OSCP + GPEN Need advice !

Lastexile

Arch-Supremacy Member
Joined
Mar 6, 2004
Messages
11,718
Reaction score
126
Why do you think the famous sg hacker Spaceraccoon is so good at bug hunting?

I think he's not only smart but also invested a lot of time and effort into learning everything that comes along his way. If you have read his blog spots where he wrote about his methodology to hunt for certain bugs, he seems to have a good grasp at the primitive blocks that could lead to a bug. With that kind of understanding, he is more likely to observe weird behaviours and dig deeper into them.

Furthermore success breeds success. Once one hits a certain reputation, he/she will be invited to private bounty programme and live events, that's where low hanging bugs are more likely to be found. Collaborating with other top hunters also help one improve the hunting methodology to discover other bugs that one doesn't usually hunt for.

If i were to do bug bounty, I will either check out all the latest research or do some research for myself then hunt specifically for those stuff across different bounty programmes. Otherwise I would go for subtle business logic bugs or single-sign on authentication issues.

 

Trader11

Banned
Joined
Oct 14, 2018
Messages
15,697
Reaction score
5,235
I think he's not only smart but also invested a lot of time and effort into learning everything that comes along his way. If you have read his blog spots where he wrote about his methodology to hunt for certain bugs, he seems to have a good grasp at the primitive blocks that could lead to a bug. With that kind of understanding, he is more likely to observe weird behaviours and dig deeper into them.

Furthermore success breeds success. Once one hits a certain reputation, he/she will be invited to private bounty programme and live events, that's where low hanging bugs are more likely to be found. Collaborating with other top hunters also help one improve the hunting methodology to discover other bugs that one doesn't usually hunt for.

If i were to do bug bounty, I will either check out all the latest research or do some research for myself then hunt specifically for those stuff across different bounty programmes. Otherwise I would go for subtle business logic bugs or single-sign on authentication issues.


Within two years, he became a top hacker. Whereas most people take 10-20 years to do that. President Scholar is really different calibre....
https://www.todayonline.com/singapore/five-receive-presidents-scholarship

Bro, do you hunt for bugs as well to earn extra reputation? If you try the latest research, all the India and US hackers are going to try the same thing as well and you will have many duplicates.
 
Last edited:

Lastexile

Arch-Supremacy Member
Joined
Mar 6, 2004
Messages
11,718
Reaction score
126
Within two years, he became a top hacker. Whereas most people take 10-20 years to do that. President Scholar is really different calibre....
https://www.todayonline.com/singapore/five-receive-presidents-scholarship

Bro, do you hunt for bugs as well to earn extra reputation? If you try the latest research, all the India and US hackers are going to try the same thing as well and you will have many duplicates.

No you don't need 10-20 years to do achieve that. It is definitely doable within 2 years, but you need to persevere in the first year and put in all the effort to learn the stuff. I won't discount his effort just because he's a president scholar.

Well it boils down to how much you understand the research to cater to edge cases that people are unlikely to find and how you develop your own heuristic and automate the discovery process to be faster than others. Or do your own research :)
 

Trader11

Banned
Joined
Oct 14, 2018
Messages
15,697
Reaction score
5,235
No you don't need 10-20 years to do achieve that. It is definitely doable within 2 years, but you need to persevere in the first year and put in all the effort to learn the stuff. I won't discount his effort just because he's a president scholar.

Well it boils down to how much you understand the research to cater to edge cases that people are unlikely to find and how you develop your own heuristic and automate the discovery process to be faster than others. Or do your own research :)

What specific stuffs are you referring to? I see most apps don't have schoolboy errors now. The problem are mostly neglected assets which pentester ignore or nobody cares about
 
Important Forum Advisory Note
This forum is moderated by volunteer moderators who will react only to members' feedback on posts. Moderators are not employees or representatives of HWZ Forums. Forum members and moderators are responsible for their own posts. Please refer to our Community Guidelines and Standards and Terms and Conditions for more information.
Top