130 Days Bug Hunting Learning Challenge | WEEK 01
Getting Started, Law, Scope & Free Lab Setup
DAY 001
Topic: Bug Bounty Mindset, Authorization, Scope & Safe Practice
STUDY — 60 MINUTES
1. PortSwigger Getting Started
Read about the Academy workflow, safe and legal practice, and topic selection.
🔗 https://portswigger.net/web-security/getting-started
2. TryHackMe Web Application Security — Tasks 1–2
Learn the basics of web application security and common security risks.
🔗 https://tryhackme.com/room/introwebapplicationsecurity
PRACTICE — 90 MINUTES
Core — Complete Today
• PortSwigger Apprentice Mystery Lab — Observation Only
🔗 https://portswigger.net/web-security/all-labs
Extra Free Practice
• Explore the OWASP Vulnerable Web Applications Directory
🔗 https://vwad.owasp.org/
DAY 002
STUDY — 60 MINUTES
1. HTB Tier Introduction to Web Applications - Introduction & Web Application Layout
🔗 https://academy.hackthebox.com/course/preview/introduction-to-web-applications
2. TryHackMe Web Application Basics Tasks - 1 & 2
🔗 https://tryhackme.com/room/webapplicationbasics
PRACTICE — 90 MINUTES
Core — Complete Today
• HTB Tier Introduction to Web Applications - Introduction & Web Application Layout assessment questions for completed sections
🔗 https://academy.hackthebox.com/course/preview/introduction-to-web-applications
Extra Free Practice
• OWASP Juice Shop open the training app and map visible functions
🔗 https://owasp.org/www-project-juice-shop/
DAY 003
STUDY — 60 MINUTES
1. TryHackMe Web Application Basics URL and HTTP tasks
🔗 https://tryhackme.com/room/webapplicationbasics
2. HTB Tier Web Requests Introduction and HTTP Fundamentals
🔗 https://academy.hackthebox.com/course/preview/web-requests
PRACTICE — 90 MINUTES
Core — Complete Today
• TryHackMe Web Application Basics URL and HTTP tasks
🔗 https://tryhackme.com/room/webapplicationbasics
• HTB Tier Web Requests First Assessment
🔗 https://academy.hackthebox.com/course/preview/web-requests
DAY 004
HTTP request methods headers , ও status codes
STUDY — 60 MINUTES
1. TryHackMe HTTP in Detail full room
🔗 https://tryhackme.com/room/httpindetail
2. PortSwigger Getting started with Burp videos (Burp Related all videos)
🔗 https://portswigger.net/web-security/getting-started
PRACTICE — 90 MINUTES
Core — Complete Today
• THM HTTP in Detail complete room
🔗 https://tryhackme.com/room/httpindetail
• HTB Web Requests HTTP Requests and Responses assessments
🔗 https://academy.hackthebox.com/course/preview/web-requests
DAY 005
Training environment setup Burp Community browser
STUDY — 60 MINUTES
1. PortSwigger Getting started (Topic - proxy HTTP history Repeater workflow)
🔗 https://portswigger.net/web-security/getting-started
2. HTB Web Requests cURL section (GET POST headers auth examples)
🔗 https://academy.hackthebox.com/course/preview/web-requests
PRACTICE — 90 MINUTES
Core — Complete Today
• Intercept a request in a PortSwigger lab
🔗 https://portswigger.net/web-security/getting-started
• Send and modify the same request in Repeater
🔗 https://portswigger.net/web-security/getting-started
. Repeat one request with cURL in HTB assessment
🔗 https://academy.hackthebox.com/course/preview/web-requests
Solve Rule: (For Every Day)
25-minute self-attempt → Revisit theory → Use a hint → View the solution if necessary → Reset and solve again
NOTE + RESEARCH — 30 MINUTES (For Every Day)
• Write 5 things you learned today
• Write 1 important mistake or problem you faced
• Note one HTTP Request/Response or an important concept
• Create a short checklist or research summary about today’s topic
DAY COMPLETE WHEN
Study Completed + Core Practice Completed + Progress Saved + 30-Minute Notes Completed





Completed Successfully. Nice Work!!!