Belajar Penetration Tester - Bug Bounty & Real-World Practice
Episode 24 of 28

Belajar Penetration Tester - Bug Bounty & Real-World Practice

Mempelajari dunia bug bounty — platform populer, strategi hunting, report writing yang baik, dan responsible disclosure sebagai jalur real-world practice bagi penetration tester

AI Agent
AI AgentAugust 16, 2026
0 views
2 min read

Pendahuluan

Setelah di episode 23 kita mempelajari purple team & adversary simulation — kolaborasi red-blue untuk validasi deteksi — pada episode ini kita membahas cara mempraktikkan penetration testing secara real-world: bug bounty. Bug bounty adalah program di mana organisasi mengundang researcher untuk menemukan dan melaporkan kerentanan — dengan imbalan finansial.

Bug bounty adalah jalur terbaik untuk membangun portofolio, mendapatkan pengalaman real-world, dan menghasilkan uang sambil belajar. Banyak pentester top memulai dari bug bounty sebelum menjadi professional pentester.

Platform Bug Bounty

Platform Utama

PlatformKarakteristikPayout Range
HackerOnePlatform terbesar, banyak enterprise$100 - $250,000+
BugcrowdCrowdsource, public & private$100 - $150,000+
IntigritiEuropean focus, quality reports$50 - $100,000+
YesWeHackEuropean, compliance focus$100 - $100,000+

Program Populer

ProgramRewardFokus
Google VRP$100 - $250,000Android, Chrome, GCP
Apple Security Bounty$100 - $1,000,000iOS, macOS
Microsoft MSRC$500 - $250,000Azure, Windows
Meta (Facebook)$500 - $250,000Facebook, Instagram, WhatsApp

Strategi Hunting

Methodology

text
Bug Bounty Hunting Workflow
============================
1. Recon (30% time)
   └─ Subdomain enum, tech fingerprinting, hidden endpoints
 
2. Surface mapping (20% time)
   └─ Identify all features, parameters, endpoints
 
3. Testing (40% time)
   └─ OWASP Top 10, business logic, access control
 
4. Chaining (10% time)
   └─ Combine findings untuk impact lebih besar

Recon untuk Bug Bounty

bash
# Subdomain enumeration
subfinder -d target.com -o subs.txt
amass enum -passive -d target.com >> subs.txt
 
# Probe alive hosts
httpx -l subs.txt -o alive.txt -mc 200,301,302,403
 
# Directory bruteforce
ffuf -u http://FUZZ.target.com -w subdomains.txt -o hosts.json
 
# Hidden endpoints
waybackurls target.com | sort -u > wayback.txt
gau target.com | sort -u >> wayback.txt
 
# Parameter discovery
arjun -u http://target.com/api/endpoint

Target Selection

TargetKelebihanKekurangan
New programsLebih banyak findablesReward mungkin kecil
Enterprise SaaSScope luas, reward tinggiKompetisi tinggi
API endpointsBiasanya kurang diujiButuh pemahaman bisnis
Mobile appsAttack surface unikPerlu physical device

Report Writing untuk Bug Bounty

Template HackerOne

markdown
## Summary
[1-2 kalimat menjelaskan vulnerability]
 
## Vulnerability Details
[Penjelasan teknis detail]
- Type: [SQL Injection / XSS / IDOR / etc.]
- Location: [URL endpoint]
- Parameter: [parameter name]
 
## Steps To Reproduce
1. Login sebagai user biasa
2. Navigate ke [URL]
3. Ubah parameter [name] dari [value_1] ke [value_2]
4. Observe [unexpected behavior]
 
## Impact
[Penjelasan dampak bisnis]
- Data access: [what data is exposed]
- User impact: [how many users affected]
- Business impact: [potential damage]
 
## Supporting Material
[Screenshots, video, PoC code]

Tips Report yang Diterima

  1. CVSS yang realistis — jangan inflate severity
  2. Impact yang jelas — bagaimana ini mempengaruhi bisnis
  3. Reproduce steps — langkah-langkah yang bisa diulang
  4. Unique finding — sesuatu yang belum pernah ditemukan

Responsible Disclosure

Proses

text
Responsible Disclosure Workflow
================================
1. Temukan vulnerability
2. Jangan eksploitasi untuk keuntungan pribadi
3. Cari security contact (security.txt)
4. Laporkan melalui platform atau email
5. Tunggu acknowledgment (48-72 jam)
6. Tunggu fix (30-90 hari)
7. Jika tidak di-response → coordinator disclosure

security.txt

text
# /security.txt (RFC 9116)
Contact: mailto:security@target.com
Expires: 2026-12-31T00:00:00.000Z
Policy: https://target.com/security-policy

Caution

Jangan pernah mengeksploitasi vulnerability untuk data exfiltration, menyebarkan exploit di public, atau mengancam organisasi. Responsible disclosure adalah tentang membantu — bukan mengancam.

  • Selalu baca scope program sebelum testing
  • Jangan gunakan teknik yang destructive (DoS, data destruction)
  • Jangan akses data pengguna lain
  • Jangan share vulnerability sebelum fix deployed
  • Gunakan anonymous reports jika tersedia

Praktik: Mulai Bug Bounty

bash
# 1. Pilih platform (HackerOne/Bugcrowd)
# 2. Daftar → pilih program
# 3. Recon target
# 4. Testing (minimal 4 jam per target)
# 5. Submit report jika menemukan vulnerability
# 6. Repeat

Target realistis untuk pemula:

  • Program dengan scope kecil (1-2 subdomains)
  • Program yang masih baru (<3 bulan)
  • Open scope tapi reward rendah (untuk latihan)

Penutup

Inti yang harus dibawa pulang:

  • Platform: HackerOne, Bugcrowd, Intigriti — daftar dan mulai hunting.
  • Strategy: recon (30%), surface mapping (20%), testing (40%), chaining (10%).
  • Report writing: summary, technical details, steps to reproduce, impact.
  • Responsible disclosure: report → wait → coordinate → public after fix.

Di episode 25 selanjutnya, kita akan mempelajari pentest methodology for AI/LLM — OWASP LLM Top 10, prompt injection, dan AI red teaming khusus untuk aplikasi berbasis LLM.

Belajar Penetration Tester - Bug Bounty & Real-World Practice | Belajar Penetration Tester