Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Introduction to Bug Bounty Programs
- Defining bug bounty hunting.
- Exploring various program types and platforms, including HackerOne, Bugcrowd, and Synack.
- Addressing legal and ethical aspects, such as scope, disclosure policies, and NDAs.
Vulnerability Classes and OWASP Top 10
- Analyzing the OWASP Top 10 vulnerabilities.
- Examining case studies derived from real-world bug bounty reports.
- Utilizing tools and checklists to detect issues.
Essential Tools
- Fundamentals of Burp Suite, covering interception, scanning, and the repeater feature.
- Utilizing browser developer tools.
- Applying reconnaissance tools like Nmap, Sublist3r, and Dirb.
Testing for Common Vulnerabilities
- Cross-Site Scripting (XSS).
- SQL Injection (SQLi).
- Cross-Site Request Forgery (CSRF).
Bug Hunting Methodologies
- Conducting reconnaissance and target enumeration.
- Comparing manual versus automated testing strategies.
- Applying effective bug bounty hunting tips and workflows.
Reporting and Disclosure
- Crafting high-quality vulnerability reports.
- Including proof of concept (PoC) and clear risk explanations.
- Collaborating with triagers and program managers.
Bug Bounty Platforms and Professional Growth
- Reviewing major platforms such as HackerOne, Bugcrowd, Synack, and YesWeHack.
- Exploring ethical hacking certifications, including CEH and OSCP.
- Understanding program scopes, rules of engagement, and industry best practices.
Summary and Next Steps
Requirements
- Familiarity with fundamental web technologies, such as HTML and HTTP.
- Proficiency in using web browsers and standard developer tools.
- A keen interest in cybersecurity and ethical hacking practices.
Target Audience
- Individuals aspiring to become ethical hackers.
- Security enthusiasts and IT professionals.
- Developers and QA testers with an interest in web application security.
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.