10 Tips For Crushing Bug Bounties in the First 12 Months

Поділитися
Вставка
  • Опубліковано 7 лют 2025

КОМЕНТАРІ • 142

  • @mirhat9330
    @mirhat9330 4 роки тому +92

    1. Persistence
    2. Automation
    3. Quality Educational Resources(Pentesterlab, The web application hacker's handbook)
    4. Collaboration
    5. Community
    6. Health
    7. Know the basics
    8. Do what you're good at
    9. Hack where there's less competition
    10. Just Start

  • @aerodraws1689
    @aerodraws1689 2 роки тому +4

    See, I'm looking for videos on hunting bugs, like irl bugs, moths, bees, butterflies, beetles, THAT type of bugs. And I sat here SO confused for a solid couple minutes- anyways, still a great video! Really well put together

  • @arzoo_singh
    @arzoo_singh 3 роки тому +2

    Brother I must say .
    I love the way you Communicate very down to earth and trying to help other .
    Just subscribed for you're Greta attitude .
    Keep on doing great works .

  • @ishanpatel8386
    @ishanpatel8386 4 роки тому +5

    Damn damn damn, I've been following you on twitter and I am one of the first people to sub as I know your worth man I'm sharing your channel and videos so that many people can get your valuable tips and knowledge ♥️ thank you so much man for doing this for us.

  • @joshgordon7299
    @joshgordon7299 4 роки тому +2

    I've learned how to use nmap recently and made a script that takes the IPs of all subdomains and pipes it threw nmap and the stores the results in its own directory and file. Im very stoked on what I've learned

  • @brice2825
    @brice2825 Рік тому

    I like the way you touched on health, most people ignore it, thanks for the video

  • @oneplus7t382
    @oneplus7t382 3 роки тому

    Very first video I watched fully on UA-cam ❤️the way you speak hits different ❤️ HUMBLE ❤️ Respect to you sir❤️

  • @pavelPwn
    @pavelPwn 2 роки тому +4

    I got involved in the 'hunting' less than a week ago. I really got obsessed and went through 100/200 topics, videos, websites, hunters, tweets, etc ... and you are the first one to mention OWASP Top 10 + the Fundamentals metaphor, this touched me a lot and I think it's the most important, together with the Persistence ( and Curiosity ).
    THANK YOU for your contributions and existence 🙏

  • @kartikeyasharma6056
    @kartikeyasharma6056 4 роки тому +1

    After watching your video i am gonna take 100 days of learning challenge and will update it regularly 👍👍

  • @VishalChauhan-nb7lb
    @VishalChauhan-nb7lb 4 роки тому +5

    This is really a great video that everyone must watch in their initial phase of bug hunting.
    This should be the actual guide .. great work ✌️.. this helps me 😇

  • @PTD2023
    @PTD2023 4 роки тому +7

    Could not agree more about the health side of thing. I have been the one man I.T army who's always on call 24 /7 - it doesn't end well

  • @naveenkumarb7102
    @naveenkumarb7102 Рік тому

    Its really good motivator and brings more energy after seeing this video. Also, clearly explained the tips based on your experience

  • @haksting
    @haksting 4 роки тому +2

    Hey Luke, did somebody told u that u r awsm in explaining n teaching things ? Awsm video n tips 👍

  • @mib141345
    @mib141345 2 роки тому

    Thanks for these tips, I'm just starting out bug bounty hunting.

