{"product_id":"bug-bounty-bootcamp-isbn-9781718501546","title":"Bug Bounty Bootcamp","description":"\u003cb\u003e\u003ci\u003eBug Bounty Bootcamp \u003c\/i\u003eteaches you how to hack web applications. You will learn how to perform reconnaissance on a target, how to identify vulnerabilities, and how to exploit them. You’ll also learn how to navigate bug bounty programs set up by companies to reward security professionals for finding bugs in their web applications.\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003eBug bounty programs are company-sponsored programs that invite researchers to search for vulnerabilities on their applications and reward them for their findings. This book is designed to help beginners with little to no security experience learn web hacking, find bugs, and stay competitive in this booming and lucrative industry. \u003cbr\u003e \u003cbr\u003eYou’ll start by learning how to choose a program, write quality bug reports, and maintain professional relationships in the industry. Then you’ll learn how to set up a web hacking lab and use a proxy to capture traffic. In Part 3 of the book, you’ll explore the mechanisms of common web vulnerabilities, like XSS, SQL injection, and template injection, and receive detailed advice on how to find them and bypass common protections. You’ll also learn how to chain multiple bugs to maximize the impact of your vulnerabilities.\u003cbr\u003e \u003cbr\u003eFinally, the book touches on advanced techniques rarely covered in introductory hacking books but that are crucial to understand to hack web applications. You’ll learn how to hack mobile apps, review an application’s source code for security issues, find vulnerabilities in APIs, and automate your hacking process. By the end of the book, you’ll have learned the tools and techniques necessary to be a competent web hacker and find bugs on a bug bounty program.\u003cb\u003eIntroduction\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003e\u003cb\u003eIntroduction\u003cbr\u003ePart I: The Industry\u003c\/b\u003e\u003cbr\u003e\u003cb\u003eChapter 1: \u003c\/b\u003ePicking a Bug Bounty Program\u003cbr\u003e\u003cb\u003eChapter 2: \u003c\/b\u003eSustaining Your Success\u003cbr\u003e\u003cbr\u003e\u003cb\u003ePart II: Getting Started\u003c\/b\u003e\u003cbr\u003e\u003cb\u003eChapter 3: \u003c\/b\u003eHow the Internet Works\u003cbr\u003e\u003cb\u003eChapter 4: \u003c\/b\u003eEnvironmental Setup and Traffic Interception\u003cbr\u003e\u003cb\u003eChapter 5: \u003c\/b\u003eWeb Hacking Reconnaissance\u003cbr\u003e\u003cbr\u003e\u003cb\u003ePart III: Web Vulnerabilities\u003c\/b\u003e\u003cbr\u003e\u003cb\u003eChapter 6: \u003c\/b\u003eCross-Site Scripting\u003cbr\u003e\u003cb\u003eChapter 7: \u003c\/b\u003eOpen Redirects\u003cbr\u003e\u003cb\u003eChapter 8: \u003c\/b\u003eClickjacking\u003cbr\u003e\u003cb\u003eChapter 9: \u003c\/b\u003eCross-Site Request Forgery\u003cbr\u003e\u003cb\u003eChapter 10:\u003c\/b\u003e Insecure Direct Object Reference\u003cbr\u003e\u003cb\u003eChapter 11: \u003c\/b\u003eSQL Injection\u003cbr\u003e\u003cb\u003eChapter 12: \u003c\/b\u003eRace Conditions\u003cbr\u003e\u003cb\u003eChapter 13: \u003c\/b\u003eServer-Side Request Forgery\u003cbr\u003e\u003cb\u003eChapter 14:\u003c\/b\u003e Insecure Deserialization\u003cbr\u003e\u003cb\u003eChapter 15: \u003c\/b\u003eXML External Entity Vulnerabilities\u003cbr\u003e\u003cb\u003eChapter 16: \u003c\/b\u003eTemplate Injection\u003cbr\u003e\u003cb\u003eChapter 17: \u003c\/b\u003eApplication Logic Errors and Broken Access Control\u003cbr\u003e\u003cb\u003eChapter 18: \u003c\/b\u003eRemote Code Execution\u003cbr\u003e\u003cb\u003eChapter 19: \u003c\/b\u003eSame Origin Policy Issues\u003cbr\u003e\u003cb\u003eChapter 20: \u003c\/b\u003eSingle Sign-on Issues\u003cbr\u003e\u003cb\u003eChapter 21: \u003c\/b\u003eInformation Disclosure\u003cbr\u003e\u003cbr\u003e\u003cb\u003ePart IV: Expert Techniques\u003c\/b\u003e\u003cbr\u003e\u003cb\u003eChapter 22:\u003c\/b\u003e Conducting Code Reviews\u003cbr\u003e\u003cb\u003eChapter 23: \u003c\/b\u003eHacking Android Apps\u003cbr\u003e\u003cb\u003eChapter 24: \u003c\/b\u003eAPI Hacking\u003cbr\u003e\u003cb\u003eChapter 25: \u003c\/b\u003eAutomatic Vulnerability Discovery Using Fuzzers\u003cbr\u003e\u003cbr\u003e\u003cb\u003eIndex\u003c\/b\u003e\"A really good book for getting started in Bug Bounty, out at a time when something like this was really needed. You can take as many ethical hacking courses as you want, but when it comes to bug bounty, there is so much information and tools it can be imitating to start . . . This really should be the first book read by ANYONE looking to start in the bug bounty game.