Skip to content

Making this repository for beginners to secure their first bounty within 90 days.

Notifications You must be signed in to change notification settings

najam1997/bugbountyin90days

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 
 
 

Repository files navigation

Conquering the process of Bug Bounty

Making this repository for beginners in bug bounty. Aim is to master reconnaissance techniques and gain intermediate-level experience as a Client-Side vulnerabilities' Bounty Hunter.
Started: 1st Aug 2024

Pre-requisite: Make sure you've good understanding of JS. You can also refer my path

Key:
✔️ : Completed
❌ : Incomplete
⭕ : In progress

Week 1 (Cross Site Scripting Basics):

Day 1:

Day 2:

Day 3:

Day 4:

Day 5:

Day 6:

Day 7:

Week 2 (Javascript Basics):

Day 8:

  • [✔️] Started Revising all XSS concepts including some Labs.

Day 9:

  • [✔️] Completed Revision.

Day 10:

Day 11 and 12:

Day 13:

Day 14:

Week 3 (Javascript Basics 2 and started learning Recon. Basics):

Day 15:

Day 16:

Day 17:

Note:

Now that we are done with JS basics. We will move back to XSS.

Day 18:

  • [✔️] Watched some Dom-based XSS tutorials on Youtube.

Day 19 and 20:

Day 21:

Week 4 ():

Day 22:

Day 23:

Days 24 and 25:

Day 26 to 28:

Week 5 (XSS real-world scenarios):

Days 29 to 35:

  • [✔️] Read multiple Reports on Medium and infosec Writeups regarding various types of reported XSS vulnerabilities
  • [✔️] Watched multiple XSS POCs on Youtube
  • [✔️] Learnt to Used Chrome Dev Tools to find DOM Based XSS
  • [✔️] Revised Portswigger Labs on DOM Based XSS
  • [✔️] Mobile Application Research Days 1 to 5

Week 6 (Strengthened XSS concepts for real-world scenarios):

Days 36 to 38:

  • [✔️] Worked on finding DOM based XSS sinks on Github along with Client-Side debugging

Day 39 to 42:

  • [✔️] Revised Portswigger Labs on DOM Based XSS and searched for potential sinks in real-world applications.
  • [✔️] Enumeration Day 10

Week 7 (Mastering XSS - Escaping Characters):

Days 43 to 49:

  • [✔️] Completed Remaining DOM Based XSS Labs on Portswigger
  • [✔️] Started XSS Challenges
  • [✔️] Researched for tools to perform Automated XSS

Week 8 (Mastering XSS - Breaking Logic):

Days 50 to 56:

Week 9 (Client-Side Vulnerabilities and Reconnaissance):

Days 57 to 61:

Days 62 and 63:

Week 10 (Client-Side Vulnerabilities and Reconnaissance):

Days 64 to 70:

  • [✔️] Enumeration Day 13
  • [✔️] Enumeration Day 14
  • [⭕]

Week 11 (Client-Side Vulnerabilities and Reconnaissance):

Days 71 to 77:

  • [⭕]

Week 12 (Client-Side Vulnerabilities and Reconnaissance):

Days 78 to 84:

  • [⭕]

About

Making this repository for beginners to secure their first bounty within 90 days.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published