  • @hugoalexandregoncalvespica124
    @hugoalexandregoncalvespica124 4 роки тому +2

    I love your way to see things, and not just about bugbounty,but life in general (when u talked about the law of the universe , for example). Amazing tips ! Can I ask you ... because that really gave me motivation...You really believe that with hardwork and dedication a guy thats just a beginner could achieve something as bugbounty? Sometimes it looks like its really difficult... today I was studying xss and men... It looked really hard and almost impossible to learn! And other thing if you may... About collaboration... U think there is somebody that wants to collaborate with an beginner in this world? Thanks for your videos! Keep up with this great content! 🙏

    • @hakluke
      @hakluke  4 роки тому +1

      Absolutely - everyone who is successful in anything was a beginner once, and now they're successful! You would be able to find some people to collaborate with in the various bug bounty discords and slacks around the place :)

    • @hugoalexandregoncalvespica124
      @hugoalexandregoncalvespica124 4 роки тому

      @@hakluke Thanks for your kind words 🙏! It really helps! Im still on the getting knowledge phase before try real bugbounty. Can u advice some discords? Im on bugcrowd and h1. Thanks for your time

  • @andreagrigoletto8101
    @andreagrigoletto8101 4 роки тому +4

    Thank you for this video, it's an energy boost for me!

  • @faboxbkn
    @faboxbkn 2 роки тому

    Amazing content! Subscribed, greetings from Chile.

  • @sep7im535
    @sep7im535 4 роки тому

    I really needed to hear this advice and I didn't even know it. Thanks a lot! Cheers from Argentina

  • @InfiniteLogins
    @InfiniteLogins 4 роки тому +1

    Fantastic content man! Thank you for this.

  • @JK-pb3vj
    @JK-pb3vj 4 роки тому +1

    Outstanding advice mate - keep this type of thing up, people need to hear it! 🤙 cheers from BNE, AU

    • @hakluke
      @hakluke  4 роки тому

      Thanks Justin! We live in a great city!

  • @fenilshah9221
    @fenilshah9221 4 роки тому +21

    Luke, can you make your own discord server, please?

  • @MrBlackhats
    @MrBlackhats 4 роки тому

    Excellent 10 tips Luke! Thanks a lot from Argentina ... Also you make top toolz in Github!

  • @oneplanet2198
    @oneplanet2198 2 роки тому

    God bless you for the direction...good man

  • @darkhack3r417
    @darkhack3r417 4 роки тому

    another amazing person on youtube !!!
    just subscribed 😚😚 😍😍

  • @blackblack5702
    @blackblack5702 4 роки тому +2

    Thanks Master Luke , building my Skyscraper foundation :)

  • @dubwavefm3834
    @dubwavefm3834 2 роки тому

    brilliant vid man. helped me alot

  • @naveenkumarb7102
    @naveenkumarb7102 Рік тому

    I could see two different titles and more are close to each other
    The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws
    he Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws
    Any specific version or edition you refer?

  • @9509daniel
    @9509daniel 4 роки тому +1

    Luke you are the best! Can you share tips on how to script the automation part efficiently?

  • @deanramos9728
    @deanramos9728 4 роки тому

    Great person and great video! Nothing but the best for luke!

  • @RishabhMishraIndia
    @RishabhMishraIndia 4 роки тому +1

    I have one question, I picked a relatively small program to start with, how much time should we invest in such a program before we move on to another program in case we are unable to find anything?

    • @hakluke
      @hakluke  4 роки тому +1

      There really isn't a correct answer to this, it depends on the program and your skill set. I'd say if you feel like you've exhausted everything on that program - time to move on.

    • @RishabhMishraIndia
      @RishabhMishraIndia 4 роки тому

      @@hakluke thanks! Really appreciate it! ❤️

  • @bmac5044
    @bmac5044 4 роки тому +1

    Do you think it's possible to get into bug bounty hunting if you don't come from a Dev background? And if yes, where do you think would be the best place to start, or what skills to focus on?

    • @hakluke
      @hakluke  4 роки тому

      Yes it is possible, and I'd follow the steps in this video :) Also checkout my talk from levelup on the same topic.

    • @neotroncs
      @neotroncs 2 роки тому

      Heard a friend talking about this and wanted to check it out. Been surfing youtube. My problem is there is no foundation to start on. People say there is so many different way to do this that there is no one way. You have to start where your skills are at or what you're passionate about. I know nothing about any of this but it does interest me. I do have a small background in networking but that is all. Did you find your answer on were to start? If so please give details.