\"\u003cbr\u003e\u003cb\u003e—Alex\/Muldwych, The Security Noob\u003cbr\u003e\u003c\/b\u003e\u003cbr\u003e\"\u003ci\u003eBug Bounty Bootcamp\u003c\/i\u003e should be on every hacker's shelf. Vickie Li answers an important question: 'So you found your first flaw, what's next?' By explaining how to write a bug report and interact with clients, she presents a wonderful guide on starting your security career.\"\u003cbr\u003e\u003cb\u003e—Andrew Orr, Associate Editor, The Mac Observer\u003cbr\u003e\u003c\/b\u003e\u003cbr\u003e\"I have enjoyed \u003ci\u003eBug Bounty Bootcamp\u003c\/i\u003e over the past few weeks and this is great for bug bounty beginners like myself. Anyone who is interested in learning more about different web vulnerabilities, bug bounty platforms, how the internet works, and how to make money making the web safer this is the book for you. Thanks to Vickie for writing such a great book!\"\u003cbr\u003e\u003cb\u003e—The Digital Empress, YouTuber and Blogger\u003cbr\u003e\u003c\/b\u003e\u003cbr\u003e\"\u003ci\u003eBug Bounty Bootcamp\u003c\/i\u003e by Vickie Li is a thorough and masterful explanation for how to find bugs and responsibly report them. It is written so clearly, and provides such useful step-by-step instructions that as I was reading it, I was tempted to start hunting for bugs myself.\"\u003cbr\u003e\u003cb\u003e—Cynthia Brumfield, President, DCT-Associates\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003e\"\u003ci\u003eBug Bounty Bootcamp\u003c\/i\u003e is a great resource for those who want to participate in Bug Bounties because it not only teaches you about the technical aspects, but helps you develop a methodology and sustain your testing. Some technology knowledge is assumed, but it does a solid job of describing the relevant vulnerability types from first principles, so it can be a strong resource for those new to the security space. The writing style is clear and to the point.\"\u003cbr\u003e\u003cb\u003e—David Tomaschik, Security Engineer at Google, Blogger at System Overlord\u003cbr\u003e\u003c\/b\u003e\u003cbr\u003e\"I highly suggest reading \u003ci\u003eBug Bounty Bootcamp\u003c\/i\u003e.\"\u003cbr\u003e\u003cb\u003e—@HolyBugx\u003cbr\u003e\u003c\/b\u003e\u003cbr\u003e\"Pure GEM. Learned a lot of things from her book.\"\u003cbr\u003e\u003cb\u003e—Aakash Choudhary, @LearnerHunter\u003cbr\u003e\u003c\/b\u003e\u003cbr\u003e\"Loved the book. Well written, clear, concise, and easy to follow. Everyone from the beginner bug hunter to the seasoned pro will find a nugget, some nuggets or just pure nuggets of amazing information, tips and advice.\"\u003cbr\u003e\u003cb\u003e—Douglas Campbell, Advanced Reviewer\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003e\"The only book you need to get started in bug bounty is @vickieli7's book coming out from @nostarch, \u003ci\u003eBug Bounty Bootcamp\u003c\/i\u003e. It's a detailed how-to with lots of technical how-to steps.\"\u003cbr\u003e\u003cb\u003e—Metacurity, Top Infosec News Destination, @Metacurity\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003e\"The new go-to resource for a beginner in web app hacking . . . I recommend this book before anything else for a beginner trying to learn web security. Vickie provides an excellent delivery of breaking down complex concepts that makes it easy to comprehend. Also, the step by step guidance of exploiting a vulnerability is fantastic to refer back to . . . If you are a complete beginner and feel confused or lost in all of the information out there then stop, grab this book, read through it once, then use it as your guide.\"\u003cbr\u003e\u003cb\u003e—AntiRuse, @AntiRuse, Blogger\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003e\"Definitely recommend it!