
Learn to ethically hack on HackerOne, earn rewards for findings, and explore five starter bugs like password reset leakage and authentication cookie exposure with hands-on demos.
Discover why hackerone offers lucrative bug bounties—from 100 to 10,000 dollars per submission—by remotely hacking major brands, web and mobile apps, and government clients.
Develop a bug hunter mindset with a start strategy for HackerOne, focusing on medium and high impact bugs, quick responses, and first submissions to maximize rewards from the five bugs.
Examine how password reset links can leak via the refer header when a page loads external resources, risking password reset token exposure and potential account takeover, with a practical demo.
Demonstrates automatic leakage of a password reset link by loading an image from an external domain and exposing the reset token via the refer header, using browser dev tools.
Learn how session cookies and server-side logout handling determine true user lockout, why deleting a cookie on the client side is insufficient, and how a demo reveals this vulnerability.
Demonstrates testing session management by manipulating the authentication session ID cookie to reveal how server-side invalidation can fail, risking access to a logged-out account.
Explore insecure processing of credit card data, focusing on sensitive data cached in plain text. Learn hands-on with client-site code analysis and a demo to identify this web app bug.
Demonstrates insecure processing of credit card data in a web app, showing plaintext data exposure and missing autocomplete off, verified via browser inspector.
Explore how authentication cookies with session IDs can be disclosed over insecure channels and how to mitigate this risk by enabling the secure flag and enforcing https.
This demo uses Burp Suite to intercept an http request, revealing how the session id cookie can be disclosed over insecure http, even when https is enforced.
Identify how attackers perform user enumeration by comparing responses to existing and non-existing emails. Explore how forgot password functionality can reveal registered users, with a hands-on demo.
Explore user enumeration through login and forgot password flows, revealing how different responses expose registered versus non registered emails. Learn how attackers automate checks to build email lists.
Discover five proven bug types on HackerOne that pay up to ten thousand dollars per bug, including password reset abuse, cookie and credit card data exposure, and forgot-password enumeration.
This course will teach how to start hacking and making money at HackerOne – the most popular bug hunting platform. At HackerOne you can legally hack some of the biggest companies (Twitter, Uber, Yahoo, Coinbase, Slack, etc.), and you can get paid for your findings. You can earn for example $100, $1,000 or $10,000 per one bug. It’s just amazing. All you need are Internet connection and knowledge.
Yes, you need knowledge and this is exactly what I’m going to give you in this course. I’m one of the top hackers at HackerOne (among more than 100,000 registered hackers), and I really know how to make money out there. If you want to become a successful bug hunter, but you don't know how to start, then this course is just for you.
You will learn about 5 bugs that I recommend you to start with (these bugs have been successful for me for years). Here are these bugs:
1. Automatic Leakage of Password Reset Link
2. Getting Access to the Account of the Logged Out User
3. Insecure Processing of Credit Card Data
4. Disclosure of Authentication Cookie
5. User Enumeration
For every single bug there is a DEMO so that you can see how to find these bugs step-by-step in practice.
Are you ready to become a bug hunter? Let’s enroll to this course and start an exciting journey.
If you are interested in the next 5 bugs that really work, then I also recommend you to see the follow-up course "Keep Hacking at HackerOne".
-------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Course Rating: ★★★★★
"In just a few days I earned more money than I paid for this course! Highly recommended."
- Sam Paul, Student
Course Rating: ★★★★★
"The concepts are very clearly explained - I like the structure of the course (Like a brief overview followed by a demo). This course is a perfect start for a beginner like me. Thanks, Dawid! :)"
- Naveen, Grad student
Course Rating: ★★★★★
"Clear articulation of bugs and demo. Nice introduction to bug hunting."
- Cecil Su, Director
-------------------------------------------------------------------------------------------------------------------------------------------------------------------------