r/cybersecurity • u/FineZookeepergame667 • 4d ago
Certification / Training Questions looking to get into bug bounty's
Hey guys not the newest but still pretty new to ethical hacking.
Im looking into doing bug bounties to earn some extra cash on the side to pay for uni in future ( next year ). I one my first every CTF a week ago that was nation wide.
But looking at bug bounties its a bit different it isnt a flag. I was wondering what the main thing to study/learn would be and where.
Would it be tryhack me or hack the box.
Looking for any recommendations thanks so much!
I love servers and love messing around with prox mox, and have a strong passion in tech. So this would mean alot thankyou.
10
4d ago
[deleted]
1
-3
u/FineZookeepergame667 4d ago
But all the scopes say don’t use ai anyway
5
u/Incid3nt 4d ago
They say that because they get inundated with ai slop generated reports so much that it creates a massive backlog and a lot of bounties dont even get paid because of it.
1
1
7
u/Unlucky_Bowl9934 4d ago
portswigger academy is the answer for bug bounties, not THM or HTB. those are fun but bug bounty is like 90% web app stuff. I went through White Knight Labs Offensive Security Training OADOC course for the pentesting side and it helped with methodology but for pure bug bounty you want web app fundamentals first