The similarities between Bug Bounty and Video Game

The similarities between Bug Bounty and Video Game


In video games, you usually see the consequences of your actions after 30 seconds. In bug bounty, it takes several days or weeks. That's why it is harder to stay motivated in bug bounty.

In video games, the player with more actions-per-minute is more likely to win. It is the same in bug bounty, the bug hunter who performs more actions in a long period of time, is more likely to be successful than the one with lesser actions. The effectiveness of the actions matter too, but it will increase as the bug hunter gains more experience, so it happens naturally.

Some examples of actions-per-minute in bug bounty.
- Browses the target website and get familiar with its features.
- Looks at the details and discover "advanced", hard to see features. (if you post a comment in French, the website offers to translate it to English, this is a hard to see feature)
- Reads documentations, each article can be count as an action.
- Brainstorms attack scenarios.
- Verifies assumptions that you have while doing any of the above.
- Submits a report
- Replies to a report
- Looks up an English word/phrases to make your report clearer.
- Everything that may help you in the future is an action.

Accumulates enough of these actions will help you find bugs faster. You should judge your day by how many actions you can do, rather than how many bugs you can find. This is a more motivating way to do bug bounty.

Comments

  1. Hello! It's me! I am the same guy that has been commenting your recent blog posts. A week ago I found my first bug, an Open Redirect, though the security team said that I was a known issue so no rewards for me, wich kinda sucks but hey, it's still my first bug after I started bug hunting three months ago. What I am gonna do now is keep trying to hack everyday for at least 30 minutes and read Hackerone reports and writeups, and hopefully money will come eventually as I get better and better!

    ReplyDelete
    Replies
    1. I recognize you :). That's really nice to hear. That's a good and solid plan!

      Delete

Post a Comment

Comments are very welcome. I read all comments!

Popular posts from this blog

Beginner Tutorial - How to learn the Technical Skill and Hacker Mindset That Are Required to Find Your First Bug Bounty.

The power of focus

How to succeed in bug bounty as a non-talented bug hunter