From 0 to your first bounty · with real reports, not toy CTFs

Bug Bounty Labs
based on real reports

practice with real bounties

Hacking labs based on real HackerOne, Bugcrowd and Intigriti reports. Download, exploit, learn. From €7.99/mo.

hack your first lab

No commitment · cancel anytime · no card to explore

650

hunters training

50

labs from real reports

380

completions

$200,000

in bounties practiced

40 flags captured this week
BBLABS — bug bounty labs based on real reports
7,99€/mes
... Labs
// Live · unpolished data

The Spanish bug bounty community, in real numbers

No inflated metrics. No “potential users”. Just what the platform has actually delivered.

Registered hunters

Labs based on real reports

Labs solved by the community

Flags captured

Total completions

$ bounty practiced

// what you take away

You walk away knowing how to hunt bugs that pay. For real.

Forget toy CTFs. Here you practice with the same logic that's paying thousands of euros on HackerOne, Bugcrowd and YesWeHack every month.

You'll spot real IDOR, SSRF and RCE

Reports that paid €5k–25k tell you exactly what to look for. Learn where to look and why.

You'll practice pre and post-auth flows

Each lab simulates the context of the original bug: scope, conditions, hypotheses. Just like a real program.

You'll learn to chain vulnerabilities

The big bounties come from chains. XSS + IDOR. Open Redirect + OAuth. Race + SSRF. Learn the pattern.

You'll have writeups for your CV

Every solved lab is documented proof. Share them on LinkedIn, on your blog, or in your hunter portfolio.

All of it, by following the roadmap from 0 to your first bounty →

From zero to a hunter who gets paid

We built the roadmap that takes you from 0 to your first bounty

We mapped the exact path, module by module: from your first Easy XSS to Insane and Extreme. Each lab unlocks the next. Just follow the trail.

Each lab recreates a real report that paid between €500 and €25,000. Learn to find them yourself.
  1. 0

    You start today

    No prior experience

  2. 1

    First step

    1 labs

  3. 5

    On the right track

    5 labs

  4. 10

    Solid hunter

    10 labs

  5. 25

    Standout hunter

    25 labs

  6. 50

    Top 5% global

    50 labs

  7. 100

    Hunter 1%

    100 labs

  8. Your first bounty

No commitment · from €7.99/mo

// real rewards

These are the bounties you'll learn to hunt

Every lab is based on a paid report. The reward you see is the real money the original hunter earned for finding that bug on HackerOne, Bugcrowd or YesWeHack.

// this isn't theory

Real hunters catching bugs that actually pay

Every win is real and verifiable: a BBLabs hunter solving a lab based on a bug that paid that bounty. Click any of them to see their card.

// the ones who write the labs

Hunters with a real track record

The creators who design the labs have taken down real programs. They're not generic instructors: they're active hunters with paid bounties.

Gorka El Bochi
// who's behind this

Built by a real hunter. Not a company.

I didn't build BBLabs as just another business. I built it because I learned bug bounty by hunting real bugs — not toy CTFs with made-up flaws. It's the platform I wish I'd had: every lab is a report that paid real money. I still hunt (see for yourself), and I read every message that reaches me.

Gorka El Bochi · founder
See my hunter profile
650

hunters training

50

labs from real reports

380

completions

$200,000

in bounties practiced

40 flags captured this week

Pricing

Choose how to pay for your full access

A single PRO+ plan with everything. The annual one is the most popular — almost 3 months free vs monthly. A year is how long it takes to train on real bugs, replicate them and land your first bounty. No commitment.

PRO+ Monthly
To try it, no strings
€7.99/mo

Flexible · cancel anytime

≈ €0.26 a day
  • Access to every lab, all difficulties (incl. Insane and Extreme)
  • Live labs: spin up the vulnerable environment in one click
  • Step-by-step writeups for every lab
  • Full roadmap + shareable certificates
  • Private hunters Discord
  • Instant access to every new lab
Most popular · −22%
PRO+ Annual
The favorite · best value
€6.25/mo

€74.99/yr · you save €20.89

  • Access to every lab, all difficulties (incl. Insane and Extreme)
  • Live labs: spin up the vulnerable environment in one click
  • Step-by-step writeups for every lab
  • Full roadmap + shareable certificates
  • Private hunters Discord
  • Instant access to every new lab
  • Early access: play new labs the moment they're scheduled, before anyone else
One-time
Lifetime PRO+
One payment, yours forever
€149.99 one-time

No renewals · forever

  • 1h 1:1 call with the founder to advise you and level you up as much as possibleNEW · limited time
  • Early access: play new labs the moment they're scheduled, before anyone else
  • Access to every lab, all difficulties (incl. Insane and Extreme)
  • Live labs: spin up the vulnerable environment in one click
  • Step-by-step writeups for every lab
  • Full roadmap + shareable certificates
  • Private hunters Discord
  • Instant access to every new lab
  • Private access to the BBLABS Discord community with the best hunters
🔥 The 1:1 call is new and available for a limited time — lock it in while it's still included

Less than half the price of HackTheBox (€168/yr) or PentesterLab (€420/yr) — and with real reports, not CTFs.

