Lazo Lab Sign up

Web Security / Building secure apps

Lesson 25 of 27

Bug bounties and responsible disclosure

Bug bounty programmes pay researchers to report vulnerabilities through proper channels. Only test within a programme's published scope and rules.

Key points

  • Read the scope and rules first
  • Report privately, don't publish
  • HackerOne and Bugcrowd host programmes
Watch a video on thisOpens YouTube search results for “Bug bounties and responsible disclosure” in a new tab

Quiz · +10 XP

What must you do before testing a bug bounty target?

Log in to save progress and earn XP.