Hacker News new | ask | show | jobs
by rootsudo 2951 days ago
This is a great post. Wireshark, burp site, mitm tools are all that I use. You'd be surprised how far you can get with kali/fiddler with most apps.

OWASP also is a great baseline to start recon.

Buto to add on more, most of the time it's because of misapplication or something not following good practice and knowing this is only possible by being in the field for a while.

1 comments

Would those three tools be enough to get started/find some bug bounties?