Bug Bounty: Wordlists — Please do them properly.

7 min readJun 19, 2023

You are only so good as your weakest link. And in bug bounty, most people’s weakest link, and most ignored is always their wordlists. Every stage of bug hunting is dependent in some way or another on wordlists, and I’m afraid Seclist’s raft-medium-words-lowercase.txt isn’t going to cut it.

Today, we’re going to cover 6 things:

  • You’re probably doing it…




CTI analyst | Head of Security @revoltchat | Bug Bounty Hunter. https://twitter.com/BrownBearSec. Alana Witten (she/her)