\"\u003cbr\u003e\u003cb\u003e—Michael, @DoAbarrel_Troll\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003e\"\u003ci\u003eBug Bounty Bootcamp\u003c\/i\u003e is *the* book for everyone in Information Technology, not just those interested in bug bounties . . . This easy-to-read guide breaks down complicated topics into a simple progression through technical concepts. From a foundational overview of the industry and how to get started, the reader progresses from Cross Site Scripting all the way through to API hacking and use of Fuzzers. Vickie Li has done a tremendous service to information security by sharing her expert understanding of bug hunting in a highly accessible way. Recommended reading for all IT professionals, new or veteran.\"\u003cbr\u003e\u003cb\u003e—Jess Vachon, Advanced Reviewer\u003cbr\u003e\u003c\/b\u003e\u003cbr\u003e\"Vicki Li’s book took me from knowing nothing about bug bounties, to finding my first bug. Li goes over the process of bug bounties, writing reports, and how to make relationships with companies. Li also has expert techniques that will help your automate your hacking experience and even hacking android apps.\"\u003cbr\u003e\u003cb\u003e—Anthony Ware, Advanced Reviewer\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003e\"For anyone interested in bug detection of web services, this book is for you. It takes an approach that is enjoyable for all levels. It covers the essentials for understanding web servers and why the assortment of vulnerabilities exists with steps in what to look for in approaching those security risks. It’s not going to make you an expert overnight, but it will set you on the path towards success, bypassing the common mistakes where others have fallen.\"\u003cbr\u003e\u003cb\u003e—Riley A., Advanced Reviewer\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003e\"Step-by-step instructions to achieve your first bug bounty and a great book to reference as a security professional. This book will give insight to how bug bounty programs operate and provide resources to learn programming, security tools, and breakdown OWASP top 10 vulnerabilities.\"\u003cbr\u003e\u003cb\u003e—Jessica W., Advanced Reviewer\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003e\"Since reading \u003ci\u003eThe Web Application Hacker's Handbook\u003c\/i\u003e a few years ago, I haven't seen that much web security knowledge organized in one place as in \u003ci\u003eBug Bounty Bootcamp\u003c\/i\u003e. Vickie did a fantastic job of covering many different vulnerability classes that are important for offensively testing web applications. Explanations are made so that beginners would understand them but I was also able to find some inspirations each time I looked at the book when testing a specific vulnerability class. I highly recommend \u003ci\u003eBug Bounty Bootcamp\u003c\/i\u003e for everyone who wants to learn about web security.\"\u003cbr\u003e\u003cb\u003e—Bug Bounty Reports Explained, YouTuber and Advanced Reviewer\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003e\"A great companion to @yaworsk's earlier book, \u003ci\u003eReal-World Bounty Hunting\u003c\/i\u003e (also by\u003cbr\u003e@nostarch), and deserves a place on your bookshelf.\"\u003cbr\u003e\u003cb\u003e—@jub0bs\u003cbr\u003e\u003cbr\u003e\u003c\/b\u003e\"An informative and well-written guide that should be of interest to anyone considering a career in API hacking through bug bounty hunting.\" \u003cbr\u003e\u003cb\u003e—Dana Epp, Security Boulevard\u003c\/b\u003e\u003cb\u003eVickie Li\u003c\/b\u003e is a developer and security researcher experienced in finding and exploiting vulnerabilities in web applications. She has reported vulnerabilities to firms such as Facebook, Yelp and Starbucks and contributes to a number of online training programs and technical blogs. \u003cbr\u003e\u003cbr\u003e\u003cbr\u003e ","brand":"No Starch Press","offers":[{"title":"Default Title","offer_id":46302295326949,"sku":"NP9781718501546","price":49.99,"currency_code":"USD","in_stock":false}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/1842\/7735\/files\/9781718501546.jpg?v=1767723158","url":"https:\/\/k12savings.com\/products\/bug-bounty-bootcamp-isbn-9781718501546","provider":"K12savings","version":"1.0","type":"link"}