Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Introduction to Bug Bounty Programs
- Defining bug bounty hunting.
- Overview of program types and major platforms (HackerOne, Bugcrowd, Synack).
- Navigating legal and ethical boundaries (scope, disclosure, NDAs).
Vulnerability Categories and the OWASP Top 10
- Explaining the OWASP Top 10 vulnerabilities.
- Reviewing case studies from actual bug bounty reports.
- Utilising tools and checklists to detect issues.
Essential Tools
- Fundamentals of Burp Suite (interception, scanning, repeater).
- Utilising browser developer tools.
- Reconnaissance utilities: Nmap, Sublist3r, Dirb, and others.
Testing for Common Vulnerabilities
- Cross-Site Scripting (XSS).
- SQL Injection (SQLi).
- Cross-Site Request Forgery (CSRF).
Bug Hunting Methodologies
- Conducting reconnaissance and target enumeration.
- Comparing manual versus automated testing strategies.
- Applying best practices and workflows for bug hunting.
Reporting and Disclosure
- Crafting high-quality vulnerability reports.
- Including proof of concept (PoC) and risk assessments.
- Communicating effectively with triagers and program managers.
Bug Bounty Platforms and Career Development
- Surveying key platforms (HackerOne, Bugcrowd, Synack, YesWeHack).
- Pursuing ethical hacking certifications (CEH, OSCP, etc.).
- Understanding program scopes, rules of engagement, and best practices.
Conclusion and Future Pathways
Requirements
- Familiarity with fundamental web technologies (e.g., HTML, HTTP).
- Proficiency in using web browsers and standard developer tools.
- A keen interest in cybersecurity and ethical hacking practices.
Target Audience
- Aspiring ethical hackers.
- Security enthusiasts and IT specialists.
- Developers and QA testers with an interest in web application security.
21 Hours
Custom Corporate Training
Training solutions designed exclusively for businesses.
- Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
- Flexible Schedule: Dates and times adapted to your team's agenda.
- Format: Online (live), In-company (at your offices), or Hybrid.
Price per private group, online live training, starting from 4800 € + VAT*
Contact us for an exact quote and to hear our latest promotions
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.