BBLABS v2BBLABSv2
>Home>Labs
>New labs

Latest 3 labs

Loading…

View all labs →
>Creators>Ranking
>Learn

Learn bug bounty

AcademyGuides, cheatsheets and glossaryVulnerabilitiesXSS, SQLi, IDOR, SSRF and moreHunter RoadmapYour step-by-step bug bounty pathBlogBug bounty guides and news
>Business>Pricing
ES
Log inLog in
>Home>Labs>New labs>Creators>Ranking>Learn>Business>Pricing
ES
Sign inCreate account

Contact

Practice, learn and hack

Bug bounty practice platform with labs based on real reports. Learn ethical hacking in safe environments.

contact→

Follow us

YouTube
@0xGorka
X
@gorkaelbochi
LinkedIn
gorka-el-bochi-morillo
Instagram
@_.gorkaaa.b
Email
team@bblabs.es

Access every lab from €7.99/mo

New labs every week. Cancel anytime.

Create account

BBLabs is the bug bounty labs platform where you learn bug bounty with real vulnerabilities extracted from paid reports on HackerOne, Bugcrowd and Intigriti. Here you practice web hacking —XSS, SQLi, IDOR, SSRF, CSRF and more— in downloadable environments, capture the flag, read the writeup and apply the technique on active bug bounty programs.

BBLabs is the alternative to HackTheBox, TryHackMe and PentesterLab for those who want to practice bug bounty with real reports instead of artificial CTFs. From €7.99/mo, no commitment.

→ Learn bug bounty from scratch→ How to do bug bounty step by step→ Real bug bounty reports→ BBLabs for companies and academiesLabsAcademyVulnerabilitiesToolsHunter rankingXSS labsIDOR labsSSRF labsCSRF labsHackTheBox alternativeHack4u alternativeTryHackMe alternativePortSwigger alternativePentesterLab alternativeBug Bounty Labs comparisonHackerOne to practiceOffSec / OSCP alternativeINE / eWPT alternativeHTB Academy alternativeDVWA alternativeJuice Shop alternativeVulnHub alternativePentesterAcademy alternativeRoot-Me alternativeHackTheBox vs TryHackMeBest bug bounty platforms 2026BlogSpoilersWhat is bug bounty?How much do you earn in bug bounty?OWASP Top 10 explainedBest sites to practice web hackingHow to become an ethical hacker from scratchBurp Suite tutorial (Spanish)OSCP guide and prepGoogle Dorks for bug bountyHow much an ethical hacker earns in SpainBug bounty tools 2026Best cybersecurity certifications 2026Burp Suite tutorialsqlmap tutorialffuf web fuzzingnuclei tutorialHTTP Request SmugglingWAF bypassPrompt injection (LLM)Google Dorks
Made withand code
TermsPrivacyComparisonES

© 2026 BBLABS v2 — All rights reserved

Knowledge Lab

Blog & Resources

Technical guides, methodologies and resources to master bug bounty. Learn ethical hacking techniques with hands-on content.

hunters training
709

hunters training

labs from real reports
55

labs from real reports

completions
1,204

completions

in bounties practiced
$213,970

in bounties practiced

46 flags captured this week·Real reports from HackerOne · Bugcrowd · Intigriti·No commitment·Free Academy
BBLabs · bug bounty training

Stop reading about bugs and start hunting them

Create your free account and practice on labs based on real reports that paid out thousands of euros. The Academy is free forever.

Create free accountSee the labs

No card · free Academy · cancel anytime

Read Beginner's guide to IDOR
techniquesfeatured
Mar 10, 202612 min read

Beginner's guide to IDOR

Learn to identify and exploit IDOR (Insecure Direct Object Reference) vulnerabilities in web applications. From the basics to writing effective reports.

B
BBLabsSecurity Researcher
read article
#idor#api#bug-bounty
Read How to set up your bug bounty environment
toolsfeatured
Feb 22, 202615 min read

How to set up your bug bounty environment

Everything you need to build a professional bug bounty setup: from choosing your operating system to automating reconnaissance.

B
BBLabsSecurity Researcher
read article
#tools#setup#burp-suite
Read First steps on HackerOne
methodology
Feb 5, 202610 min read

First steps on HackerOne

A complete guide to getting started on HackerOne: from creating your account to submitting your first vulnerability report. Tips for beginners.

B
BBLabsSecurity Researcher
read article
#hackerone#platforms#beginners
Read Advanced recon techniques
methodology
Jan 15, 202618 min read

Advanced recon techniques

Take your reconnaissance phase to the next level with advanced techniques for subdomain enumeration, JavaScript file analysis, GitHub dorking and automation.

B
BBLabsSecurity Researcher
read article
#recon#subdomains#osint
Read Authentication bypass: JWT attacks
techniques
Dec 20, 202514 min read

Authentication bypass: JWT attacks

Explore the most common techniques for attacking insecure JSON Web Token implementations: from the none algorithm to JKU/JWK injection.

