Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Introduction to Bug Bounty Programs
- Defining the concept of bug bounty hunting
- Overview of program types and leading platforms (HackerOne, Bugcrowd, Synack)
- Key legal and ethical considerations, including scope, disclosure policies, and NDAs
Vulnerability Classes and OWASP Top 10
- An in-depth look at OWASP Top 10 vulnerabilities
- Analyzing case studies from real-world bug bounty reports
- Utilizing specific tools and checklists to identify potential issues
Essential Tools
- Fundamentals of Burp Suite, covering interception, scanning, and the repeater
- Leveraging browser developer tools for analysis
- Applying reconnaissance tools such as Nmap, Sublist3r, and Dirb
Testing for Common Vulnerabilities
- Cross-Site Scripting (XSS)
- SQL Injection (SQLi)
- Cross-Site Request Forgery (CSRF)
Bug Hunting Methodologies
- Conducting reconnaissance and target enumeration
- Comparing manual versus automated testing strategies
- Adopting effective tips and workflows for bug bounty hunting
Reporting and Disclosure
- Crafting high-quality vulnerability reports
- Presenting proof of concept (PoC) and explaining associated risks
- Collaborating effectively with triagers and program managers
Bug Bounty Platforms and Professional Development
- Review of major platforms including HackerOne, Bugcrowd, Synack, and YesWeHack
- Exploring ethical hacking certifications such as CEH and OSCP
- Comprehending program scopes, rules of engagement, and industry best practices
Summary and Next Steps
Requirements
- Familiarity with fundamental web technologies, such as HTML and HTTP
- Practical experience with web browsers and standard developer tools
- A keen interest in cybersecurity and ethical hacking
Audience
- Aspiring ethical hackers
- Security enthusiasts and IT professionals
- Developers and QA testers with an interest in web application security
21 Hours
Custom Corporate Training
Training solutions designed exclusively for businesses.
- Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
- Flexible Schedule: Dates and times adapted to your team's agenda.
- Format: Online (live), In-company (at your offices), or Hybrid.
Price per private group, online live training, starting from 3900 € + VAT*
Contact us for an exact quote and to hear our latest promotions
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.