You will never be ready until you start!
This idea is born from someone who started programming at 14 and never felt ready until 40, doing all sorts of other work in the meantime.
Especially today, you will never know everything. "Enough" is simply the amount of preparation that lets you start and get through 80% of the work (see the Pareto Principle).
I start with an advantage here, since I'm already a web programmer, so the fundamentals of how the internet works are already familiar to me — though I still want a quick refresher on that too.
I searched around for resources and courses and came across NahamSec on YouTube. I found his suggestions useful, but his Hands-On Web Exploitation Course felt a bit disorganized to me (a lot of the material comes from an earlier Udemy course).
I know I need both theory and hands-on practice to start off on the right foot, and I made my choices partly based on the web proxy I'd already decided to use:
- Bug Bounty Bootcamp by Vickie Li
- Real-World Bug Hunting by Peter Yaworski
- PortSwigger Academy
- Caido Hubs
- YesWeHack Dojo
Vickie Li and Peter Yaworski are cited by NahamSec and many others, and I prefer books when studying. PortSwigger Academy is a reference point in the field, and it's free too. I picked the last two resources based on my choice of web proxy and bug bounty platform (the next article will go into more depth on that).
BUT WAIT... ALL OF THAT??
Holy shit! Clearly not! I'm old! I don't have that kind of time before I can start!
After some thought and a read through the OWASP Top Ten, I decided to focus my initial efforts on just three types of bugs:
- Insecure Direct Object Reference (IDOR)
- Cross-Site Scripting (XSS)
- Information Disclosure and Business Logic Vulnerabilities
They don't map perfectly 1:1 onto the 2025 OWASP Top Ten, but I still chose them for the logic involved in each type of bug.
There's already a lot to work through in bug bounty hunting with just these three, but narrowing the scope cuts down my starting study and practice time considerably.
So here's my plan.
Basics:
- Real-World Bug Hunting, Ch. 1: Bug Bounty Basics
- Bug Bounty Bootcamp, Ch. 3: How the Internet Works
- Bug Bounty Bootcamp, Ch. 4: Environment Setup (*)
- Bug Bounty Bootcamp, Ch. 5: Web Hacking Reconnaissance
- Real-World Bug Hunting, Ch. 19: Finding Your Own Bug Bounties
(*) If you prefer Caido and want to know exactly why I chose it over Burp Suite, you'll have to wait for my next article...
XSS
- Bug Bounty Bootcamp, Ch. 6
- Real-World Bug Hunting, Ch. 7
- PortSwigger Academy: XSS section
- Caido Hubs: Reflected XSS lab
- YWH Dojo: CWE-79
IDOR
- Bug Bounty Bootcamp, Ch. 10
- Real-World Bug Hunting, Ch. 16
- PortSwigger Academy: Access Control Vulnerabilities section
- Caido Hubs: Reflected IDOR lab
- YWH Dojo: CWE-639
App Logic and Information Disclosure
- Bug Bounty Bootcamp, Ch. 21
- Real-World Bug Hunting, Ch. 18
- PortSwigger Academy: Information Disclosure section
- PortSwigger Academy: Business Logic section
- Caido Hubs: Shift Payload lab
- Caido Hubs: Reflected HTTP Hunt Lottery lab
Once you've worked through all that, move on to:
Reports
- Bug Bounty Bootcamp, Ch. 2
- Real-World Bug Hunting, Ch. 20
After that, you can decide how you want to work (your own PC? a VPS?) and which platform or program to target.
If you're curious about my choices there, you'll need to wait for the next article.
At that point you know just enough to start!