Skip to content

Bergee's Stories on Bug Hunting

hacking, cyber security and programming

Menu
  • Blog
  • Books
  • About Me
  • Side projects
Menu

Books


Bug Bounty Bootcamp

Bug Bounty Bootcamp by Vickie Lee

The ultimate starting point for anyone looking to turn hacking into a paycheck. Vickie Li masterfully guides you from basic web security to advanced reporting techniques.

 


Real-World Bug Hunting

Real-World Bug Hunting by Peter Yaworski

A true modern classic. Peter Yaworski deconstructs real-world bug reports from giants like Twitter and Facebook. Learn how to chain vulnerabilities into devastating exploits.

 


Hacking APIs

Hacking APIs by Corey Ball

Corey Ball teaches you how to map, test, and exploit the hidden interfaces that power modern apps. Essential for finding high-paying bugs in enterprise environments.

 


Black Hat GraphQL

Black Hat GraphQL by Nick Aleks, Dolev Farhi and Opheliar Chan

Master the security challenges of GraphQL. This book explores advanced attack vectors specific to modern data architectures. A high-demand niche for any researcher.

  • Two crits, one zip
  • Why do you need the VPS for bug bounty
  • WAF bypass and credential theft with XSS and Google Analytics
  • How two dollars and one zip file let me read the server files
  • Subdomain takeover – easy $150 for five minutes of work
  • How I hacked XXXX for fun and !profit
  • Accessing admin panel with fuzzing, digging and guessing
  • From AngularJS CSTI to credentials theft
  • The story of exposed service, SSRF, CSP bypass and credentials stealing via XSS
  • “Hacking” the hotel room TV
  • Broken links hijacking and CDN takeover
  • How I found multiple critical bugs in Red Bull
  • Chaining multiple vulnerabilities for credential stealing
  • Blind account takeover
  • Turning cookie based XSS into account takeover
  • Blind os command injection
  • Five-minute hunting for hidden XSS
  • URL filter bypass, RFI and XSS
  • The forgotten API and XSS filter bypass
  • XSS via Angular Template Injection
  • Breaking things legally for fun and profit

Hackers' playground


https://www.tryhackme.com
https://www.pentesterlab.com
https://www.hackthebox.com
https://portswigger.net/web-security/all-labs
© 2026 Bergee's Stories on Bug Hunting | Powered by Minimalist Blog WordPress Theme