Podcast · YouTube

🔴 WHAT is it like to WORK as a BUG BOUNTY Hunter? 💸💰💸 MAKE MONEY HACKING 💪💪ETHICAL HACKING

In this section we get to know the people of the cybersecurity world better, and kicking it off is José Domingo, better known as link, number 46 in HackerOne’s ranking. In other words, someone who makes a living finding flaws in companies across half the world.

José explains what bug bounty is with no frills: patience, a solid technical background and, above all, your own methodology. Here he throws out a warning I share: don’t just copy the tips you see on Twitter as if they were gospel, because a lot of them are smoke to make you waste your time, you have to understand why things happen and not just repeat them. He runs through juicy anecdotes, from credentials forgotten in a README file nobody looks at to a reverse proxy bypass that earned him a five-figure bounty.

We talk about whether the traditional pentest is dead (he thinks the future is bug bounty, though the pentest still has its place), about why finding something in a public program is playing on hard mode and about an idea that keeps coming up on the channel: if you get in just for the money, you stop halfway. This is about vocation.