Table of Contents

Philosophy

Differences from standard testing

Single-sourced:

Crowdsourced:

Tips / Notes:

Because competition is introduced; when working in a bug bounty it is essential to have templates set up for your “most found” classes of vulnerabilities. Obviously custom vulnerabilities will always be custom writeups, but having a template for ones that come up often is essential. Protip: always remember to change the URLS and domains in the templates. Nothing will get a bug invalidated faster than stating the wrong domain or URLs in a report.

When desigining these templates there are two really great resources to read: