Skip to content

Latest commit

 

History

History
113 lines (110 loc) · 6.12 KB

README.md

File metadata and controls

113 lines (110 loc) · 6.12 KB

Conquering the process of Bug Bounty

Making this repository for beginners in bug bounty. Aim is to master reconnaissance techniques and gain intermediate-level experience as a Client-Side vulnerabilities' Bounty Hunter.
Started: 1st Aug 2024

Pre-requisite: Make sure you've good understanding of JS. You can also refer my path

Key:
✔️ : Completed
❌ : Incomplete
⭕ : In progress

Week 1 (Cross Site Scripting Basics):

Day 1:

Day 2:

Day 3:

Day 4:

Day 5:

Day 6:

Day 7:

Week 2 (Javascript Basics):

Day 8:

  • [✔️] Started Revising all XSS concepts including some Labs.

Day 9:

  • [✔️] Completed Revision.

Day 10:

Day 11 and 12:

Day 13:

Day 14:

Week 3 (Javascript Basics 2 and started learning Recon. Basics):

Day 15:

Day 16:

Day 17:

Note:

Now that we are done with JS basics. We will move back to XSS.

Day 18:

  • [✔️] Watched some Dom-based XSS tutorials on Youtube.

Day 19 and 20:

Day 21:

Week 4 ():

Day 22:

Day 23:

Days 24 and 25:

Day 26 to 28:

Week 5 (XSS real-world scenarios):

Days 29 to 35:

  • [✔️] Read multiple Reports on Medium and infosec Writeups regarding various types of reported XSS vulnerabilities
  • [✔️] Watched multiple XSS POCs on Youtube
  • [✔️] Learnt to Used Chrome Dev Tools to find DOM Based XSS
  • [✔️] Revised Portswigger Labs on DOM Based XSS
  • [✔️] Mobile Application Research Days 1 to 5

Week 6 (Strengthened XSS concepts for real-world scenarios):

Days 36 to 38:

  • [✔️] Worked on finding DOM based XSS sinks on Github along with Client-Side debugging

Day 39 to 42:

  • [✔️] Revised Portswigger Labs on DOM Based XSS and searched for potential sinks in real-world applications.
  • [✔️] Enumeration Day 10

Week 7 (Mastering XSS - Escaping Characters):

Days 43 to 49:

  • [✔️] Completed Remaining DOM Based XSS Labs on Portswigger
  • [✔️] Started XSS Challenges
  • [✔️] Researched for tools to perform Automated XSS

Week 8 (Mastering XSS - Breaking Logic):

Days 50 to 56:

Week 9 (Client-Side Vulnerabilities and Reconnaissance):

Days 57 to 61:

Days 62 and 63:

Week 10 (Client-Side Vulnerabilities and Reconnaissance):

Days 64 to 70:

  • [✔️] Enumeration Day 13
  • [✔️] Enumeration Day 14
  • [⭕]

Week 11 (Client-Side Vulnerabilities and Reconnaissance):

Days 71 to 77:

  • [⭕]

Week 12 (Client-Side Vulnerabilities and Reconnaissance):

Days 78 to 84:

  • [⭕]