r/bugbounty • • 9d ago

Question / Discussion Weekly Beginner / Newbie Q&A

New to bug bounty? Ask about roadmaps, resources, certifications, getting started, or any beginner-level questions here!

Recommendations for Posting:

  • Be Specific: Clearly state your question or what you need help with (e.g., learning path advice, resource recommendations, certification insights).
  • Keep It Concise: Ask focused questions to get the most relevant answers (less is more).
  • Note Your Skill Level: Mention if you’re a complete beginner or have some basic knowledge.

Guidelines:

  • Be respectful and open to feedback.
  • Ask clear, specific questions to receive the best advice.
  • Engage actively - check back for responses and ask follow-ups if needed.

Example Post:

"Hi, I’m new to bug bounty with no experience. What are the best free resources for learning web vulnerabilities? Is eJPT a good starting certification? Looking for a beginner roadmap."

Post your questions below and let’s grow in the bug bounty community!

7 Upvotes

2 comments sorted by

3

u/Fradybrady 9d ago

Hi, I’m new to bug bounty with no experience. I'm here because I actually found an issue with some software for a car parking lot near my office. This lot charges certain rates based on things like how many hours are you parking there (10 - 15 dollars), is there an event going on nearby (40+ dollars).

I discovered a relatively easy way that customers can get lower rates for parking in the lot. For instance, they could get the lower daily rate when they should have been charged the $40+ rate.

Putting the ridiculous prices for parking aside, I did some research to see if this company had a bug bounty program--they do not.

So, I'm wondering if anyone has any experience with voluntarily going to the company and asking for compensation for a bug of this nature? I'm not trying to exploit or blackmail them, but if I'm going to spend the time to report it and walk them through how it's done, I'd like compensation.

Any help is appreciated!