Secure SSL payment

Processed by Stripe

No commitment

Cancel anytime

+650 active hunters

Growing community

Before you decide

What if I have no experience?

The roadmap starts at Easy difficulty with step-by-step writeups, and the free Academy covers the theory of each vulnerability before you practice.

How long until I land my first bounty?

It depends on your pace, but at 1-2h a day the real jump is usually 3-6 months. The roadmap is built to get you there without skipping fundamentals.

Why not PortSwigger, which is free?

PortSwigger teaches theory with made-up labs. Here you practice with REAL reports that already paid bounties, with Spanish writeups and a clear path.

Got questions? Check the FAQ or write to us at team@bblabs.es

Comparison

BBLabs vs other platforms for bug bounty

€7.99/mo vs €11–37.99/mo. Real bug bounty reports vs gamified CTFs.

BBLabs PRO+€7.99/mo
€74.99Annual cost
Based on real reports
Spanish content
New labs every week
Free Academy
Downloadable environments
Active community
HackTheBox~€14/mo
€168Annual cost
Based on real reports
Spanish content
New labs every week
Free Academy
Downloadable environments
Active community
TryHackMe~€11/mo
€132Annual cost
Based on real reports
Spanish content
New labs every week
Free Academy
Downloadable environments
Active community
PentesterLab~€37.99/mo
€420Annual cost
Based on real reports
Spanish content
New labs every week
Free Academy
Downloadable environments
Active community
PortSwiggerFree
€0Annual cost
Based on real reports
Spanish content
New labs every week
Free Academy
Downloadable environments
Active community

BBLabs wins where it matters for bug bounty — and costs less than half.

Start from €7.99/mo →

FAQ

Frequently asked questions

A bug bounty lab is a controlled environment that replicates a real vulnerability previously reported and paid out on platforms like HackerOne, Bugcrowd or Intigriti. On BBLabs you download the environment, spin it up locally, exploit the vulnerability and validate your solution by capturing a CTF-style flag. Each lab includes a writeup with the full methodology.

You can practice bug bounty on BBLabs with labs based on real reports, from €7.99/mo. Other alternatives are HackTheBox and TryHackMe (gamified CTFs), PentesterLab (web theory, ~€37.99/mo) and the PortSwigger Web Security Academy (free, without real paid labs). BBLabs is the only one specialized in already-paid reports with a full writeup.

The shortest path: start with the free BBLabs Academy (theory of XSS, SQLi, IDOR, SSRF and CSRF), then solve Easy-difficulty labs with their writeup alongside, move up to Medium once you recognize patterns, and from there join public HackerOne or Bugcrowd programs. Each lab teaches you to think like the hunter who reported the original bug.

BBLabs is the platform specialized in bug bounty with labs based on real paid reports, hunter ranking and an active Discord community. It replicates vulnerabilities that paid out real money in production, not artificial CTF puzzles.

The labs (with a downloadable environment + flag + writeup) require a PRO+ subscription from €7.99/mo, with annual and lifetime options. The Academy —theory, payloads, cheatsheets, dictionary and per-category methodologies— is 100% free: create an account with no card and explore it without paying anything.

More than 16 web vulnerability categories: XSS (reflected, stored and DOM), SQL Injection, IDOR, SSRF, CSRF, Open Redirect, Race Conditions, Path Traversal, API Abuse (mass assignment, BOPLA), Business Logic, Auth Bypass, RCE, XXE, SSTI and more. Every category is fed weekly with new labs based on recent reports.

Our labs replicate vulnerabilities that paid real bounties on HackerOne, Bugcrowd and Intigriti. They're not artificial CTFs. It also costs €7.99/mo (vs €14–37.99/mo from competitors) and includes a free Academy with payloads and methodologies.

PortSwigger is excellent theory, and we actually recommend using it. But its labs are exercises designed to teach a concept, not replicas of bugs that paid real money. On BBLabs you practice exactly what a hunter found in production and got paid for, with the real program context and a full writeup. It's the difference between solving an exam exercise and reproducing the real case that paid €5,000.

There are dozens of labs covering more than 16 vulnerability categories, and we publish a new one every Monday. The full Hunter Roadmap (from Easy XSS up to Insane/Extreme) takes months to complete even for advanced hunters. You won't run out of practice.

Yes. Labs range from Easy to Insane difficulty. Each one includes a step-by-step writeup with the full solution. The free Academy teaches you the theory of each vulnerability before you practice it. You'll learn by doing, not by reading.

Yes. Every lab replicates a vulnerability reported in real bug bounty programs that paid real money. You practice with what actually shows up in production, not with made-up puzzles.

Yes, with no commitment or penalty. Cancel from your panel at any time and keep access until the end of the paid period. No fine print.

Every Monday we publish new labs based on recent reports. The content is updated constantly with the latest techniques that are working in active programs.

Visa, Mastercard, Apple Pay and Google Pay through Stripe. Secure payment with SSL encryption. We also offer an annual plan with 22% off and a one-time lifetime plan.

// academy, company or event?

Put BBLabs in your team's hands

Per-cohort licenses, custom CTFs and co-branded certificates.

Discover BBLabs for business