Course Overview

The course Keep Hacking and Making Money at HackerOne is designed for ethical hackers and cybersecurity enthusiasts who want to take their skills to the next level by participating in bug bounty programs, specifically on the HackerOne platform. This course emphasizes the real-world application of hacking techniques, focusing on vulnerabilities that can be exploited in web applications. Understanding these vulnerabilities not only helps in securing systems but also presents an opportunity to earn rewards by finding bugs and reporting them.

This course begins with a detailed explanation of how to impersonate a user via insecure logins, followed by practical demonstrations. It then covers other critical security issues, such as the risks associated with sensitive information in metadata and the disclosure of credentials, which can be exploited by attackers. The course also addresses the dangers of insecure password changes, providing a hands-on demonstration of how attackers can exploit weak password management practices. Additionally, the course explores dictionary attacks, demonstrating how attackers can break weak passwords by systematically guessing potential combinations.

By the end of this course, you'll gain an in-depth understanding of common vulnerabilities, learn practical exploitation techniques, and know how to secure systems effectively.

What You Will Learn

  • Explore the next 5 bugs that really work
  • Discover how to find these bugs step by step in practice (DEMOS)
  • Get paid for your findings
  • Become a successful bug hunter
  • Learn from one of the top hackers at HackerOne

Program Curriculum

  • How to Impersonate a User via Insecure Log In – Overview
  • How to Impersonate a User via Insecure Log In – Demo
  • $7 Million Cybersecurity Scholarship by EC-Council
  • Chapter 1 Quiz

  • Sensitive Information in Metadata – Overview
  • Sensitive Information in Metadata – Demo
  • Chapter 2 Quiz

  • Disclosure of Credentials – Overview
  • Disclosure of Credentials – Demo
  • Chapter 3 Quiz

  • Insecure Password Change – Overview
  • Insecure Password Change – Demo
  • Chapter 4 Quiz

  • Dictionary Attack – Overview
  • Dictionary Attack – Demo
  • Chapter 5 Quiz

Summary

Load more modules

Instructor

Dawid Czagan

Dawid Czagan (@dawidczagan) is an internationally recognized security researcher and trainer. He is listed among the top hackers at HackerOne. Dawid Czagan has found security vulnerabilities in Google, Yahoo, Mozilla, Microsoft, Twitter and other companies. Due to the severity of many bugs, he received numerous awards for his findings. Dawid Czagan shares his security bug hunting experience in his hands-on trainings “Hacking Web Applications – Case Studies of Award-Winning Bugs in Google, Yahoo, Mozilla and More” and “Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation”. He delivered security training courses at key industry conferences such as Hack In The Box (Amsterdam), CanSecWest (Vancouver), 44CON (London), Hack In Paris (Paris), DeepSec (Vienna), NorthSec (Montreal), HITB GSEC (Singapore), BruCON (Ghent) and for many corporate clients. His students include security specialists from Oracle, Adobe, ESET, ING, Red Hat, Trend Micro, Philips and the government sector (references are attached to Dawid Czagan's LinkedIn profile (https://www.linkedin.com/in/dawid-czagan-85ba3666/). They can also be found here: https://silesiasecuritylab.com/services/training/#opinions). Dawid Czagan is the founder and CEO of Silesia Security Lab – a company which delivers specialized security testing and training services. He is also an author of online security courses. To find out about the latest in Dawid Czagan’s work, you are invited to subscribe to his newsletter (https://silesiasecuritylab.com/newsletter) and follow him on Twitter (@dawidczagan) and LinkedIn (https://www.linkedin.com/in/dawid-czagan-85ba3666/).

Join over 1 Million professionals from the most renowned Companies in the world!

certificate

Choose the Pro Plan That Fits Your Learning Journey

Invest in your future with flexible Pro subscription plans. Whether you're starting your cybersecurity journey or expanding your expertise, choose the membership duration that works for you and gain access to our complete learning platform.

Monthly Plans
Annual Plans
Save 20% with our annual plans!

Pro

Ideal for continuous learning, offering extensive resources with 900+ courses and diverse Learning Paths to enhance your skills.

$ 599.00
Billed annually or $69.00 billed monthly

What is included

  • Access to 900+ Premium Short Courses
  • 70+ Structured Learning Paths
  • Validation of Completion with All Courses and Learning Paths
  • New Courses Added Every Month
Early Access Offer

Pro +

Experience immersive learning with Practice Labs and CTF Challenges for comprehensive skill-building.

$ 699.00
Billed annually or $79.00 billed monthly

Everything in Pro and

  • 500+ Practice Labs with Guided Instructions
  • 400+ CTF Challenges with Detailed Walkthroughs
  • New Practice Labs and Challenges Added Every Month

Related Courses

1 of 50