I decided to hack on private program for 20 hours, In this story, I'll share my experiences about my journey.

The most common mistake in Bug bounty, when bug hunter picked a target to hack, hacker doesn't spend a long time on the target. So, when you pick a target hack on it for a long time. Actually, 20 hours is not a long time but it's enough to understand company logic. Let's talk about steps.

1 - Use timer

When you start to hack focus and use timer. I used for this.

Screenshot

2 - Take notes

Write everything you see about your target, technologies, responses for specific payloads, roles, capabilities for every single role… I will share my template and some example notes for this journey.

Screenshot

Priveleges in your target

Screenshot

Feature of endpoints and your notes about app

Screenshot

Error messages

Screenshot

Bugs & Potential Bugs

Screenshot

Reports

I made 5000$ in this journey. First of all, when I work with timer and notes like this, I enjoyed a lot than classic method. I'll share some of my reports too. Thanks for inspiring me!

Screenshot
Screenshot
Screenshot
Screenshot
Screenshot
Screenshot
Screenshot
Screenshot
Screenshot

Thanks you, have a great day.