- Bug Bounty Hunting Essentials
- Carlos A. Lozano Shahmeer Amir
- 129字
- 2021-06-10 18:35:26
Targeting the right program
Targeting a bug is not a matter of luck. Instead, it is considered to be a matter of skills and luck. Don't waste time on finding the already reported bugs. Otherwise, you may end up being depressed by the duplication. It is suggested to spend time on understanding the functionality of the application. Also, try making notes and have a track of suspicious endpoints. You are not going to earn a satisfactory amount for the known issues if you are too early or the first one to report. If you get to know about a program within 10 to 12 hours of its launch, don't waste your time in looking for the issues at the surface level; rather, take a deep dive into the application.
推薦閱讀
- 黑客大曝光:無線網(wǎng)絡(luò)安全(原書第3版)
- 零信任網(wǎng)絡(luò):在不可信網(wǎng)絡(luò)中構(gòu)建安全系統(tǒng)
- 深入淺出隱私計(jì)算:技術(shù)解析與應(yīng)用實(shí)踐
- 計(jì)算機(jī)病毒原理與防范(第2版)
- 零信任網(wǎng)絡(luò):在不可信網(wǎng)絡(luò)中構(gòu)建安全系統(tǒng)(第2版)
- 軟件安全保障體系架構(gòu)
- 信息安全等級保護(hù)測評與整改指導(dǎo)手冊
- 博弈論與數(shù)據(jù)安全
- CTF快速上手:PicoCTF真題解析(Web篇)
- 信息系統(tǒng)安全等級化保護(hù)原理與實(shí)踐
- 黑客攻防從入門到精通:黑客與反黑客工具篇(第2版)
- ATT&CK與威脅獵殺實(shí)戰(zhàn)
- 數(shù)據(jù)恢復(fù)技術(shù)深度揭秘
- CCNA Security 210-260 Certification Guide
- ATT&CK視角下的紅藍(lán)對抗實(shí)戰(zhàn)指南