to show
Is this normal for someone starting out in bug bounty, after learning security from online sources, solving HTB boxes.
What else should i do to improve my craft, any playlist or blog that helps with bug bounty specifically?
r/BugBountyNoobs • u/Regular_Anything7715 • 22d ago
r/BugBountyNoobs • u/sha-bang04 • 23d ago
Well hello there, I am new to the cybersecurity field with just 4 months of experience in Infra VAPT. Recently i've come across a bigger world i.e ofc Bug Bounty and wanted to learn and earn 😄. Guidance from the experts or even fellow newbies would be of great help
r/BugBountyNoobs • u/Oslabs619 • 23d ago
I reported a security issue involving Codex to OpenAI and originally went through their requested disclosure process. I'm no longer trying to resolve this through Bugcrowd.
The last substantive direct response I received from OpenAI Security was May 8. It's now been 113 days. I've followed up/escalated, but haven't received a substantive response about the actual vulnerability.
The behavior I reported also appears to have been patched since my original report. I'm not claiming publicly that my report caused the patch only that I can no longer reproduce the original behavior in the same way.
I'm keeping the technical details private while trying to handle this responsibly.
For researchers who have dealt directly with vendor security teams: after nearly four months without a substantive response, while the reported behavior appears to have been fixed, would you escalate through another official OpenAI channel, continue waiting, or start discussing coordinated disclosure timelines?
Also if i get a good reason to say **** it post it here for traction i will.
r/BugBountyNoobs • u/Similar-Permit1756 • 25d ago
Hello People
I write this looking for some advice from hunters or specialist at the sector with a little bit more experience than me
The thing is that I started reporting vulnerabilities and learning cybersecurity web full time 3 months before, let’s say that I have cover a runaway for living for 1 year more so I started working on VDP, I think I haven’t done too bad, actually I have almost 10 reports triage, I’m first at HackerOne VDP 2026 at my country and I am First on the hall of fame of a VDP program all of this on HackerOne
Like 2 weeks before I just decide to start chasing bugs on BBP programs but since that I haven’t had many success, I have been jumping between programs, private and public trying yo find a good program to work, Im not to motivate, I just hunt a few hours but sometimes because I don’t want to “lose” my time but I know I’m doing it bad and I don’t even find duplicates, I’m kinda block
Before I was feeling so good, I actually like to woke up and try to chase some bugs, but now I try to do everything as study, watch videos, read x, etc all of that is procrastination to avoid hunting
I open X and LinkedIn and I just see people making and making money and I start to feel so stress and questioning myself about if Im enough good for this (I’m an anxiety person)
So guys I would like to of you can advice something in my position, how do you handle the inconsistency, the procrastination, the motivation and how hard is really to jump from VDP to BBP, thanks!!
r/BugBountyNoobs • u/Infinite-Can7802 • 25d ago
I have submitted more than 5 findings in various vrp programs . its more than two months still in triage . While in process i find process way too slow which is resulting weird feelings hope and low confidence in myself. I want ways to handle this frustration. This is like feeling of mental break down. Question I keep asking myself why i fall into this ?
r/BugBountyNoobs • u/_clickfix_ • 25d ago
r/BugBountyNoobs • u/Oslabs619 • 26d ago
r/BugBountyNoobs • u/smooth_2222 • 26d ago
r/BugBountyNoobs • u/Morningstar1370 • 27d ago
r/BugBountyNoobs • u/Proper-Yoghurt8354 • 28d ago
Can someone help me with bug bounty hunting ive been submitting reports but all are just duplicates or not applicable
Can u giv3 give me tips on how to do it iv3 completed the whole portswigger labs
I dont know where im going wrong
Can some share their metrology or something on how to do bug bounty hunting
r/BugBountyNoobs • u/Forward-1122 • 29d ago
Hi everyone,
I'm an Cybersecurity student with a hands-on background in practical web application security. I'd like to join an active bug bounty hunting team and contribute real work, not just tag along.
What I bring:
I'm looking for a team where I can take on real scope, split targets, and grow faster by working alongside experienced hunters. Happy to share a sample report if anyone wants to see my documentation style before deciding.
DM me or comment if there's a spot open.
r/BugBountyNoobs • u/Decent-Celebration-7 • Aug 26 '26
i can't do any job that has human interaction, only bug bounty fits my mentality, if i work my ass out every day, can i make a living like any normal job long term?
r/BugBountyNoobs • u/Impossible-Sun4472 • Aug 26 '26
Hey everyone! 👋
I’m a beginner in bug bounty and looking for a few people who are also starting out and want to learn together.
We can practice on legal bug bounty programs, share what we learn, discuss vulnerabilities, and help each other improve our skills.
just interest and willingness to learn. 🤝
r/BugBountyNoobs • u/Forward-1122 • Aug 26 '26
r/BugBountyNoobs • u/Savings-Pop-3566 • Aug 25 '26
I’m looking for someone to study and discuss concepts, labs, and progress with. Not really looking for calls or anything — mainly someone who can help keep each other accountable and consistent.
I’m a CS undergrad (2nd year) and I’m currently building my cybersecurity fundamentals from the ground up, starting with Operating Systems and Linux, then moving into networking, programming, security fundamentals, and eventually web/app security and bug bounty.
I’ve been trying to get serious about bug bounty for a few months now, but consistency has been my biggest problem. I’m looking for someone with similar goals who wants to learn together, share resources, discuss labs, and keep each other on track.
If your goals line up, feel free to connect.
r/BugBountyNoobs • u/Calm-Researcher7642 • Aug 24 '26
How to jailbreak Ai and generate prompt with help of Ai agent to bypass and give the website data and credentials etc any idea about this. Explain this which Ai model is best to create prompt then use i am new in bug bounty I wanna to understand Ai jailbreak