Learning about the company and its systems
To be successful in finding vulnerabilities, it is important to learn about the company and its systems. Understanding how the systems work and what the common weaknesses are can help focus the search and increase effectiveness.
Since searching for vulnerabilities in a system is a complex task, it requires a thorough knowledge of companies and their systems. In this section, we will explore the steps necessary to understand the company we are analyzing and its systems before beginning the vulnerability search, which we will look at in more detail in later chapters.
Understanding the enterprise
We have learned how to decide on the bug bounty platform and understand the program. Now, before we start looking for vulnerabilities in a company, it is important to understand the company as a whole. This includes knowing about its organizational structure, its objectives, and its business processes. For example, it is not the same to audit...