top | item 24500198

Hacking on Bug Bounties for Four Years

89 points| infosecau | 5 years ago |blog.assetnote.io

10 comments

order
[+] drsh0|5 years ago|reply
I've got to respect the transparency and spirit of this post. Major props. What I really love is seeing all the partnerships that have gone into some of his work over the years. Didn't realize how mammoth of a task some of these reports must have been that were only made possible via collaboration.
[+] melvinroest|5 years ago|reply
A friend of mine looked at the feasibility of getting into bug bounty as a professional career. He mentioned that if you're not specialized on a specific attack, you have no chance.

I think it's quite refreshing to see that Shubham Shah is a strong counter example.

[+] Hitton|5 years ago|reply
Is he really strong counter example? If you actually count bounties he got this year so far, it's less than $50,000. I think he could easily earn more working as some kind of security engineer (with way less flexibility though).
[+] doopy1|5 years ago|reply
Automation of niche bug classes is the name of the game for high earners. Or you're the 0.01% and find new vulnerabilities in services that will pay big bucks for them. For example account takeovers in Google, FB and the like or remote code execution in high profile software have payouts that are a minimum of five figures.
[+] agustif|5 years ago|reply
Well, he seems specialized on a variety of attacks, but specialization is there nonetheless!
[+] pakwa|5 years ago|reply
Hey Shubham, nice report and write up.

Do you see much demand on the mobile security side, either as a specialist or focussing on mobile bounties?