Thoughts

Bug bounty, feedback, strategy and alchemy

Published:

Honey attracts bees, and like many others who occasionally share moments of success, I often get asked recurring questions about bug bounty hunting: how I got started, what advice I’d give, what roadmap to follow, and so on. I figured it might be worthwhile to put some of my thoughts, experiences, and perspectives into writing for anyone curious about the subject.

Draft of a night walk: the diagnosis of a researcher’s quest for success

Published:

I’m coming back from a long nighttime walk with a friend, during which we had several interesting discussions. One of them seemed relevant enough to turn into the short draft you’re reading now. This friend has been training in offensive web security for almost a year. He’s an intelligent and particularly studious person, yet despite that, he’s struggling to find his first vulnerability during his bug bounty sessions, and we were trying to identify the potential reasons behind it.