Before touching anything: read the scope (which domains/apps/assets), the out-of-scope list, the rules (no DoS, no automated flooding, no social engineering), and the reward table. The policy is a contract — internalise it.
Bug Bounty Launchpad
walkthrough · How bug bounty really works
Reading a program policy.
That's the free preview. Enrol to continue the course.
Enrol