B
BBLabsSecurity Researcher
read article
#jwt#authentication#bypass
Read SSRF: From P4 to Critical
techniques
Nov 30, 202516 min read

SSRF: From P4 to Critical

Learn to escalate SSRF vulnerabilities from a low severity to critical impact. Exploitation techniques, filter bypasses and attack chains in cloud environments.

B
BBLabsSecurity Researcher
read article
#ssrf#cloud#escalation
Read What is bug bounty: the complete 2026 guide (how it works, how much it pays, is it legal)
guidesfeatured
2026-06-2513 min read

What is bug bounty: the complete 2026 guide (how it works, how much it pays, is it legal)

What bug bounty is, how a program works step by step, which platforms it runs on (HackerOne, Bugcrowd, Intigriti, YesWeHack), how much you earn, whether it's legal and where to start from scratch.

GEB
Gorka El BochiFounder of BBLABS
read article
#bug-bounty#beginners#hackerone#guide
Read How much you earn in bug bounty (real figures 2026)
guides
2026-06-2512 min read

How much you earn in bug bounty (real figures 2026)

What bug bounty really pays: average rewards by vulnerability type and severity, what top hunters earn, the reality for beginners and why most people don't make a living from it.

GEB
Gorka El BochiFounder of BBLABS
read article
#bug-bounty#money#career#beginners
Read OWASP Top 10 (2021/2025) explained with real examples
guidesfeatured
2026-06-2516 min read

OWASP Top 10 (2021/2025) explained with real examples

The OWASP Top 10 explained category by category, with real examples: broken access control, injections, SSRF, cryptographic failures and more. With links to the theory and hands-on labs for each flaw.

GEB
Gorka El BochiFounder of BBLABS
read article
#owasp#vulnerabilities#web-security#bug-bounty
Read The 30+ best websites to practice web hacking and CTF (2026)
guides
2026-06-2514 min read

The 30+ best websites to practice web hacking and CTF (2026)

Where to practice web hacking legally: 30+ platforms and labs ordered by level — BBLABS, PortSwigger, Hack The Box, TryHackMe, OWASP Juice Shop, Root Me and many more. Honest and useful.

GEB
Gorka El BochiFounder of BBLABS
read article
#practice#ctf#resources#bug-bounty
Read How to become an ethical hacker from scratch: 2026 roadmap (no prior experience)
guidesfeatured
2026-07-2114 min read

How to become an ethical hacker from scratch: 2026 roadmap (no prior experience)

How to become an ethical hacker from scratch with no prior experience: what it is, whether you need to program, whether it's legal and the step-by-step roadmap (fundamentals → web → OWASP Top 10 → labs → first bug bounty). With realistic timelines and the mistakes that hold you back.

GEB
Gorka El BochiFounder of BBLABS
read article
#ethical-hacker#beginners#roadmap#web-hacking#bug-bounty
Read Burp Suite from scratch: a bug bounty tutorial (2026)
toolsfeatured
2026-07-2115 min read

Burp Suite from scratch: a bug bounty tutorial (2026)

Burp Suite tutorial from scratch: what it is, installing and configuring the proxy (127.0.0.1:8080 + CA certificate), Proxy/Intercept, Repeater, Intruder, Decoder, useful extensions, Community vs Pro and a real hunting workflow.

GEB
Gorka El BochiFounder of BBLABS
read article
#burp-suite#tools#proxy#bug-bounty#beginners
Read OSCP guide: what it is, how to prepare and whether it's worth it (2026)
guides
2026-07-2113 min read

OSCP guide: what it is, how to prepare and whether it's worth it (2026)

OSCP guide: what it is, what the exam evaluates (infrastructure pentest, Active Directory, 24h + report), who it's for, how to prepare, OSCP vs eJPT vs eWPT and why it's infrastructure pentesting, not web bug bounty (complementary).

GEB
Gorka El BochiFounder of BBLABS
read article
#oscp#certifications#pentesting#career#offsec
Read Google Dorks for bug bounty: recon with search engines (guide + examples)
techniques
2026-07-2112 min read

Google Dorks for bug bounty: recon with search engines (guide + examples)

Google Dorks guide for bug bounty: what they are, the operators (site:, inurl:, intitle:, filetype:, ext:, intext:), ready-to-use examples for info exposure, panels, sensitive files and subdomains, ethical use within scope and how they fit into your recon.

GEB
Gorka El BochiFounder of BBLABS
read article
#google-dorks#recon#osint#dorking#bug-bounty
Read How much an ethical hacker / pentester earns in Spain (2026)
career
2026-07-2112 min read

How much an ethical hacker / pentester earns in Spain (2026)

How much an ethical hacker or pentester earns in Spain in 2026: salary ranges by seniority (junior, mid, senior, red team), the difference between an employment salary and bug bounty income, career paths and how to land your first job.

