Skip to content

Roadmap

Bug Bounty

A realistic route into responsible disclosure: program rules, asset knowledge, a repeatable testing loop, and report quality.

Intermediate6 stagesOngoing; 6–12 weeks to a first solid report

Prerequisites

  • Web fundamentals
  • Patience with duplicates and N/A responses

Who it is for

Self-directed learners aiming at public disclosure programs

Outcome: You read a policy before you touch a target, focus on classes the app genuinely exposes, and write reports triagers can act on.

Stages

Work them in order the first time. Ticking a stage only records your own progress, in this browser.

Progress0 / 60%

Stored in this browser only. No account, no sync.

  1. Read the policy like a contract

    In-scope assets, prohibited testing types, rate expectations, safe harbour.

    4 hours

    Learn

    • Out-of-scope list vs wildcard
    • What 'no destructive testing' means concretely
  2. Build the asset list

    Passive discovery of names and services, then confirm what is in scope.

    1 week
  3. Understand the application

    Business logic beats payload libraries. What does this app protect, and for whom?

    1–2 weeks
  4. Pick two issue classes

    Depth in authorisation and one input-handling class, revisited across features.

    2–4 weeks
  5. Reports that get triaged

    Exact steps, clean impact statement, no drama.

    1 week

    Learn

    • Reproduction from a fresh account
    • Writing impact for a product owner
  6. Disclosure discipline

    No publicPoC without agreement. Data you should not have, stop and report.

    3 hours

Tools in this path

Each tool page carries installation steps, commands and the errors you will hit.