  • @sail6114
    @sail6114 4 роки тому

    We want another one 🔥🔥 waiting !

  • @sunilkumarnath3488
    @sunilkumarnath3488 4 роки тому

    All checked except 2 and 4... Poor in automation and collaboration... You explain well within words... Keep going... Kudos..

  • @rohitborate5126
    @rohitborate5126 2 роки тому

    Can you make a video series on how hackers should get started with coding

  • @jamesbuckley5330
    @jamesbuckley5330 4 роки тому

    I am just starting out and cam across your blog about automating sub domain takeover recon. It seems a good starting point. Would you still recommend subfinder over amass ?

  • @katr2771
    @katr2771 2 роки тому

    What tool do we use to automation

  • @macktheripper7454
    @macktheripper7454 Рік тому

    Hey buddy great video. When you say get involved in the community, do you mean discord? What exactly do you mean? If you do mean discord it’d be great to have some links 🙏

  • @nithinravi10
    @nithinravi10 4 роки тому +5

    Hey @hakluke, can you add timestamps for the upcoming videos? Might be really helpful.

  • @muhamadrafli7831
    @muhamadrafli7831 4 роки тому

    does pentesterlab help for someone who doesnt have any it background??

  • @rahulasthana15
    @rahulasthana15 4 роки тому

    Thanks for starting the channel 😃

  • @dhruvilpatel1201
    @dhruvilpatel1201 4 роки тому +1

    Hakluke rocks.

  • @techsahabi1725
    @techsahabi1725 2 роки тому

    Thanks for sharing Luke Bro

  • @dans2666
    @dans2666 4 роки тому +1

    Do bug bounties include attacking the actual server or network as well? Like Hackthebox CTF style?

    • @hakluke
      @hakluke  4 роки тому +1

      Depends on the scope, but generally yes

  • @domaincontroller
    @domaincontroller 4 роки тому

    03:21 fresh programs, new target, new subdomains, new ip adress range, acquisitions, changes to DNS records, endpoints, refurbished the website

  • @neerajk008
    @neerajk008 4 роки тому +2

    @hakluke What all can be automated and how can be , can you please make a video on that, thanks for your support, i heard you saying for that to automate stuff for consistency, Appreciate in advance

  • @hemanth1260
    @hemanth1260 4 роки тому

    Excellent Video , loved it , keep doing more videos .....

  • @ucheugbomah2228
    @ucheugbomah2228 11 місяців тому

    sorry how long did it take you to find your first bug my Man?

  • @xtravagantjose4210
    @xtravagantjose4210 4 роки тому

    Hakluke is the best.

  • @scarytruths01
    @scarytruths01 Рік тому

    I also work for bugcrowd and have been struggling a bit...

  • @0xhhhhff
    @0xhhhhff 3 роки тому

    What are the basics we need to know other than Burpsuite? I am learning JavaScript and python. I'm a beginner. Tips?

  • @sunilrai5506
    @sunilrai5506 3 роки тому

    Hello, sir, I had watch your video in bugcrowd (How to Crush Bug Bounties in the first 12 Months) and I am totally confused that you talk about bug bounty automated and earn passive income that means you explain about investing or something. could you plz explain sir

  • @mearenotme
    @mearenotme 4 роки тому

    i just have a question , i am hunting only 2h up to 3h every day the rest of my time trying expanding my knowledge , so should i expend more time in hunting then learning , i just try full time hunting every Thursday but also no result at all

  • @abartandhakal9258
    @abartandhakal9258 4 роки тому

    Take my subscription 🤪
    Thanks heaps mate!

    • @hakluke
      @hakluke  4 роки тому +1

      Hope you're well haxormad!

    • @abartandhakal9258
      @abartandhakal9258 4 роки тому

      @@hakluke Yes I am 😁
      Hoping you doing well alongside the fam there!