GEB
Gorka El BochiFounder of BBLABS
read article
#salary#career#pentester#employment#ethical-hacker
Read sqlmap from scratch: a bug bounty tutorial (2026)
tools
2026-07-2111 min read

sqlmap from scratch: a bug bounty tutorial (2026)

Step-by-step sqlmap tutorial: detect and exploit SQL injections with -u, list databases with --dbs, dump tables with -D/-T/--dump, automate with --batch, tune --level/--risk, evade WAFs with tamper scripts and reach --os-shell. Always within an authorized scope.

GEB
Gorka El BochiFounder of BBLABS
read article
#sqlmap#sqli#tools#sql-injection#tutorial
Read ffuf: web fuzzing from scratch (directories, vhost and parameters)
tools
2026-07-2111 min read

ffuf: web fuzzing from scratch (directories, vhost and parameters)

ffuf tutorial: fuzzing directories, subdomains/vhosts and GET/POST parameters, how to filter noise with -fc/-fs and calibrate with -mc/-ac, SecLists wordlists and when to use gobuster or dirsearch as alternatives.

GEB
Gorka El BochiFounder of BBLABS
read article
#ffuf#fuzzing#recon#tools#seclists
Read Nuclei tutorial (templates, severity and automation)
tools
2026-07-2110 min read

Nuclei tutorial (templates, severity and automation)

Nuclei tutorial: what it is, how to run scans with -t and -severity, keep templates up to date, write your own YAML template and chain it with recon (subfinder | httpx | nuclei) to scan at scale without drowning in false positives.

GEB
Gorka El BochiFounder of BBLABS
read article
#nuclei#recon#automation#tools#templates
Read The essential bug bounty tools (2026)
toolsfeatured
2026-07-2112 min read

The essential bug bounty tools (2026)

The essential bug bounty tool stack for 2026: proxy (Burp Suite/Caido), exploitation (sqlmap), fuzzing (ffuf/gobuster), scanning (nuclei), recon (subfinder, amass, httpx, waybackurls/gau) and intelligence (Shodan). What each does, when to use it and how they fit together.

GEB
Gorka El BochiFounder of BBLABS
read article
#tools#burp-suite#recon#arsenal#bug-bounty
Read The best offensive cybersecurity certifications (2026): OSCP, eWPT, eJPT, CEH, PNPT, OSWE
guidesfeatured
2026-07-2112 min read

The best offensive cybersecurity certifications (2026): OSCP, eWPT, eJPT, CEH, PNPT, OSWE

An honest comparison of the best offensive cybersecurity certifications in 2026: OSCP, eJPT, eWPT/eWPTX, CEH, PNPT and OSWE. What they are, who each is for, which to choose based on your goal (employment, web pentesting, bug bounty) and a suggested path without the hype.

GEB
Gorka El BochiFounder of BBLABS
read article
#certifications#oscp#ewpt#career#pentest
Read HTTP Request Smuggling explained (CL.TE, TE.CL, TE.TE)
techniques
2026-07-2111 min read

HTTP Request Smuggling explained (CL.TE, TE.CL, TE.TE)

What HTTP Request Smuggling is, why it happens, its CL.TE, TE.CL and TE.TE variants, how to detect it with timing and differential techniques, its impact (bypassing controls, cache poisoning, request stealing) and how to test it with Burp's HTTP Request Smuggler extension.

GEB
Gorka El BochiFounder of BBLABS
read article
#request-smuggling#http#cache-poisoning#techniques#advanced
Read WAF bypass techniques: how to evade an application firewall (ethical use)
techniques
2026-07-2112 min read

WAF bypass techniques: how to evade an application firewall (ethical use)

What a WAF is, how to fingerprint it and the most-used bypass techniques —encoding, case toggling, inline comments, HPP, chunked encoding and alternative payloads— applied to XSS and SQL injection. A practical and strictly ethical approach, within scope.

GEB
Gorka El BochiFounder of BBLABS
read article
#waf#bypass#xss#sqli#evasion#techniques
Read Prompt injection and LLM hacking: the new bug bounty surface
techniques
2026-07-2111 min read

Prompt injection and LLM hacking: the new bug bounty surface

What prompt injection is (direct and indirect), how it relates to jailbreaks and data exfiltration via LLMs, the OWASP Top 10 for LLMs, how this surface shows up in the bug bounty of AI-powered applications and how to test it responsibly.

GEB
Gorka El BochiFounder of BBLABS
read article
#prompt-injection#llm#ai#owasp-llm#techniques

Categories

Popular Tags

Newsletter

Get notified about new articles and guides. No spam, unsubscribe anytime.

Subscribe via RSS