I decided to hack on private program for 20 hours, In this story, I'll share my experiences about my journey.
The most common mistake in Bug bounty, when bug hunter picked a target to hack, hacker doesn't spend a long time on the target. So, when you pick a target hack on it for a long time. Actually, 20 hours is not a long time but it's enough to understand company logic. Let's talk about steps.
1 - Use timer
When you start to hack focus and use timer. I used for this.

2 - Take notes
Write everything you see about your target, technologies, responses for specific payloads, roles, capabilities for every single role… I will share my template and some example notes for this journey.

Priveleges in your target

Feature of endpoints and your notes about app

Error messages

Bugs & Potential Bugs

Reports
I made 5000$ in this journey. First of all, when I work with timer and notes like this, I enjoyed a lot than classic method. I'll share some of my reports too. Thanks for inspiring me!









Thanks you, have a great day.