  • @sinwolf5539
    @sinwolf5539 4 роки тому

    Thank you for the awesome video !!

  • @lnchandila6300
    @lnchandila6300 4 роки тому

    sir make a series for developing tools/scripts related to bash

  • @aty4282
    @aty4282 3 роки тому

    I wanna do this, but isnt it weird to just rely on that trust? Like you tell a company "hey, look, this is broken and this can happen" then what if the company ignores you and just fixes that? Or do you make some kind of a contract before looking for their bugs?

    • @Cognitoman
      @Cognitoman 2 роки тому

      Then next time to you find one you sell it online lol

  • @vikingsghosts6213
    @vikingsghosts6213 4 роки тому

    Good content keep going

  • @rafaelbarua3601
    @rafaelbarua3601 4 роки тому

    thanks man for this great video❤

    • @hakluke
      @hakluke  4 роки тому

      Thanks for commenting!

  • @monusingh2336
    @monusingh2336 4 роки тому

    Love your content brooooooooooo !!

  • @小猪圆圆
    @小猪圆圆 3 роки тому

    i dont know how to find a community? can u give me a example

  • @denverzimunya8303
    @denverzimunya8303 2 роки тому

    Thank you Luke

  • @robertfling6173
    @robertfling6173 4 роки тому +1

    Where would i go to find some collaborators? I think its easier to learn in a group, need to find a good group

    • @nithinravi10
      @nithinravi10 4 роки тому

      I've been practising for sometime recently and open to collab

    • @robertfling6173
      @robertfling6173 4 роки тому

      @@nithinravi10 on Instagram or Twitter I will dm u

    • @brandonroldan5430
      @brandonroldan5430 4 роки тому

      @@robertfling6173 do you mind if i join too?

    • @sayondutta3530
      @sayondutta3530 4 роки тому

      @@brandonroldan5430 and if you don't mind me too

    • @nithinravi10
      @nithinravi10 4 роки тому

      @@robertfling6173 Drop by your discord sir, I'll dm you.

  • @hackersguild8445
    @hackersguild8445 4 роки тому

    Awesome man with the awesome video.:D

  • @shrirangkahale
    @shrirangkahale 4 роки тому +1

    Ty

  • @sy-gamer9556
    @sy-gamer9556 4 роки тому

    Is real world bug bounty hunting 2019 book is good for beginners

    • @hakluke
      @hakluke  4 роки тому +1

      I have not heard of it

    • @sy-gamer9556
      @sy-gamer9556 4 роки тому

      @@hakluke its a revised version of web hacking 101

  • @0xsudip892
    @0xsudip892 4 роки тому

    Awesome content 😯

  • @aneeshnadh5377
    @aneeshnadh5377 4 роки тому

    Really good, it helps

  • @jessepinkman2031
    @jessepinkman2031 4 роки тому

    Amazing video Keep up

  • @ЮрійМинаш
    @ЮрійМинаш Рік тому

    Thanks!

  • @ankitkushwah09
    @ankitkushwah09 4 роки тому

    Thank You ❤️❤️❤️

  • @safenatsafenat9468
    @safenatsafenat9468 4 роки тому

    Can you make a video for how to make an automation script for monitoring or scanning a certain stuff ... thanks for your help.

    • @hakluke
      @hakluke  4 роки тому +1

      We shall see!

  • @nikhilkhetan9125
    @nikhilkhetan9125 4 роки тому

    Thank you😊

  • @Hackworm
    @Hackworm 2 роки тому

    Thanks man 🧑❤️

  • @mouradmohsen838
    @mouradmohsen838 3 роки тому

    Thanks a lot

  • @dopbip4399
    @dopbip4399 4 роки тому

    Thanks man...

  • @deepakkumar-ri6xs
    @deepakkumar-ri6xs 4 роки тому

    Just started

  • @pauraspatil9314
    @pauraspatil9314 3 роки тому

    Awesome tips!

