← Intel
Oct 6, 2026 · HackerOnStreet

Bug Bounty & Penetration Testing Best Giude Ever

interest in Penetration Testing and Bug bounty in 2023–infinity and that Bug Bounty & Penetration Testing Best Giude Ever You are taking an interest in Penetration Testing and Bug bounty in 2023–infinity and that is good now it’s

bug bountybug bounty penetrationbugbountypenetrationtestingbestgiudeeverfind
Bug Bounty & Penetration Testing Best Giude Ever

interest in Penetration Testing and Bug bounty in 2023–infinity and that


Bug Bounty & Penetration Testing Best Giude Ever

You are taking an interest in Penetration Testing and Bug bounty in 2023–infinity and that is good now it’s time to move on to the next level. More information means more knowledge and knowledge mean more Expreance and Rewards.

My Name is Imran and Im in red teaming. Red teaming helps me a lot to understand many things. Generally there are few limitations in the boundary but in red teaming things are very different. Trying to understand the things that cannot be recovered or the data is also checked where the rest of the people are afraid from here.The game of red teaming starts from here.

Remember that money in cyber security comes from where no one is looking.
1*vmuhOyLgF AR4V1vi03eUA

Penetration testing is like a type of masturbation, you have to find a new method every time. Just keep this thing in your mind that every time you have to find a new way and you have to find a solution to this thing, how can it be done.

Always keep an eye on the things that no one can suspect, for example, you are working on Apple’s domain. Also keep in mind that many people are working on it, you have to find a solution where the number of people is less and the attention of the staff is less. are.

For Example myapple.com is your Target and some taget is done by 1Milions Hunters .

Why don’t we look for a domain where the rush is less and nobody has noticed. my.apple.api.dev.apple.com is example .

Scanning IP addresses and DNS in bulk:

Bulk IP address scanning and DNS scanning can be very useful. If you are out looking for bugs and you are going to get there before the rest and achieve your goal, then this will be a very unique way.

Namp works on the same thing as mapping to a net. Many people use Scan which is very useful and efficient for scanning UDCP TCP and FTP ports on the entire Internet. There are many similar tools that can be modified. You can use it for your personal work or take the help of artificial intelligence.

The Developer Toolkit inside any browser:

There are many things, it is not necessary that you can find many things with the help of a special tool. Here’s what we know: The Developer Toolkit inside any browser can tell you about a lot of things. Sensitive information can be leaked in any way but it is your job to find it..

1*6pZb GRQkYC4TAp1F4YAcwThe throw of the console is to see that there is no such sensitive information leaking anywhere.
1*yyv1wF7O9jZ42qZZHNoqDA

In the network area, we can see where the requests are coming from and where they are going to, what is the content of this request. And do we have any information that we can use, as you can see below, there is a pipeline of V1, an API, which can be an essential thing for anyone.

We use Burb Suite because we want to see what’s going on, but while we’re learning about the many tools available on the Internet, the biggest tool is its own web browser. Which can inform you about many things.

Investigating data on the Internet that previously existed related to a vulnerability that is similar to it.

Whenever we are going to search about something, it is very important for us to know about this thing, how much percentage of truth is included in the first information available on the Internet. If that fact is such that you can see what happened in the end and how to collect and use this data so that you can reach your goal.

For this you should know about all the websites where the reports are published.

For example, HackerOne , Bugcrowd ,proofpoint, exploitDB and all those open source platforms that collect and publish such reports.

This video will help you a lot in understanding how you can find things and collect data.

Click Here

This video will give a brief introduction, in which you will know how things are going and from whom we will collect data. This is part one. In the next video we will see how to process this data and how we will try to bypass things by using different scripts.

Click Part 2 :

In this video, you will know how we can detect different things by using network mapping tool and using ping request method so that it is easy for us

Tools we are usig for this :

  • Nmap
  • DNSmaper
  • OSZAP
  • Custom Sctipt in Python and Other Tools

Let’s look at an example and compare it to what we’re looking for in understanding this and all previous articles.