Roadmap
Bug Bounty
A realistic route into responsible disclosure: program rules, asset knowledge, a repeatable testing loop, and report quality.
Prerequisites
- Web fundamentals
- Patience with duplicates and N/A responses
Who it is for
Self-directed learners aiming at public disclosure programs
Outcome: You read a policy before you touch a target, focus on classes the app genuinely exposes, and write reports triagers can act on.
Stages
Work them in order the first time. Ticking a stage only records your own progress, in this browser.
Stored in this browser only. No account, no sync.
Read the policy like a contract
In-scope assets, prohibited testing types, rate expectations, safe harbour.
4 hoursLearn
- Out-of-scope list vs wildcard
- What 'no destructive testing' means concretely
Build the asset list
Passive discovery of names and services, then confirm what is in scope.
1 weekUnderstand the application
Business logic beats payload libraries. What does this app protect, and for whom?
1–2 weeksToolsBurp SuitePick two issue classes
Depth in authorisation and one input-handling class, revisited across features.
2–4 weeksReports that get triaged
Exact steps, clean impact statement, no drama.
1 weekLearn
- Reproduction from a fresh account
- Writing impact for a product owner
Disclosure discipline
No publicPoC without agreement. Data you should not have, stop and report.
3 hoursLearn
Tools in this path
Each tool page carries installation steps, commands and the errors you will hit.