  • @ProjectSage
    @ProjectSage 4 роки тому

    makeMORE.exe !!!!!!!!!!
    Love ya man ^^ thank you for that !

  • @computerevolve8416
    @computerevolve8416 3 роки тому

    thanks for this video

  • @b-78mofakkarulislamtonoy17
    @b-78mofakkarulislamtonoy17 3 роки тому

    Bro please share you bug pocs🥰

  • @MH-tw1qi
    @MH-tw1qi 4 роки тому

    Persistence 💯💯💯

  • @moe42937
    @moe42937 4 роки тому

    Thank you

  • @NA-nr4fb
    @NA-nr4fb 3 роки тому

    Ok Sir

  • @deeperdeeper7882
    @deeperdeeper7882 Рік тому

    I guess you told in a video smtime ago Like start trying(may be in this video only.. I m bit on drinks.. hving trouble figuring out, sorry) .. I hv started actively after seeing your video though.. and, thanks to you.. I was just learning labs on portswigger n wen I tried exploring with bit free hand after ur advice to try, I came across subdomain takeovers. Wealth of knowledge out there on so many things..
    and, actually before that I tried checking Real companies from hackerone after ur advice to try. And, what I saw in labs n wat I was seeing wen intercepting real things was like, if I hv to say, disappointing, scary n heart wrenching. It’s as if I thought Like I cud find a bug but the site was literally humiliating me.
    What can we do except for learning things like an amateur🤭.. I will keep trying.. I may fail again n again n again..
    thanks for valuable words💐

    • @deeperdeeper7882
      @deeperdeeper7882 Рік тому

      If I hv to confess shamelessly, I get scared wen I see so mny requests rolling in burp proxy with just a single click on website. Whatever concepts I hv learned don’t seem applicable there.
      It frustrates.. may b tats y ppl like hakluke advise to try n Feel it..
      I m trying wen I can.. let’s see😐😴

  • @good2577
    @good2577 4 роки тому

    Thankyou 🙂

  • @yamkelakutu5707
    @yamkelakutu5707 4 роки тому

    A gem 💯

  • @iamskidrow
    @iamskidrow 3 роки тому

    Crushing bug bounties with 15k others

  • @tusharvyas7483
    @tusharvyas7483 4 роки тому

    Awesome 👍

  • @tekken-pakistan2718
    @tekken-pakistan2718 4 роки тому

    1:20 damn same!

    • @tekken-pakistan2718
      @tekken-pakistan2718 4 роки тому

      Thanks, this was really good and motivating. Liked, subscribed and press that bell icon! ( :

  • @andreyq9179
    @andreyq9179 4 роки тому

    thanks!

  • @ohiomim1045
    @ohiomim1045 4 роки тому

    For the second tip...I want to add...Just learn bash stuff

  • @StefanRows
    @StefanRows 4 роки тому

    Here, take my sub.

    • @hakluke
      @hakluke  4 роки тому

      Hope you're well Ceos3c!

  • @technicaltalk1638
    @technicaltalk1638 4 роки тому

    Love from Pakistan

  • @shubham_srt
    @shubham_srt 2 роки тому

    ❤️

  • @fenilshah9221
    @fenilshah9221 4 роки тому

    You rock man!!!!!!

  • @arpeetrathi
    @arpeetrathi 4 роки тому

    Tips❤❤

  • @itsfran76
    @itsfran76 4 роки тому

    "get enough sleep" ehhhhhmmmmm

  • @aymenelhaski8985
    @aymenelhaski8985 4 роки тому

    subscribe button: [on fire]

  • @yanicksauvageau5284
    @yanicksauvageau5284 Рік тому

    Wow,,never see you,,no 8 oufff you want to kill me,,listen a 2 first minute and i’m totaly stuck on your parole......long time no see,and never write that....new wold,peace

  • @goooooo9197
    @goooooo9197 4 роки тому

    Love u 3000